pub struct Profile {
pub name: String,
pub path: String,
pub base_url: String,
pub signer: Arc<dyn SignerBackend>,
pub filter: Arc<FilterPolicy>,
pub challenges: Arc<ChallengeRegistry>,
pub order: OrderConfig,
pub eab: EabConfig,
pub meta: MetaConfig,
pub notify: Arc<NotifyDispatcher>,
}Expand description
One ACME endpoint: its identity, its URLs, and the three subsystems that answer for it.
Everything per-endpoint lives here rather than beside the global config in
AppState, so a handler cannot pair one profile’s signer with another’s
base URL — the two always travel together.
Fields§
§name: StringThe configured name ([profiles.<name>]), also the URL segment and the
value stored in accounts.profile / orders.profile.
path: StringWhere the router mounts it: /profile/<name>.
base_url: StringThe public base for every URL this endpoint hands out and for the
RFC 8555 §6.4 url check: server.base_url + Profile::path.
signer: Arc<dyn SignerBackend>§filter: Arc<FilterPolicy>§challenges: Arc<ChallengeRegistry>§order: OrderConfig§eab: EabConfig§meta: MetaConfigThe optional meta members this endpoint’s directory advertises
(RFC 8555 §7.1.1). Per-profile, like everything else here: two endpoints
on one process can have different terms of service.
notify: Arc<NotifyDispatcher>Implementations§
Source§impl Profile
impl Profile
Sourcepub fn new(name: &str, base_url: &str, parts: ProfileParts) -> Self
pub fn new(name: &str, base_url: &str, parts: ProfileParts) -> Self
Assembles a profile, deriving its path and base URL from its name — the two are never configured, so they cannot drift from each other or from what the database records.
Sourcepub fn directory_url(&self) -> String
pub fn directory_url(&self) -> String
This endpoint’s directory URL — where a client starts.
Derived here rather than format!-ed at each of the three call sites
(the startup log line, the admin API’s profile listing, and anything
added later), all of which have to agree with what build_router
actually mounts.
Sourcepub fn build_all(
config: &Config,
database: Arc<Database>,
jobs: &JobQueue,
) -> Result<Vec<Arc<Profile>>>
pub fn build_all( config: &Config, database: Arc<Database>, jobs: &JobQueue, ) -> Result<Vec<Arc<Profile>>>
Builds every endpoint this configuration mounts, ready to serve.
Lives here rather than in cli::serve_on because it is the assembly step,
not dispatch: it resolves the profiles, builds the signer backends
(deduplicated by configuration — see signer::build_backends), and
gives each profile its own filter chain and challenge registry. Every
failure is fatal at startup, so they come back as one error for the
caller to report and exit on.
Each profile’s subsystems are built inside a span naming it, so the
warnings they emit at build time (filter_disabled,
challenge_validation_bypassed) say which endpoint is wide open —
with several mounted, an unattributed warning is worse than none.
jobs is the enqueue side of the durable queue, handed in rather than
built here for the reason the Auditor is built in serve_on_with:
[jobs] is process-wide, one queue drained by one runner, and a profile
is not the thing that owns it.
Sourcepub fn build_all_with(
config: &Config,
resolved: &[ProfileConfig],
generation: &GenerationParts,
) -> Result<Vec<Arc<Profile>>>
pub fn build_all_with( config: &Config, resolved: &[ProfileConfig], generation: &GenerationParts, ) -> Result<Vec<Arc<Profile>>>
One generation of profiles, over an Assembly that outlives it.
The half of build_all a configuration reload runs
again. Everything it touches is cheap and side-effect-free to rebuild —
a filter policy, an IPAM client, a challenge registry — which is exactly
why the stateful half lives in the Assembly instead. The signer
backends are the interesting middle case: they are rebuilt here too, but
only the ones whose configuration actually moved, and those adopt what
the outgoing instance held (see signer::build_backends).
Auto Trait Implementations§
impl !RefUnwindSafe for Profile
impl !UnwindSafe for Profile
impl Freeze for Profile
impl Send for Profile
impl Sync for Profile
impl Unpin for Profile
impl UnsafeUnpin for Profile
Blanket Implementations§
Source§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
Source§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more