Skip to main content

Module ipam

Module ipam 

Source
Expand description

IP address management: which names does an address own?

One question, asked of whichever inventory an estate already keeps. It used to be a filter — filter.netbox — which welded the question to one vendor’s REST API: the config lived under [filter.netbox], the seam was shaped around NetBox’s endpoints, and the filter was named after the product. A second inventory had nowhere to plug in.

So the question lives here and the policy built on the answer stays in filter::ipam, which is the only consumer. The split is the same one signer makes: a backend reports what is true, a caller decides what to do about it.

§Denied versus Internal

The most consequential property here, and the reason IpamError is a struct rather than an enum with a “denied” variant: an Ipam never denies anything. It reports what an inventory holds, and every failure to obtain that — unreachable, 500, a refused token, a timeout — is this server failing to reach a decision, which the filter turns into a retryable 500 rather than a refusal. The only inventory-sourced denial is AddressNames::Unknown, which is a fact about the address rather than a failure to look it up.

That is what keeps the subsystem from ever failing open: an inventory outage stops issuance instead of permitting everything.

§The budget lives here

IpamRegistry wraps every lookup in a tokio::time::timeout, the way ChallengeRegistry wraps every validation attempt. A backend may make four requests to answer one question; one budget covers all of them, and a backend added later cannot forget to apply it. custom is the proof of that last clause: its lookup is a forked process rather than a request at all, and it is covered without having been written to be.

§Matching is exact

Names are normalized — lowercased and stripped of a trailing dot — and otherwise compared literally. No suffix rule, no wildcard expansion: an entry example.com does not permit a.example.com, and a request for *.example.com requires that exact string in the inventory. The same choice compile_anchored makes for the regex-based filters, for the same reason — a rule that quietly covers more than it says is the bypass an allowlist exists to prevent.

Modules§

custom
The custom IPAM backend: the inventory is an operator-supplied script.
http
The JSON-over-HTTP transport both IPAM backends speak.
netbox
The netbox IPAM backend: what NetBox associates with an address.
phpipam
The phpipam IPAM backend: what phpIPAM associates with an address.

Structs§

IpamError
The inventory failed to reach a decision.
IpamRegistry
The configured backend plus the budget every lookup runs under.

Enums§

AddressNames
What an inventory knows about one address.
Source
One place a permitted name may come from.

Traits§

Ipam
The inventory this profile consults.

Functions§

from_config
Builds the configured inventory, or None when none is configured.
normalize
Lowercased and stripped of a trailing dot, the form both sides compare in.

Type Aliases§

Sources
The sources a backend was configured with, after validation.