#[non_exhaustive]pub enum InternalCredential {
None,
BootstrapToken(SecretString),
KubeServiceAccountToken {
token_path: PathBuf,
audience: String,
},
MtlsIdentity {
cert: PathBuf,
key: PathBuf,
ca: PathBuf,
},
}Expand description
The credential a gear attaches to its system (platform-plane) calls.
Selected by deployment profile at the bootstrap layer. The variant set is
frozen now to keep the API stable across phases, but only
InternalCredential::None (Profile 1) and
InternalCredential::KubeServiceAccountToken (Profile 3) are wired in the
first phase. InternalCredential::BootstrapToken (Profile 2) and
InternalCredential::MtlsIdentity (mTLS end state) are struct-only —
their validation/wiring is deferred to a later phase.
Variants (Non-exhaustive)§
This enum is marked as non-exhaustive
None
Profile 1 (in-process): no credential — the process boundary is the trust root, so no header/metadata is attached.
BootstrapToken(SecretString)
Profile 2 (single-node): an ephemeral bootstrap token minted by the Platform Host. Struct-only in the first phase; validation deferred to P2.
KubeServiceAccountToken
Profile 3 (K8s): a projected ServiceAccount JWT (auto-mounted,
auto-rotated). token_path is the projected-volume path; audience is
the expected token audience (e.g. toolkit-internal).
Fields
MtlsIdentity
End state (and Profile 2 multi-node): an mTLS client identity. Struct-only here; mTLS validation/wiring is deferred to a later phase.
Trait Implementations§
Source§impl Clone for InternalCredential
impl Clone for InternalCredential
Source§fn clone(&self) -> InternalCredential
fn clone(&self) -> InternalCredential
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more