#[non_exhaustive]pub enum PlatformIdentity {
KubernetesServiceAccount {
namespace: String,
service_account: String,
pod: Option<String>,
},
Spiffe {
trust_domain: String,
name: String,
version: String,
},
Shared {
name: String,
},
OutboundMarker,
Unknown,
}Expand description
Method-agnostic platform identity produced by validating an
InternalCredential.
The variant reflects which credential authenticated the caller; platform
handlers consume a PlatformSecurityContext without branching on it. New
authentication methods add a variant — hence #[non_exhaustive] — without
changing PlatformSecurityContext’s shape.
Variants (Non-exhaustive)§
This enum is marked as non-exhaustive
KubernetesServiceAccount
First phase: a validated K8s ServiceAccount (from a projected SA token
verified via the TokenReview API).
Fields
Spiffe
Next phase: an mTLS + SPIFFE workload identity parsed from the X.509 SAN
(spiffe://<trust_domain>/gear/<name>/<version>). Reserved — not
populated in the first phase.
Fields
A caller authenticated by a pre-shared secret (dev / single-node
profiles). Not tied to any deployment substrate: it exists so the
platform plane can be exercised end-to-end without Kubernetes. The
name is a configured label used for workload-policy decisions.
OutboundMarker
A credential-free outbound plane marker, not an authenticated caller.
Produced only by PlatformSecurityContext::outbound_marker, so gear
code can satisfy a platform-plane signature without possessing a real
identity. It is never the result of validating anything, and must never
authorize anything.
It has its own variant because it used to share Self::Unknown,
leaving one value meaning two unrelated things — a locally minted marker
and a peer identity this build does not recognise — with peer_name()
answering "<unknown>" for both.
Unknown
Catch-all for variants introduced in a newer library version.
Produced only by serde::Deserialize when the "type" field holds an
unrecognised value; peer_name returns "<unknown>" for it.
It no longer doubles as the outbound marker — see
Self::OutboundMarker.
Implementations§
Source§impl PlatformIdentity
impl PlatformIdentity
Sourcepub fn peer_name(&self) -> &str
pub fn peer_name(&self) -> &str
The caller’s name, distilled for workload-policy decisions.
For a PlatformIdentity::KubernetesServiceAccount this is the ServiceAccount
name; for PlatformIdentity::Spiffe it is the workload (gear) component
of the SPIFFE ID.
Trait Implementations§
Source§impl Clone for PlatformIdentity
impl Clone for PlatformIdentity
Source§fn clone(&self) -> PlatformIdentity
fn clone(&self) -> PlatformIdentity
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more