Skip to main content

InternalAuthConfig

Enum InternalAuthConfig 

Source
pub enum InternalAuthConfig {
    SharedSecret {
        secret: SecretString,
        peer_name: String,
    },
    Kube {
        audiences: Vec<String>,
        token_path: Option<PathBuf>,
    },
}
Expand description

Platform-plane authentication provider selection.

Serialized with an internal provider tag, e.g.

internal_auth:
  provider: shared_secret
  secret: "dev-internal-token"
  peer_name: "hello"

or

internal_auth:
  provider: kube
  audiences: ["toolkit-internal"]
  token_path: /var/run/secrets/tokens/toolkit-internal

Variants§

§

SharedSecret

A single pre-shared secret (dev / single-node). See the module docs.

Fields

§secret: SecretString

The shared token accepted (inbound) and attached (outbound).

A SecretString rather than a String so redaction is structural: it zeroizes on drop and renders as [REDACTED] in any {:?} sink, instead of depending on the hand-written Debug and Serialize impls below staying correct as fields are added.

§peer_name: String

Caller label assigned to validated peers (inbound side only).

§

Kube

A projected Kubernetes ServiceAccount token (Profile 3).

Fields

§audiences: Vec<String>

Expected token audiences for TokenReview (inbound).

Required, and must not be empty. An empty list disables audience binding twice over in toolkit-k8s-auth: no audience is sent to the API server, and the client-side comparison against the response is skipped. Any ServiceAccount token the API server accepts — from any workload in the cluster, issued for any audience — would then authenticate as a platform peer.

It used to default to empty, so a config that simply omitted the field got that silently.

§token_path: Option<PathBuf>

Projected-token path to read + rotate for outbound calls. When absent, no outbound credential is attached (inbound-only).

Implementations§

Source§

impl InternalAuthConfig

Source

pub fn build_authenticator( &self, ) -> Result<BuiltAuthenticator, InvalidInternalAuth>

Build the inbound validator when it can be constructed without a heavier backend.

§Errors

Returns InvalidInternalAuth::SharedSecret when the configured shared secret is unusable — empty, or the redaction placeholder from a serialized config. Returns InvalidInternalAuth::EmptyKubeAudiences when provider: kube has no configured audiences.

Source

pub fn shared_secret(&self) -> Option<SecretString>

The static outbound credential for the shared-secret provider, if any.

Source

pub fn is_kube(&self) -> bool

Whether this config selects the Kubernetes provider.

Source

pub fn kube_audiences(&self) -> Option<&[String]>

The configured TokenReview audiences for the Kubernetes provider.

Source

pub fn kube_token_path(&self) -> Option<&Path>

The projected-token path for the Kubernetes provider’s outbound credential, if configured.

Trait Implementations§

Source§

impl Clone for InternalAuthConfig

Source§

fn clone(&self) -> InternalAuthConfig

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for InternalAuthConfig

Manual Debug that never renders the shared secret. The derived impl would print secret verbatim, leaking the platform-plane credential into any {:?} sink (config tracing, panic messages, error context). All other fields — including peer_name and the Kube variant — are shown as-is.

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<'de> Deserialize<'de> for InternalAuthConfig

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl Serialize for InternalAuthConfig

Manual Serialize that never emits the shared secret in plaintext.

A derived Serialize would write secret verbatim, leaking the platform-plane credential whenever a containing config is serialized — most notably AppConfig::to_yaml behind --print-config. Instead the secret is replaced with a <redacted> placeholder; every other field (and the internally-tagged provider shape) is preserved so the output still round- trips structurally.

This is safe because the config is only ever deserialized to obtain the real secret; serialization is used for diagnostics, never to transmit the credential.

Source§

fn serialize<S: Serializer>(&self, serializer: S) -> Result<S::Ok, S::Error>

Serialize this value into the given Serde serializer. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more