Skip to main content

alien_core/
remote_bindings.rs

1use crate::{ResourceEntry, ResourceLifecycle, ResourceType};
2
3#[derive(Debug, Clone, Copy, PartialEq, Eq)]
4pub enum RemoteBindingKind {
5    Storage,
6    Key,
7    Ai,
8}
9
10/// One resource type's provider-neutral Remote Bindings contract.
11#[derive(Debug, Clone, Copy, PartialEq, Eq)]
12pub struct RemoteBindingDefinition {
13    pub resource_type: &'static str,
14    pub permission_set: &'static str,
15    pub kind: RemoteBindingKind,
16    pub description: &'static str,
17    /// Setup-owned parent resources that this binding kind may require. They do not turn a
18    /// bindings-only stack into an application stack.
19    pub setup_support_resource_types: &'static [&'static str],
20    /// Increment when the permission set's effective grants change. This makes direct setup
21    /// updates reconcile permissions even when the application resource config is unchanged.
22    pub revision: u32,
23}
24
25const DEFINITIONS: &[RemoteBindingDefinition] = &[
26    RemoteBindingDefinition {
27        resource_type: "storage",
28        permission_set: "storage/remote-data-write",
29        kind: RemoteBindingKind::Storage,
30        description: "Read and write objects in this storage resource",
31        setup_support_resource_types: &[
32            "azure_resource_group",
33            "azure_storage_account",
34            "service_activation",
35        ],
36        revision: 1,
37    },
38    RemoteBindingDefinition {
39        resource_type: "key",
40        permission_set: "key/remote-cryptography",
41        kind: RemoteBindingKind::Key,
42        description: "Encrypt and decrypt small values with this key",
43        setup_support_resource_types: &["azure_resource_group", "service_activation"],
44        revision: 1,
45    },
46    RemoteBindingDefinition {
47        resource_type: "ai",
48        permission_set: "ai/invoke",
49        kind: RemoteBindingKind::Ai,
50        description: "Invoke models through this AI resource",
51        setup_support_resource_types: &["azure_resource_group", "service_activation"],
52        revision: 1,
53    },
54];
55
56pub fn remote_binding_definition(
57    resource_type: &ResourceType,
58) -> Option<&'static RemoteBindingDefinition> {
59    DEFINITIONS
60        .iter()
61        .find(|definition| definition.resource_type == resource_type.as_ref())
62}
63
64pub fn remote_binding_for_entry(entry: &ResourceEntry) -> Option<&'static RemoteBindingDefinition> {
65    (entry.remote_access && entry.lifecycle == ResourceLifecycle::Frozen)
66        .then(|| remote_binding_definition(&entry.config.resource_type()))
67        .flatten()
68}
69
70pub fn remote_binding_definitions() -> &'static [RemoteBindingDefinition] {
71    DEFINITIONS
72}