tollgate-store
The storage contract of Tollgate,
and MemoryStore, the reference implementation of it.
Narrow traits separate the data plane from lifecycle authority:
LeaseAllocatoratomically debits an account's balance into fenced, TTL-bounded leases, and settles them by release or expiry reclaim.SnapshotSourcefetches compiled account snapshots and subscribes to pushes.UsageSinkingests usage events in idempotent, fencing-checked batches.KeySourceserves validated, revisioned pages of active credential digests.AdminStoreandKeyDirectoryhold administrative and credential-lifecycle authority, which instances do not need.
Every method takes now as an argument: a store never reads a clock, so
backends are deterministic under test and the clock decision lives in one
place.
The reference implementation
MemoryStore proves the traits are not shaped like any particular database,
runs the correctness suite without infrastructure, and documents the
settlement rules a real backend must reproduce.
tollgate-store-postgres
reproduces them exactly, and a mirrored test suite holds the two to one
contract.
use ;
use ;
use ;
#
# async
Features
wire: the HTTP wire contract shared bytollgate-serverandtollgate-client's HTTP transport. Off by default, so store-only consumers skipserde.
Contract
The settlement rules and the conservation equation are specified in
INVARIANTS.md;
docs/USAGE_ACCOUNTING.md
covers batch rejection semantics, and
docs/LEASE_OWNERSHIP.md
lease ownership.
License
MIT OR Apache-2.0, at your option. Tollgate is a product of MorphIQ Labs, a trade name of Prophetizo LLC.