Skip to main content

Module cli

Module cli 

Source
Expand description

The command tree, and the startup path itself.

Nothing here prints or exits. Every command body returns Result<(), CliError> and dispatch routes to it, so each arm is a plain function a test can call and assert on rather than an unreachable dead end. src/main.rs is where that Result becomes an exit status, and it is the only place in the project that calls std::process::exit — a library whose failure mode is ending the process is one nothing else can use.

Startup is split on the socket boundary, which is what lets a test drive the whole path on an ephemeral port with its own shutdown future instead of a process signal:

  • serve binds server.bind_address, installs the SIGHUP handler, and hands the socket on.
  • serve_on validates the admin configuration and binds that socket too, when [admin] is enabled.
  • serve_on_with does everything else — profile resolution, deduplicated signer backends, per-profile filters and validators, TLS, the job registry (every signer’s handlers, notification delivery and the four table sweeps), the runner draining it, and axum::serve with connect info attached.

That assembly is [build_generation], and it is called again on every reload rather than only at startup — so the two cannot drift, and a subsystem added to one is added to the other by construction. What a reload may change, and what it refuses by name, is crate::reload’s to say; serve_on_with_reloads is where the two meet.

The logic behind each admin subcommand lives in crate::admin, not here; this module is the clap surface over it. [logging] turns [logging] into an installed subscriber, validating every value before installing anything.

What a command prints is render’s, and how it is coloured is style’s. Those renderings sit here rather than in crate::admin because they have exactly one consumer — the terminal — where the JSON ones beside them are a wire format the web admin parses too. dispatch resolves one Palette and threads it down; nonce and upstream take none, printing only fixed text.

Re-exports§

pub use account::AccountCommand;
pub use audit::AuditCommand;
pub use eab::EabCommand;
pub use nonce::NonceCommand;
pub use order::OrderCommand;
pub use profile::ProfileCommand;
pub use upstream::UpstreamCommand;
pub use webadmin::AdminCommand;
pub use crate::cli::style::ColorChoice;
pub use crate::cli::style::Palette;

Modules§

account
audit
eab
filter
acme-proxy filter show|explain — reading the configured access policy.
generate
completions <shell> and man: the two commands whose output is the command tree.
nonce
order
profile
profile list — the ACME endpoints this configuration mounts.
render
The human-readable renderings, and the only place colour is woven in.
style
Colour for the admin CLI’s human-readable output.
upstream
acme-proxy upstream … — managing this server’s own ACME account at the upstream CA, when the relay signer backend is in use.
webadmin
acme-proxy admin … — the web admin’s operators and their sessions.
window
The --limit/--offset window every paged listing takes.

Structs§

Cli
CliError
A command that could not complete, carrying the message to print.

Enums§

Command
LogLevel
The --log-level flag and the per-invocation decision it feeds. Re-exported for main.rs, which is where the subscriber is installed. --log-level: how much this invocation logs.
LoggingPlan
The --log-level flag and the per-invocation decision it feeds. Re-exported for main.rs, which is where the subscriber is installed. Which subscriber, if any, an invocation installs.

Functions§

check_metrics_config
Refuses a [metrics] bind address that collides with another listener’s.
dispatch
Routes a parsed command to its handler.
init_command_logging
The --log-level flag and the per-invocation decision it feeds. Re-exported for main.rs, which is where the subscriber is installed. Installs the diagnostic subscriber a one-shot admin command asked for.
init_logging
Installs the [logging] configuration. Re-exported because main.rs is what calls it — see dispatch. Installs the process-wide tracing subscriber from [logging].
plan_logging
The --log-level flag and the per-invocation decision it feeds. Re-exported for main.rs, which is where the subscriber is installed. Decides what this invocation logs, from the subcommand and the two ways an operator can ask.
serve
Binds the configured socket and runs the ACME HTTP(S) server until a shutdown signal arrives.
serve_on
Assembles and serves the application over an already-bound socket.
serve_on_with
serve_on with all three sockets supplied.
serve_on_with_reloads
serve_on_with, serving configuration reloads as well as requests.