Skip to main content

Module cli

Module cli 

Source
Expand description

The command tree, and the startup path itself.

Nothing here prints or exits. Every command body returns Result<(), CliError> and dispatch routes to it, so each arm is a plain function a test can call and assert on rather than an unreachable dead end. src/main.rs is where that Result becomes an exit status, and it is the only place in the project that calls std::process::exit — a library whose failure mode is ending the process is one nothing else can use.

Startup is split on the socket boundary, which is what lets a test drive the whole path on an ephemeral port with its own shutdown future instead of a process signal:

  • serve binds server.bind_address, installs the SIGHUP handler, and hands the socket on.
  • serve_on validates the admin configuration and binds that socket too, when [admin] is enabled.
  • serve_on_with does everything else — profile resolution, deduplicated signer backends, per-profile filters and validators, TLS, the job registry (every signer’s handlers, notification delivery and the four table sweeps), the runner draining it, and axum::serve with connect info attached.

That assembly is [build_generation], and it is called again on every reload rather than only at startup — so the two cannot drift, and a subsystem added to one is added to the other by construction. What a reload may change, and what it refuses by name, is crate::reload’s to say; serve_on_with_reloads is where the two meet.

The logic behind each admin subcommand lives in crate::admin, not here; this module is the clap surface over it. [logging] turns [logging] into an installed subscriber, validating every value before installing anything.

What a command prints is render’s, and how it is coloured is style’s. Those renderings sit here rather than in crate::admin because they have exactly one consumer — the terminal — where the JSON ones beside them are a wire format the web admin parses too. dispatch resolves one Palette and threads it down; nonce and upstream take none, printing only fixed text.

Re-exports§

pub use account::AccountCommand;
pub use audit::AuditCommand;
pub use eab::EabCommand;
pub use nonce::NonceCommand;
pub use order::OrderCommand;
pub use upstream::UpstreamCommand;
pub use webadmin::AdminCommand;
pub use crate::cli::style::ColorChoice;
pub use crate::cli::style::Palette;

Modules§

account
audit
eab
filter
acme-proxy filter show|explain — reading the configured access policy.
generate
completions <shell> and man: the two commands whose output is the command tree.
nonce
order
render
The human-readable renderings, and the only place colour is woven in.
style
Colour for the admin CLI’s human-readable output.
upstream
acme-proxy upstream … — managing this server’s own ACME account at the upstream CA, when the relay signer backend is in use.
webadmin
acme-proxy admin … — the web admin’s operators and their sessions.
window
The --limit/--offset window every paged listing takes.

Structs§

Cli
CliError
A command that could not complete, carrying the message to print.

Enums§

Command

Functions§

check_metrics_config
Refuses a [metrics] bind address that collides with another listener’s.
dispatch
Routes a parsed command to its handler.
init_logging
Installs the [logging] configuration. Re-exported because main.rs is what calls it — see dispatch. Installs the process-wide tracing subscriber from [logging].
serve
Binds the configured socket and runs the ACME HTTP(S) server until a shutdown signal arrives.
serve_on
Assembles and serves the application over an already-bound socket.
serve_on_with
serve_on with all three sockets supplied.
serve_on_with_reloads
serve_on_with, serving configuration reloads as well as requests.