Expand description
Persistence: one module per table, over sqlx and SQLite.
Queries are built with the runtime sqlx::query API rather than the
compile-time macros, so DATABASE_URL is not needed to build the crate.
Migrations are embedded and run at startup — see db.
Two invariants shape almost everything here:
- A profile is a data boundary.
accountsandorderscarry aprofilecolumn andaccountsis keyedUNIQUE(profile, pubkey), so one client key at two endpoints is two unrelated accounts. Request-path lookups always take the profile; the admin layer uses the deliberately unscopedfind_any_*variants. auditrows outlive their subjects. That table has no foreign keys, because aCASCADEwould delete the evidence along with the account or order it describes. It is INSERT-only: there is no setter and noUPDATEagainst it anywhere in the crate.
Methods return Result<_, sqlx::Error> and leave the mapping to a
crate::error::Problem to their caller.
Modules§
- account
- admin_
recovery_ code - admin_
session - admin_
user - audit
- The
audit_logmodel: append, read back, purge by age. - authz
- db
- eab
- job
- The
jobsmodel: the durable queue behindcrate::jobs. - nonce
- order
- status
- The three ACME state machines, as types rather than strings.
- upstream_
order - The mapping between a local order and the order the
relaysigner backend opened for it at the upstream CA.