acme_proxy/config/types/profile.rs
1//! `[profiles.<name>]` โ the per-endpoint overlay, plus `[eab]`.
2//!
3//! Re-exported flat from [`super`], so nothing outside this directory names
4//! the submodule.
5
6use serde::Deserialize;
7
8use super::challenge::ChallengeConfig;
9use super::filter::FilterConfig;
10use super::ipam::IpamConfig;
11use super::notify::NotifyConfig;
12use super::server::{MetaConfig, OrderConfig};
13use super::signer::SignerConfig;
14
15/// One ACME endpoint's configuration: the eight sections a profile may carry,
16/// plus the marker that declares it.
17///
18/// Every field is optional in the file โ what a profile does not say, it
19/// inherits from the matching global section (see `Config::resolve_profiles`),
20/// key by key. So `[profiles.le]` alone is a complete profile, identical to the
21/// global configuration but served under its own URL prefix.
22#[derive(Debug, Clone, Deserialize)]
23#[serde(default)]
24pub struct ProfileSections {
25 /// Whether to mount this profile at all. Defaults to `true`: a profile
26 /// exists because it is written down. It is a bool rather than a bare
27 /// marker for two reasons โ an operator can park an endpoint without
28 /// deleting its configuration, and an environment-only profile needs at
29 /// least one key to exist at all (`ACME_PROXY_PROFILES__LE__ENABLED=true`).
30 pub enabled: bool,
31 pub signer: SignerConfig,
32 pub filter: FilterConfig,
33 pub ipam: IpamConfig,
34 pub challenge: ChallengeConfig,
35 pub eab: EabConfig,
36 pub order: OrderConfig,
37 pub notify: NotifyConfig,
38 pub meta: MetaConfig,
39}
40
41impl Default for ProfileSections {
42 fn default() -> Self {
43 Self {
44 enabled: true,
45 signer: SignerConfig::default(),
46 filter: FilterConfig::default(),
47 ipam: IpamConfig::default(),
48 challenge: ChallengeConfig::default(),
49 eab: EabConfig::default(),
50 meta: MetaConfig::default(),
51 order: OrderConfig::default(),
52 notify: NotifyConfig::default(),
53 }
54 }
55}
56/// A named, fully resolved profile: its name (which is also its URL segment,
57/// `/profile/<name>`) and the sections it ended up with after inheritance.
58#[derive(Debug, Clone)]
59pub struct ProfileConfig {
60 pub name: String,
61 pub sections: ProfileSections,
62}
63/// External Account Binding (RFC 8555 ยง7.3.4) requirement.
64#[derive(Debug, Clone, Deserialize, Default)]
65#[serde(default)]
66pub struct EabConfig {
67 pub enabled: bool,
68}