pub struct BlobFallbackConfig {Show 14 fields
pub blobs: Option<BlobBackend>,
pub s3_bucket: Option<String>,
pub s3_endpoint: Option<String>,
pub s3_region: Option<String>,
pub s3_path_style: bool,
pub s3_credential: Option<S3CredentialConfig>,
pub gcs_bucket: Option<String>,
pub gcs_endpoint: Option<String>,
pub gcs_anonymous: bool,
pub azure_account: Option<String>,
pub azure_container: Option<String>,
pub azure_access_key: Option<String>,
pub azure_emulator: bool,
pub secondary_timeout_secs: Option<u64>,
}Expand description
[serve.blob_fallback] — a read-only SECONDARY blob backend for a zero-downtime backend switch
(blob-backend migration Part 2). Same backend-descriptor shape as the PRIMARY ([serve]’s
blobs/s3_*/gcs_*/azure_* fields) so a source/dest is fully described by config, plus its OWN
optional s3_credential (the secondary can source its base S3 credential from the sealed [secrets]
store via its own boatramp:/env: ref, #505). Constructed exactly like the primary but with NO
watcher provisioning (a read-only drain source never watches). Serving wraps
FallbackStorage::new(primary, secondary, …) so a primary miss on a boatramp-owned key falls through
to this secondary; writes/deletes are primary-only.
The secondary is never handed to the blob-upload/STS minter — external ingress mints against the PRIMARY only (the new backend the client should upload to), so this credential never reaches the minter path.
Fields§
§blobs: Option<BlobBackend>The secondary blob backend (fs/s3/gcs/azure) — the OLD backend to fall back to on a
primary miss. Absent ⇒ fs (the default, matching the primary’s blobs default).
s3_bucket: Option<String>S3 bucket (secondary blobs = s3).
s3_endpoint: Option<String>S3 endpoint URL (a MinIO/R2/Tigris endpoint) for the secondary.
s3_region: Option<String>S3 region for the secondary.
s3_path_style: boolUse S3 path-style addressing (MinIO) for the secondary.
s3_credential: Option<S3CredentialConfig>The secondary’s OWN node-level sealed base S3 credential source (#505) — resolved through the
SAME resolve_s3_credential path as the primary (same fail-closed posture, no second parser).
Absent ⇒ the ambient AWS env chain (unchanged).
gcs_bucket: Option<String>GCS bucket (secondary blobs = gcs).
gcs_endpoint: Option<String>GCS storage endpoint URL (a fake-gcs-server emulator) for the secondary.
gcs_anonymous: boolSkip GCS credential resolution (anonymous — the emulator) for the secondary.
azure_account: Option<String>Azure storage account name (secondary blobs = azure).
azure_container: Option<String>Azure container name for the secondary.
azure_access_key: Option<String>Azure storage account access key (shared-key auth) for the secondary.
azure_emulator: boolUse the Azurite emulator for the secondary.
secondary_timeout_secs: Option<u64>Bound (seconds) on each secondary read so a wedged secondary degrades a primary miss to
NotFound instead of hanging the serve path. Absent ⇒ DEFAULT_BLOB_FALLBACK_TIMEOUT_SECS.
Trait Implementations§
Source§impl Clone for BlobFallbackConfig
impl Clone for BlobFallbackConfig
Source§impl Debug for BlobFallbackConfig
impl Debug for BlobFallbackConfig
Source§impl Default for BlobFallbackConfig
impl Default for BlobFallbackConfig
Source§impl<'de> Deserialize<'de> for BlobFallbackConfig
impl<'de> Deserialize<'de> for BlobFallbackConfig
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
Auto Trait Implementations§
impl Freeze for BlobFallbackConfig
impl RefUnwindSafe for BlobFallbackConfig
impl Send for BlobFallbackConfig
impl Sync for BlobFallbackConfig
impl Unpin for BlobFallbackConfig
impl UnsafeUnpin for BlobFallbackConfig
impl UnwindSafe for BlobFallbackConfig
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more