Skip to main content

acme_proxy/config/types/
profile.rs

1//! `[profiles.<name>]` โ€” the per-endpoint overlay, plus `[eab]`.
2//!
3//! Re-exported flat from [`super`], so nothing outside this directory names
4//! the submodule.
5
6use serde::Deserialize;
7
8use super::challenge::ChallengeConfig;
9use super::filter::FilterConfig;
10use super::ipam::IpamConfig;
11use super::notify::NotifyConfig;
12use super::server::{MetaConfig, OrderConfig};
13use super::signer::SignerConfig;
14
15/// One ACME endpoint's configuration: the eight sections a profile may carry,
16/// plus the marker that declares it.
17///
18/// Every field is optional in the file โ€” what a profile does not say, it
19/// inherits from the matching global section (see `Config::resolve_profiles`),
20/// key by key. So `[profiles.le]` alone is a complete profile, identical to the
21/// global configuration but served under its own URL prefix.
22#[derive(Debug, Clone, Deserialize)]
23#[serde(default)]
24pub struct ProfileSections {
25    /// Whether to mount this profile at all. Defaults to `true`: a profile
26    /// exists because it is written down. It is a bool rather than a bare
27    /// marker for two reasons โ€” an operator can park an endpoint without
28    /// deleting its configuration, and an environment-only profile needs at
29    /// least one key to exist at all (`ACME_PROXY_PROFILES__LE__ENABLED=true`).
30    pub enabled: bool,
31    pub signer: SignerConfig,
32    pub filter: FilterConfig,
33    pub ipam: IpamConfig,
34    pub challenge: ChallengeConfig,
35    pub eab: EabConfig,
36    pub order: OrderConfig,
37    pub notify: NotifyConfig,
38    pub meta: MetaConfig,
39}
40
41impl Default for ProfileSections {
42    fn default() -> Self {
43        Self {
44            enabled: true,
45            signer: SignerConfig::default(),
46            filter: FilterConfig::default(),
47            ipam: IpamConfig::default(),
48            challenge: ChallengeConfig::default(),
49            eab: EabConfig::default(),
50            meta: MetaConfig::default(),
51            order: OrderConfig::default(),
52            notify: NotifyConfig::default(),
53        }
54    }
55}
56/// A named, fully resolved profile: its name (which is also its URL segment,
57/// `/profile/<name>`) and the sections it ended up with after inheritance.
58#[derive(Debug, Clone)]
59pub struct ProfileConfig {
60    pub name: String,
61    pub sections: ProfileSections,
62}
63/// External Account Binding (RFC 8555 ยง7.3.4) requirement.
64#[derive(Debug, Clone, Deserialize, Default)]
65#[serde(default)]
66pub struct EabConfig {
67    pub enabled: bool,
68}