pub fn build_admin_app(
database: Arc<Database>,
config: Arc<Config>,
profiles: &[Arc<Profile>],
audit: Arc<Auditor>,
) -> RouterExpand description
Builds the whole admin service: /health, then the JSON API under /api.
Takes profiles as a slice so it can be called before build_app
consumes the Vec in cli::serve_on — the ordering is a real constraint
and the signature is where it is stated.
§What this router deliberately does not have
- No admission control.
Admissionexists because the ACME surface is public and unauthenticated. This one defaults to loopback and needs a session on every route but login; the real availability concern is credential brute force, which admission control would not touch and the login limiter does. - No filter chain. Filters are a per-profile ACME concern, and
filter.exempt_pathsmatches profile-stripped paths. Wiring them here would be a category error. Access control on this listener is the bind address, TLS, and the session.