pub struct Egress {
pub resolver: Arc<dyn Resolver>,
pub proxies: Arc<OutboundProxies>,
pub identity: String,
}Expand description
The outbound plumbing one configuration generation dials through, and the identity of the configuration it came from.
[dns] and [proxy] are process-wide but no longer frozen, so they belong
to a generation rather than to the Assembly: a reload builds a fresh
resolver and proxy policy from the file, and every subsystem that reaches the
network is handed this generation’s pair. The signer backends look like the
exception and are not — they cache what they were built with, so
signer::build_backends folds identity into a backend’s identity key and
rebuilds any backend whose egress moved. Keeping the identity here rather
than beside the call site is what stops the two disagreeing, which would make
a dns.resolver edit a silent no-op for every signer.
Fields§
§resolver: Arc<dyn Resolver>Uncached, for the reason challenge::build_resolver explains: a client
publishing a dns-01 record moments before triggering must not be
defeated by a cached negative answer.
proxies: Arc<OutboundProxies>§identity: String[dns] and [proxy] rendered. Only ever compared to another one — never
parsed, never shown — which is the same contract signer::build_backends
keys a [signer] section on.
Implementations§
Source§impl Egress
impl Egress
Sourcepub fn from_config(config: &Config) -> Result<Self>
pub fn from_config(config: &Config) -> Result<Self>
Builds both clients from config.
Fallible for two separate reasons worth keeping apart: a proxy URL that
cannot be understood, and a dns.resolver that is not a socket address.
Both must stop a startup and refuse a reload rather than degrade — a
server that silently fell back to direct egress would dial around exactly
the control its operator configured.
Sourcepub fn outbound(&self) -> Outbound
pub fn outbound(&self) -> Outbound
The resolver and proxy policy as one value, for the subsystems that make outbound HTTP requests.
An accessor rather than a stored field: challenge::from_config builds
its own resolver past the bypass branch (constructing one is what
reads /etc/resolv.conf, so it must not happen when validation is off),
and so needs the proxy half on its own.
Auto Trait Implementations§
impl !RefUnwindSafe for Egress
impl !UnwindSafe for Egress
impl Freeze for Egress
impl Send for Egress
impl Sync for Egress
impl Unpin for Egress
impl UnsafeUnpin for Egress
Blanket Implementations§
Source§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
Source§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more