Skip to main content

Crate bestool_canopy

Crate bestool_canopy 

Source
Expand description

bestool’s canopy client: the published bes_canopy_api wire layer plus bestool’s own HTTP transport and registration/backup helpers.

The typed CanopyClient, the CanopyTransport trait, the wire types in schema, and the error types all come from bes_canopy_api and are re-exported here. This crate supplies the parts specific to how bestool reaches canopy:

The transport-shaped operations — is_tailscale, refresh, renew — live on ReqwestTransport; reach them through CanopyClient::transport.

§Wire types

The types in schema are generated from canopy’s OpenAPI document, which canopy builds and publishes as bes-canopy-api. Timestamp fields are jiff::Timestamp, credential secrets are wrapped in Redacted so they stay out of Debug output, and each generated struct carries a builder and is #[non_exhaustive]. CanopyClient has one method per endpoint taking and returning these types; any non-2xx surfaces as CanopyHttpError.

Re-exports§

pub use bes_canopy_api::bytes;
pub use bes_canopy_api::http;
pub use reqwest;

Modules§

registration
Single, machine-bound, encrypted store for this host’s canopy enrollment.
schema
Wire types and per-endpoint methods generated from canopy’s OpenAPI document.

Structs§

CanopyHttpError
A non-2xx response from a canopy endpoint.
ContainerCreds
Creds in the ECS container-credentials shape kopia’s minio-go provider polls for: note Token (not SessionToken), and Expiration as RFC3339 Z.
Redacted
Wraps a sensitive value so its Debug output doesn’t leak the contents.
ReqwestTransport
The default canopy transport: HTTP with auth configured for talking to a canopy server.

Enums§

Error
Anything that can go wrong calling canopy.
TargetOutcome
Result of GET /backup-target: a live target, or the benign dormant state (the device is not yet authorised for backups — 412/409).

Constants§

CERT_RENEW_AFTER
How long to wait between scheduled cert renewals.
DEFAULT_CANOPY_URL
TAILSCALE_URL
Base URL for the tailscale-internal canopy endpoint.

Traits§

CanopyTransport
The HTTP transport a CanopyClient sends through.

Functions§

connect
Build a canopy client against the default public (DEFAULT_CANOPY_URL) and tailscale (TAILSCALE_URL) endpoints. Use connect_to to override them.
connect_to
Build a canopy client against explicit endpoints.
device_identity
Build a short-lived self-signed client certificate from a P-256 device key PEM and wrap it as a reqwest mTLS Identity.
tailscale_client
Probe the canopy tailnet endpoint, returning a client routed to it if reachable.

Type Aliases§

CanopyClient
The typed canopy client, defaulting to bestool’s ReqwestTransport.
CanopyRequest
A request built by CanopyClient, ready for a CanopyTransport to send.
CanopyResponse
A response handed back to CanopyClient by a CanopyTransport, with its body buffered.
ClientBuilderFactory
Factory producing the base reqwest::ClientBuilder for canopy’s clients.

Attribute Macros§

async_trait