Expand description
Finding the object stores this machine can already read, and listing their contents, so buckets can be browsed like local directories. Two rules:
Never list a provider datui cannot then read. Discovery looks only at the
credentials object_store will use to open a file (not, say, gcloud’s own),
so every listed bucket opens.
Nothing here runs on the drawing thread. Every network function is async and
driven from a worker, as remote filesystem roots are.
Structs§
- Environment
- Everything discovery may look at, in one place so a test can supply it;
Environment::currentis the real one. - Instance
Identity - Which clouds’ VM or platform identity may be used. Finding one queries a metadata
service that can hang, so only when configured or signaled by the platform
(
K_SERVICEon Cloud Run/Functions;IDENTITY_ENDPOINTorMSI_ENDPOINTon Azure App Service, Functions, Container Apps). ECS and EKS are found by their own variables. - Level
- What one level of a place listed.
- Listed
- A source’s first level as home lists it: buckets for S3 and Google, storage accounts for Azure.
- Provider
- An object store datui believes it can read, and why it believes that.
- Watch
- How a listing is watched while it runs.
Constants§
- MAX_
LEVEL_ ROWS - The most rows one bucket level lists, as for a local directory; past it the listing stops and says so (141,000 partitions would be 141 requests held in memory).
Traits§
- Store
- An object store that also lists a page at a time: every store datui builds is both.
Functions§
- adc_
path - The application default credentials file where
object_storereads it (%APPDATA%\gcloud\on Windows,$HOME/.config/gcloud/elsewhere), kept in step so discovery agrees with opening. - detect
- Object stores this machine can read, in display order. Empty is normal without cloud credentials; nothing prompts, installs or logs in.
- gcs_
next_ page_ token - The
pageTokenfor the next page of a bucket list, when the response has one. - instance_
identity - is_
marker - A key that is not data to open: job receipts and folder markers. Narrower than
crate::home::discover::is_bookkeeping(which decides a directory’s kind): a leading_is not enough here, since_manifest.parquetmay be worth opening. - is_
refusal - Whether an error is the service refusing the request, rather than failing to answer.
- list_
account - The containers of one account in an Azure source, as rows to step into.
- list_
buckets - Every bucket the provider’s credentials can see. Per provider, since
object_storeis bucket-scoped; both borrow its credential handling (no new crypto), so listing and opening use the same credentials. - list_
first_ level - Everything at the top of a source.
- list_
objects - One level of a bucket or prefix as home rows, up to
MAX_LEVEL_ROWS. A delimited listing: a million objects under a hundred prefixes is one request, a hundred rows. - list_
objects_ watched list_objectsa page at a time:watchsees rows as they come and can stop between pages.- look_
at_ listing - The kind and holdings of a listing by
crate::home::discover::classify, the local rule; a prefix’s row label comes from the holdings. - narrowing_
prefix - The server-side prefix a home filter can ask a cut-short level for, if any. The
filter is fuzzy and the prefix literal, so it asks for the names’ shared part up
to their last separator (
STATION=,year=) plus the filter, in the names’ case; a filter already spelling the shared part is taken as typed. - object_
path - The object_store path for a key as stored.
Path::frompercent-encodes%, so100%.csv.gzbecame100%25.csv.gzand 404’d; existing keys are parsed as is, unless they cannot be a path. - parse_
gcs_ buckets - Bucket names from a GCS
storage/v1/bresponse. Tolerant: noitemsmeans no buckets, and an entry without a usablenameis skipped. - parse_
s3_ buckets - Bucket names from an S3
ListBucketsresponse. A custom endpoint may be hostile, so quick-xml parses it with a depth cap no legitimate response reaches. - peek_
kind - What a cloud directory holds, from the first page of a delimited listing:
Hiveforkey=valuechildren,MultiFilefor Parquet files, elseDirectory. One request; no object is read. - probe_
unsigned - Whether
resolved’s place reads unsigned:Some(true)if an unsigned request succeeds,Some(false)if refused,Noneotherwise (no network, missing object, custom endpoint). One request: aHEAD, or a one-key listing. - s3_
bucket_ region - Where S3 keeps
bucket, from thex-amz-bucket-regionheader sent unauthenticated whatever the status; once per bucket per session,Noneif unsaid. - s3_
builder - The one S3 builder, so listing and opening authenticate identically (separate
builders once let the listing drop the configured endpoint and keys).
settingsare one source’s (cloud_sources::resolve). Addressed by bucket name: onlys3://bucket/keyURLs. - split_
bucket_ url - Split a
gs://ors3://URL into bucket and prefix (no leading or trailing slash, empty for the root, asobject_storewants). A source id (s3://<id>@bucket) is dropped. - store
- The store for a resolved place, signed as the resolver decided, and the key inside it.
- unreadable_
google_ login - The credential type of a Google login
object_storecannot read (workload identity federation, an impersonated service account), when the environment or ADC file has one.
Type Aliases§
- Progress
- What a listing hands each page of rows as it comes.