pub struct Outbox { /* private fields */ }Expand description
The operator’s destinations, and the registration that puts a run in front of them.
Implementations§
Source§impl Outbox
impl Outbox
Sourcepub fn new(store: Arc<dyn PushStore>, destinations: Vec<Destination>) -> Self
pub fn new(store: Arc<dyn PushStore>, destinations: Vec<Destination>) -> Self
The outbox over a set of operator destinations.
§Panics
If two destinations share a name, or a name is blank. Both would make the stored id ambiguous, and one destination’s cursor would advance on the other’s acknowledgements — a silent loss of every event for whichever one lost the race, which is exactly what a durable outbox exists to prevent.
pub fn destinations(&self) -> &[Destination]
Sourcepub fn sealed(self, keys: Arc<dyn KeyRing>, tenant: TenantId) -> Self
pub fn sealed(self, keys: Arc<dyn KeyRing>, tenant: TenantId) -> Self
The same outbox, with its store’s credentials sealed under keys.
An operator destination’s bearer — written by open into
every run’s registration — is a credential like any caller’s, and the
store keeps it. This wraps the store in
SealedPush, so what lands at rest is
sealed and what Outbox’s worker reads back is not.
One method rather than “construct with a wrapped store” because the
runtime seals stores at build — after the embedder handed the outbox
over — and a decorator only the constructor could apply is a guarantee
the argument order decides. tenant must be the tenant the store
serves, for the reason
SealedCases::wrap gives.
Sourcepub async fn open(&self, run: RunId) -> Result<(), StoreError>
pub async fn open(&self, run: RunId) -> Result<(), StoreError>
Register every destination against a run, from its first record on.
Called by the runtime at admission and by every resume that executes.
Idempotent: PushStore::put preserves an existing cursor, so a
resumed run does not rewind a receiver that has already acknowledged
part of the history.
§Errors
StoreError if the push store cannot be written. The admission or
resume fails, which is the correct direction: a run executing without
its destinations registered would produce a history nothing is
watching, and the events it missed are unrecoverable without a scan
nobody schedules.
Trait Implementations§
Auto Trait Implementations§
impl !RefUnwindSafe for Outbox
impl !UnwindSafe for Outbox
impl Freeze for Outbox
impl Send for Outbox
impl Sync for Outbox
impl Unpin for Outbox
impl UnsafeUnpin for Outbox
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more