Expand description
The command tree.
Nothing here exits. Every command body returns Result<(), CliError>
and dispatch routes to it, so each arm is a plain function a test can
call and assert on rather than an unreachable dead end. src/main.rs is
where that Result becomes an exit status, and it is the only place in the
project that calls std::process::exit — a library whose failure mode is
ending the process is one nothing else can use.
What a command prints is its own: a body writes its answer to stdout,
since that is the answer, and returns its refusal as a CliError for
main.rs to render on stderr. A listing’s rendering is render, and a
--json body never sees a Palette.
serve is one arm like the others: the server runtime itself lives in
acme_proxy_server, and serve only turns its failure into a CliError.
The logic behind each admin subcommand lives in acme_proxy_admin::admin, not here;
this module is the clap surface over it. [logging] turns [logging] into
an installed subscriber, validating every value before installing anything.
What a command prints is render’s, and how it is coloured is
style’s. Those renderings sit here rather than in acme_proxy_admin::admin
because they have exactly one consumer — the terminal — where the JSON ones
beside them are a wire format the web admin parses too. dispatch
resolves one Palette and threads it down; nonce and upstream take
none, printing only fixed text.
Re-exports§
pub use account::AccountCommand;pub use audit::AuditCommand;pub use eab::EabCommand;pub use jobs::JobsCommand;pub use nonce::NonceCommand;pub use order::OrderCommand;pub use profile::ProfileCommand;pub use upstream::UpstreamCommand;pub use webadmin::AdminCommand;pub use crate::cli::style::ColorChoice;
Modules§
- account
acme-proxy account— list, show, update the contacts of, deactivate and delete ACME accounts.- audit
acme-proxy audit— read the audit trail, and prune it.- eab
acme-proxy eab— mint, list, revoke and delete external-account credentials (RFC 8555 §7.3.4).- filter
acme-proxy filter show|explain— reading the configured access policy.- generate
completions <shell>andman: the two commands whose output is the command tree.- jobs
acme-proxy jobs— inspect and manage the background queue (crates/jobs/src/jobs/+crates/store/src/job.rs), the subsystem whose whole purpose is surviving the failures an operator gets paged about.- nonce
acme-proxy nonce— count the replay-nonce table, and sweep it by hand.- order
acme-proxy order— list, show, revoke and clean up orders.- profile
profile list— the ACME endpoints this configuration mounts.- render
- The human-readable renderings, and the only place colour is woven in.
- schema
- Who owns the database schema for this invocation.
- style
- Whether the admin CLI’s human-readable output is coloured.
- transfer
acme-proxy transfer --to <url>— copy every row into the other backend.- upstream
acme-proxy upstream …— managing this server’s own ACME account at the upstream CA, when therelaysigner backend is in use.- webadmin
acme-proxy admin …— the web admin’s operators and their sessions.- window
- The
--limit/--offsetwindow every paged listing takes.
Structs§
- Cli
- CliError
- A command that could not complete, carrying the message to print and the kind that decides the process exit status.
Enums§
- CliError
Kind - Why a command failed, in the one distinction a script cares about: was it the host that could not carry out the request, or the request itself that could not be satisfied as written? Only the first is worth retrying.
- Command
- LogLevel
- The
--log-levelflag and the per-invocation decision it feeds. Re-exported formain.rs, which is where the subscriber is installed. The--log-levelflag and the per-invocation decision it feeds. Re-exported formain.rs, which is where the subscriber is installed. The--log-levelflag and the per-invocation decision it feeds. Re-exported formain.rs, which is where the subscriber is installed.--log-level: how much this invocation logs. - Logging
Plan - The
--log-levelflag and the per-invocation decision it feeds. Re-exported formain.rs, which is where the subscriber is installed. The--log-levelflag and the per-invocation decision it feeds. Re-exported formain.rs, which is where the subscriber is installed. The--log-levelflag and the per-invocation decision it feeds. Re-exported formain.rs, which is where the subscriber is installed. Which subscriber, if any, an invocation installs.
Functions§
- dispatch
- Routes a parsed command to its handler.
- init
acme-proxy init— migrate, then generate whatever first-run material the configuration calls for.- migrate
acme-proxy migrate— applies the embedded migrations and reports what it did.- plan_
logging - The
--log-levelflag and the per-invocation decision it feeds. Re-exported formain.rs, which is where the subscriber is installed. The--log-levelflag and the per-invocation decision it feeds. Re-exported formain.rs, which is where the subscriber is installed. The--log-levelflag and the per-invocation decision it feeds. Re-exported formain.rs, which is where the subscriber is installed. Decides what this invocation logs, from the subcommand and the two ways an operator can ask. - serve
- Runs the ACME HTTP(S) server until a shutdown signal arrives.