acme-proxy 0.5.0

An ACME (RFC 8555) server that issues from a local CA, relays to an upstream CA, or delegates to a script
Documentation
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
//! The `phpipam` IPAM backend: what phpIPAM associates with an address.
//!
//! The second inventory, and the one that shows the [`Ipam`] seam is not NetBox
//! with extra steps. It answers the same question by a different route, with a
//! different auth scheme, a different response envelope and a different idea of
//! what "no such address" looks like on the wire.
//!
//! ## What phpIPAM is asked
//!
//! One lookup always happens:
//! `GET /api/<app_id>/addresses/search/<client ip>/`. What it returns permits
//! names two ways — the address's `hostname` ([`Source::DnsName`], the direct
//! analogue of NetBox's `dns_name`) and a custom column on it
//! ([`Source::CustomField`]).
//!
//! One more is conditional: [`Source::Device`] follows the address's `deviceId`
//! to `GET /api/<app_id>/devices/<id>/` and reads the same column there. Like
//! NetBox's, it is a **fallback and not a union** — a value on the address is
//! the more specific statement.
//!
//! [`Source::Vip`] and [`Source::Fhrp`] are **refused by name at startup**:
//! phpIPAM records no address roles and no redundancy groups, so there is
//! nothing here to read. Ignoring them silently would leave an operator
//! believing a check runs that never runs.
//!
//! ## A 404 is an answer, not a failure
//!
//! The one place phpIPAM's wire behaviour differs in a way this code has to
//! know about. NetBox answers an unknown address with `200` and an empty result
//! list; phpIPAM answers `404` with `{"code":404,"message":"No addresses
//! found"}`. Reading that as a transport failure would turn every request from
//! an unrecorded machine into a retryable 500 instead of the refusal it is —
//! which is why [`JsonApiError`](crate::ipam::http::JsonApiError) carries the
//! status at all.
//!
//! ## Multi-valued custom fields
//!
//! A phpIPAM custom field is a plain text column, so several names are written
//! as one comma-separated string and split here. Hardcoded rather than
//! configurable: a comma is not legal in a DNS name, so there is no estate the
//! separator could need to differ for.

pub mod client;

use std::net::IpAddr;
use std::sync::Arc;

use async_trait::async_trait;
use serde_json::{Map, Value};
use tracing::{info, warn};

use super::{AddressNames, Ipam, IpamError, Source, Sources, field_values, parse_sources};
use crate::config::PhpIpamConfig;

/// One phpIPAM address object, reduced to what this backend reads.
#[derive(Debug, Clone, Default, PartialEq, Eq)]
pub struct PhpIpamAddress {
    /// The address's `hostname`, empty when unset.
    pub hostname: String,
    /// Every column phpIPAM returned, custom ones included — they are plain
    /// top-level members rather than a nested object as in NetBox.
    pub fields: Map<String, Value>,
    /// The device this address is assigned to, when there is one.
    pub device_id: Option<u64>,
}

/// The phpIPAM queries this backend makes.
///
/// A trait so the policy above can be tested without a phpIPAM, the same seam
/// [`NetboxApi`](crate::ipam::netbox::NetboxApi) is. `Ok(None)` from
/// [`Self::search`] is the 404 case: an answer, not a failure.
#[async_trait]
pub trait PhpIpamApi: Send + Sync {
    /// The address objects phpIPAM holds for this address, or `None` when it
    /// holds no record of it at all.
    async fn search(&self, ip: IpAddr) -> Result<Option<Vec<PhpIpamAddress>>, String>;

    /// One device's columns.
    async fn device(&self, id: u64) -> Result<Map<String, Value>, String>;
}

/// Reports which names phpIPAM associates with an address.
pub struct PhpIpamBackend {
    api: Arc<dyn PhpIpamApi>,
    custom_field: String,
    sources: Sources,
}

impl std::fmt::Debug for PhpIpamBackend {
    /// `dyn PhpIpamApi` is not `Debug`; the policy is the interesting part.
    fn fmt(&self, formatter: &mut std::fmt::Formatter<'_>) -> std::fmt::Result {
        formatter
            .debug_struct("PhpIpamBackend")
            .field("custom_field", &self.custom_field)
            .field("sources", &self.sources)
            .finish_non_exhaustive()
    }
}

/// phpIPAM records no roles and no redundancy groups, so `vip` and `fhrp` are
/// absent here and refused by name.
const SUPPORTED: &[Source] = &[Source::DnsName, Source::CustomField, Source::Device];

impl PhpIpamBackend {
    /// Builds the real phpIPAM client, then delegates. Contacts nothing.
    pub fn from_config(
        cfg: &PhpIpamConfig,
        outbound: crate::http_client::Outbound,
    ) -> anyhow::Result<Self> {
        let api = Arc::new(client::PhpIpamClient::new(cfg, outbound)?);
        let backend = Self::with_api(cfg, api)?;

        info!(
            event = "ipam_phpipam_loaded",
            outcome = "success",
            backend_url = %cfg.url,
            app_id = %cfg.app_id,
            custom_field = %cfg.custom_field,
            sources = ?backend.sources,
        );

        // Unconditional and deliberately not once-only, the
        // `ipam_netbox_tls_verification_disabled` treatment.
        if cfg.insecure_skip_verify {
            warn!(
                event = "ipam_phpipam_tls_verification_disabled",
                outcome = "advisory",
                backend_url = %cfg.url,
                "ipam.phpipam.insecure_skip_verify is on: phpIPAM's TLS certificate is not \
                 verified, so the answers this server trusts could come from anyone able to \
                 intercept the connection (ipam.phpipam.ca_cert_path is ignored while it is set)"
            );
        }

        Ok(backend)
    }

    /// Same, against a caller-supplied API. Used by tests.
    pub fn with_api(cfg: &PhpIpamConfig, api: Arc<dyn PhpIpamApi>) -> anyhow::Result<Self> {
        let sources = parse_sources("phpIPAM", "ipam.phpipam.sources", &cfg.sources, SUPPORTED)?;

        if sources.contains(&Source::CustomField) || sources.contains(&Source::Device) {
            anyhow::ensure!(
                !cfg.custom_field.trim().is_empty(),
                "ipam.phpipam.custom_field is empty while ipam.phpipam.sources names \
                 `custom_field` or `device`; name the phpIPAM column holding the permitted \
                 names (default `custom_acme_domains`)"
            );
        }

        Ok(Self {
            api,
            custom_field: cfg.custom_field.clone(),
            sources,
        })
    }

    /// The custom column's entries, split on commas.
    ///
    /// Goes through the shared [`field_values`] first, so a phpIPAM that ever
    /// starts returning a JSON array is read the same way NetBox's is; the
    /// split is what a text column needs on top of that.
    fn column_values(&self, fields: &Map<String, Value>, source: &str) -> Vec<String> {
        field_values(fields, &self.custom_field, "phpIPAM", source)
            .iter()
            .flat_map(|value| value.split(','))
            .map(str::trim)
            .filter(|name| !name.is_empty())
            .map(str::to_string)
            .collect()
    }

    /// Adds one address object's own names, and reports whether its custom
    /// column said anything — which is what decides the device fallback.
    fn add_object_names(
        &self,
        names: &mut AddressNames,
        fields: &Map<String, Value>,
        hostname: &str,
        source: &str,
    ) -> bool {
        if self.sources.contains(&Source::DnsName) {
            names.insert(hostname);
        }

        if !self.sources.contains(&Source::CustomField) {
            return false;
        }

        let values = self.column_values(fields, source);
        let answered = !values.is_empty();
        for value in values {
            names.insert(&value);
        }
        answered
    }
}

#[async_trait]
impl Ipam for PhpIpamBackend {
    fn name(&self) -> &'static str {
        "phpIPAM"
    }

    async fn names_for(&self, client_ip: IpAddr) -> Result<AddressNames, IpamError> {
        let found = self.api.search(client_ip).await.map_err(|error| {
            IpamError(format!("phpIPAM lookup for {client_ip} failed: {error}"))
        })?;

        // `None` is phpIPAM's 404 — a fact about the address, not a failure to
        // look it up. An empty list means the same thing and is treated alike.
        let Some(objects) = found.filter(|objects| !objects.is_empty()) else {
            return Ok(AddressNames::Unknown);
        };

        let mut names = AddressNames::known();
        let mut custom_field_answered = false;
        let mut device_id = None;

        for object in &objects {
            custom_field_answered |=
                self.add_object_names(&mut names, &object.fields, &object.hostname, "address");
            if device_id.is_none() {
                device_id = object.device_id;
            }
        }

        // A fallback: skipped entirely when the address spoke for itself. With
        // `custom_field` not among the sources nothing was read from the
        // address, so there is nothing to fall back *from* and the device's
        // list always applies.
        if let Some(id) = device_id
            && self.sources.contains(&Source::Device)
            && !custom_field_answered
        {
            let fields = self.api.device(id).await.map_err(|error| {
                IpamError(format!(
                    "phpIPAM lookup of device {id} for {client_ip} failed: {error}"
                ))
            })?;
            for value in self.column_values(&fields, "device") {
                names.insert(&value);
            }
        }

        Ok(names)
    }
}

#[cfg(test)]
mod tests {
    use super::*;
    use serde_json::json;
    use std::collections::HashMap;
    use std::sync::atomic::{AtomicUsize, Ordering};

    /// A phpIPAM answering from canned maps, never touching the network.
    #[derive(Default)]
    struct StubPhpIpam {
        addresses: HashMap<IpAddr, Vec<PhpIpamAddress>>,
        devices: HashMap<u64, Map<String, Value>>,
        error: Option<String>,
        device_calls: AtomicUsize,
    }

    impl StubPhpIpam {
        fn with_address(mut self, ip: &str, objects: Vec<PhpIpamAddress>) -> Self {
            self.addresses.insert(ip.parse().unwrap(), objects);
            self
        }

        fn with_device(mut self, id: u64, fields: Value) -> Self {
            self.devices.insert(id, fields.as_object().unwrap().clone());
            self
        }

        fn failing(error: &str) -> Self {
            Self {
                error: Some(error.to_string()),
                ..Self::default()
            }
        }
    }

    #[async_trait]
    impl PhpIpamApi for StubPhpIpam {
        async fn search(&self, ip: IpAddr) -> Result<Option<Vec<PhpIpamAddress>>, String> {
            if let Some(error) = &self.error {
                return Err(error.clone());
            }
            Ok(self.addresses.get(&ip).cloned())
        }

        async fn device(&self, id: u64) -> Result<Map<String, Value>, String> {
            self.device_calls.fetch_add(1, Ordering::SeqCst);
            Ok(self.devices.get(&id).cloned().unwrap_or_default())
        }
    }

    // ------------------------------------------------------------- fixtures

    fn with_hostname(hostname: &str) -> PhpIpamAddress {
        PhpIpamAddress {
            hostname: hostname.to_string(),
            ..PhpIpamAddress::default()
        }
    }

    fn with_column(value: Value) -> PhpIpamAddress {
        PhpIpamAddress {
            fields: json!({ "custom_acme_domains": value })
                .as_object()
                .unwrap()
                .clone(),
            ..PhpIpamAddress::default()
        }
    }

    fn on_device(id: u64) -> PhpIpamAddress {
        PhpIpamAddress {
            device_id: Some(id),
            ..PhpIpamAddress::default()
        }
    }

    fn config() -> PhpIpamConfig {
        PhpIpamConfig {
            url: "https://ipam.example.com".to_string(),
            token: "t0ken".to_string(),
            ..PhpIpamConfig::default()
        }
    }

    fn with_sources(sources: &[&str]) -> PhpIpamConfig {
        PhpIpamConfig {
            sources: sources.iter().map(|v| (*v).to_string()).collect(),
            ..config()
        }
    }

    fn backend(cfg: &PhpIpamConfig, api: StubPhpIpam) -> PhpIpamBackend {
        PhpIpamBackend::with_api(cfg, Arc::new(api)).unwrap()
    }

    async fn names(backend: &PhpIpamBackend) -> AddressNames {
        backend
            .names_for("10.0.0.5".parse().unwrap())
            .await
            .unwrap()
    }

    fn assert_permits(names: &AddressNames, name: &str) {
        assert!(
            names.names().contains(name),
            "{:?} lacks {name:?}",
            names.names()
        );
    }

    fn assert_refuses(names: &AddressNames, name: &str) {
        assert!(
            !names.names().contains(name),
            "{:?} unexpectedly holds {name:?}",
            names.names()
        );
    }

    // ------------------------------------------------------- the happy paths

    #[tokio::test]
    async fn the_hostname_permits_that_name() {
        let api = StubPhpIpam::default()
            .with_address("10.0.0.5", vec![with_hostname("host.example.com")]);

        assert_permits(&names(&backend(&config(), api)).await, "host.example.com");
    }

    #[tokio::test]
    async fn the_custom_column_permits_its_names() {
        let api = StubPhpIpam::default()
            .with_address("10.0.0.5", vec![with_column(json!("www.example.com"))]);

        assert_permits(&names(&backend(&config(), api)).await, "www.example.com");
    }

    /// A phpIPAM custom field is a text column, so several names arrive as one
    /// comma-separated string.
    #[tokio::test]
    async fn a_comma_separated_column_yields_several_names() {
        let api = StubPhpIpam::default().with_address(
            "10.0.0.5",
            vec![with_column(json!(
                "www.example.com, api.example.com ,,mail.example.com"
            ))],
        );

        let names = names(&backend(&config(), api)).await;
        assert_permits(&names, "www.example.com");
        assert_permits(&names, "api.example.com");
        assert_permits(&names, "mail.example.com");
        assert_eq!(names.names().len(), 3);
    }

    /// A phpIPAM that ever starts returning a JSON array is read the same way
    /// NetBox's is, because both go through the shared `field_values`.
    #[tokio::test]
    async fn a_column_holding_a_list_is_accepted_too() {
        let api = StubPhpIpam::default().with_address(
            "10.0.0.5",
            vec![with_column(json!(["a.example.com", "b.example.com"]))],
        );

        let names = names(&backend(&config(), api)).await;
        assert_permits(&names, "a.example.com");
        assert_permits(&names, "b.example.com");
    }

    #[tokio::test]
    async fn names_are_normalized_on_the_way_in() {
        let api = StubPhpIpam::default()
            .with_address("10.0.0.5", vec![with_hostname("Host.Example.COM.")]);

        assert_permits(&names(&backend(&config(), api)).await, "host.example.com");
    }

    // ------------------------------------------------------------- refusals

    /// The 404 case, which is the one shape phpIPAM does differently from
    /// NetBox: a fact about the address, never a retryable failure.
    #[tokio::test]
    async fn an_address_phpipam_does_not_know_is_unknown() {
        let names = names(&backend(&config(), StubPhpIpam::default())).await;
        assert_eq!(names, AddressNames::Unknown);
    }

    /// An empty list means the same thing as a 404 and is treated alike.
    #[tokio::test]
    async fn an_empty_result_is_also_unknown() {
        let api = StubPhpIpam::default().with_address("10.0.0.5", Vec::new());

        assert_eq!(names(&backend(&config(), api)).await, AddressNames::Unknown);
    }

    #[tokio::test]
    async fn a_recorded_address_with_no_names_is_known_and_empty() {
        let api = StubPhpIpam::default().with_address("10.0.0.5", vec![PhpIpamAddress::default()]);

        let names = names(&backend(&config(), api)).await;
        assert!(names.is_known());
        assert!(names.names().is_empty());
    }

    #[tokio::test]
    async fn a_failed_lookup_is_an_error_not_an_empty_answer() {
        let backend = backend(&config(), StubPhpIpam::failing("HTTP 500"));

        let error = backend
            .names_for("10.0.0.5".parse().unwrap())
            .await
            .unwrap_err();
        assert!(error.0.contains("HTTP 500"), "{error}");
    }

    // ------------------------------------------------------ the sources gate

    #[tokio::test]
    async fn dropping_dns_name_ignores_the_hostname() {
        let api = StubPhpIpam::default()
            .with_address("10.0.0.5", vec![with_hostname("host.example.com")]);
        let cfg = with_sources(&["custom_field", "device"]);

        assert_refuses(&names(&backend(&cfg, api)).await, "host.example.com");
    }

    #[tokio::test]
    async fn dropping_custom_field_ignores_the_column() {
        let api = StubPhpIpam::default().with_address(
            "10.0.0.5",
            vec![PhpIpamAddress {
                hostname: "host.example.com".to_string(),
                ..with_column(json!("www.example.com"))
            }],
        );
        let cfg = with_sources(&["dns_name"]);

        let names = names(&backend(&cfg, api)).await;
        assert_permits(&names, "host.example.com");
        assert_refuses(&names, "www.example.com");
    }

    // ------------------------------------------------------ device fallback

    #[tokio::test]
    async fn the_device_is_consulted_when_the_address_carries_no_names() {
        let api = StubPhpIpam::default()
            .with_address("10.0.0.5", vec![on_device(3)])
            .with_device(3, json!({ "custom_acme_domains": "machine.example.com" }));

        assert_permits(
            &names(&backend(&config(), api)).await,
            "machine.example.com",
        );
    }

    #[tokio::test]
    async fn the_device_is_not_consulted_when_the_address_answered() {
        let api = Arc::new(
            StubPhpIpam::default()
                .with_address(
                    "10.0.0.5",
                    vec![PhpIpamAddress {
                        device_id: Some(3),
                        ..with_column(json!("own.example.com"))
                    }],
                )
                .with_device(3, json!({ "custom_acme_domains": "machine.example.com" })),
        );
        let backend = PhpIpamBackend::with_api(&config(), api.clone()).unwrap();

        let names = names(&backend).await;
        assert_permits(&names, "own.example.com");
        assert_refuses(&names, "machine.example.com");
        assert_eq!(api.device_calls.load(Ordering::SeqCst), 0);
    }

    #[tokio::test]
    async fn a_hostname_alone_does_not_suppress_the_fallback() {
        let api = StubPhpIpam::default()
            .with_address(
                "10.0.0.5",
                vec![PhpIpamAddress {
                    hostname: "host.example.com".to_string(),
                    device_id: Some(3),
                    ..PhpIpamAddress::default()
                }],
            )
            .with_device(3, json!({ "custom_acme_domains": "machine.example.com" }));

        let names = names(&backend(&config(), api)).await;
        assert_permits(&names, "host.example.com");
        assert_permits(&names, "machine.example.com");
    }

    #[tokio::test]
    async fn dropping_device_never_consults_it() {
        let api = Arc::new(
            StubPhpIpam::default()
                .with_address("10.0.0.5", vec![on_device(3)])
                .with_device(3, json!({ "custom_acme_domains": "machine.example.com" })),
        );
        let cfg = with_sources(&["dns_name", "custom_field"]);
        let backend = PhpIpamBackend::with_api(&cfg, api.clone()).unwrap();

        assert_refuses(&names(&backend).await, "machine.example.com");
        assert_eq!(api.device_calls.load(Ordering::SeqCst), 0);
    }

    #[tokio::test]
    async fn an_address_on_no_device_makes_no_further_query() {
        let api = Arc::new(
            StubPhpIpam::default()
                .with_address("10.0.0.5", vec![with_hostname("host.example.com")]),
        );
        let backend = PhpIpamBackend::with_api(&config(), api.clone()).unwrap();

        assert_permits(&names(&backend).await, "host.example.com");
        assert_eq!(api.device_calls.load(Ordering::SeqCst), 0);
    }

    #[tokio::test]
    async fn a_failing_device_lookup_is_an_error() {
        struct DeviceFails;
        #[async_trait]
        impl PhpIpamApi for DeviceFails {
            async fn search(&self, _ip: IpAddr) -> Result<Option<Vec<PhpIpamAddress>>, String> {
                Ok(Some(vec![PhpIpamAddress {
                    device_id: Some(3),
                    ..PhpIpamAddress::default()
                }]))
            }
            async fn device(&self, _id: u64) -> Result<Map<String, Value>, String> {
                Err("HTTP 403".to_string())
            }
        }

        let backend = PhpIpamBackend::with_api(&config(), Arc::new(DeviceFails)).unwrap();
        let error = backend
            .names_for("10.0.0.5".parse().unwrap())
            .await
            .unwrap_err();
        assert!(error.0.contains("HTTP 403"), "{error}");
        assert!(error.0.contains("device 3"), "{error}");
    }

    // ------------------------------------------------------ startup + wiring

    /// The refusal that proves the trait is not just NetBox with extra steps:
    /// a source this product cannot answer for is named, not ignored.
    #[test]
    fn a_netbox_only_source_is_refused_by_name() {
        for source in ["vip", "fhrp"] {
            let cfg = with_sources(&["dns_name", source]);
            let error = PhpIpamBackend::with_api(&cfg, Arc::new(StubPhpIpam::default()))
                .unwrap_err()
                .to_string();
            assert!(
                error.contains(&format!("`{source}` is not a source phpIPAM has")),
                "{error}"
            );
        }
    }

    #[test]
    fn an_empty_custom_field_is_a_startup_error_when_something_reads_it() {
        let cfg = PhpIpamConfig {
            custom_field: "   ".to_string(),
            ..config()
        };
        let error = PhpIpamBackend::with_api(&cfg, Arc::new(StubPhpIpam::default()))
            .unwrap_err()
            .to_string();
        assert!(error.contains("ipam.phpipam.custom_field"), "{error}");
    }

    #[test]
    fn an_empty_custom_field_is_fine_when_nothing_reads_it() {
        let cfg = PhpIpamConfig {
            custom_field: String::new(),
            ..with_sources(&["dns_name"])
        };
        PhpIpamBackend::with_api(&cfg, Arc::new(StubPhpIpam::default()))
            .expect("no source reads the custom field");
    }

    #[test]
    fn an_empty_sources_list_is_a_startup_error() {
        let cfg = with_sources(&[]);
        let error = PhpIpamBackend::with_api(&cfg, Arc::new(StubPhpIpam::default()))
            .unwrap_err()
            .to_string();
        assert!(error.contains("ipam.phpipam.sources is empty"), "{error}");
    }

    #[test]
    fn reports_the_product_name() {
        assert_eq!(backend(&config(), StubPhpIpam::default()).name(), "phpIPAM");
    }

    #[test]
    fn the_debug_impl_shows_the_policy_without_the_api() {
        let rendered = format!("{:?}", backend(&config(), StubPhpIpam::default()));
        assert!(rendered.contains("custom_acme_domains"), "{rendered}");
        assert!(rendered.contains("Device"), "{rendered}");
    }
}