pub enum S3CredentialError {
EmptyAccessKeyId,
EmptySecret,
BoatrampRefOnCluster(String),
NoEnvelope,
MissingBoatrampSecret(String),
EnvRefNotPermitted(String),
EnvVarUnset(String),
UnsupportedScheme(String),
Backend(String),
NotUtf8,
}Expand description
A failure resolving the node-level base S3 credential. Stringly at the boundary (the caller maps it
into its serve error), but the variants keep the failure kinds distinct so the mutation gate can
assert on the fail-closed one.
Variants§
EmptyAccessKeyId
access_key_id is empty (a misconfigured source — refuse rather than mint a broken credential).
EmptySecret
The resolved secret_access_key is empty (an env:VAR="" or a boatramp: secret sealed as
empty bytes) — fail closed at startup rather than mint a static provider that fails SigV4
at request-time (403). Symmetric to Self::EmptyAccessKeyId.
BoatrampRefOnCluster(String)
A boatramp:<name> node-cred ref on the CLUSTER path — refused structurally (a scheme
check, not an incidental empty-store miss): the replicated control-plane KV that holds the
sealed store is not available at blob-build time on a cluster. Use env:<VAR> instead.
NoEnvelope
The secret_access_key is a boatramp:/env: sealed ref but no [secrets] envelope is
configured — fail closed (never a silent env fallback that would mask the misconfig).
MissingBoatrampSecret(String)
A boatramp: ref, but the sealed secret is not present in the store under the default project.
EnvRefNotPermitted(String)
An env:/bare host-env ref refused because the posture’s allow_env_secret_refs is off (the
config author’s env is the operator’s namespace — the same gate a guest env: ref hits).
EnvVarUnset(String)
An env:/bare host-env ref whose var is unset.
UnsupportedScheme(String)
A reserved-but-unimplemented scheme (a colon-bearing value whose scheme is not env/boatramp).
Backend(String)
A KV / envelope (unseal) backend failure — detail is logged, not surfaced to a client.
NotUtf8
A resolved secret that is not valid UTF-8 (an AWS secret access key is ASCII).
Trait Implementations§
Source§impl Debug for S3CredentialError
impl Debug for S3CredentialError
Source§impl Display for S3CredentialError
impl Display for S3CredentialError
impl Eq for S3CredentialError
Source§impl Error for S3CredentialError
impl Error for S3CredentialError
1.30.0 · Source§fn source(&self) -> Option<&(dyn Error + 'static)>
fn source(&self) -> Option<&(dyn Error + 'static)>
1.0.0 · Source§fn description(&self) -> &str
fn description(&self) -> &str
use the Display impl or to_string()
Source§impl PartialEq for S3CredentialError
impl PartialEq for S3CredentialError
impl StructuralPartialEq for S3CredentialError
Auto Trait Implementations§
impl Freeze for S3CredentialError
impl RefUnwindSafe for S3CredentialError
impl Send for S3CredentialError
impl Sync for S3CredentialError
impl Unpin for S3CredentialError
impl UnsafeUnpin for S3CredentialError
impl UnwindSafe for S3CredentialError
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more