Expand description
The transport half of this server’s four outbound HTTP clients.
Deliberately not a shared client type. What
challenge::http_01,
signer::relay::client,
ipam::http and
notify::webhook have in common is
plumbing: pick a URL apart into host, scheme and port; connect through the
shared resolver; wrap in TLS with the right SNI; hand the stream to hyper and
spawn the connection task. That part was written out four times, and
client_tls_config twice byte-for-byte.
What differs is policy, and each of those modules’ comment defending
“per-module locality” is right about policy and wrong about plumbing:
http_01 must not validate the peer certificate (RFC 8555 §8.3 — what
it carries is the proof, not an identity) while the other three must; each
caps its response body differently; each has its own headers and its own
error type. So this module owns the plumbing and nothing else.
Structs§
- Outbound
- Where to resolve a name, and whether to go through a proxy.