Skip to main content

AcmeCfg

Struct AcmeCfg 

Source
pub struct AcmeCfg {
    pub enabled: bool,
    pub domains: Vec<String>,
    pub email: String,
    pub directory_url: String,
    pub cache_dir: String,
    pub accept_tos: bool,
    pub budget_enabled: bool,
}
Expand description

Automatic certificate management (ACME / Let’s Encrypt) via the HTTP-01 challenge. The obtained certificate is written to TlsCfg::cert_path/key_path and served by the TLS listener. Issuance runs at startup only when no certificate exists at cert_path; there is no automatic renewal yet (see docs/ROADMAP.md) — delete the cert/key files and restart to re-issue.

Fields§

§enabled: bool

Obtain and renew a certificate automatically over ACME HTTP-01 instead of reading cert_path/key_path from disk. Requires port 80 to be reachable from the CA.

§domains: Vec<String>

Domains to request a certificate for (the first is the primary CN).

§email: String

Contact email for the ACME account (registration + expiry notices).

§directory_url: String

ACME directory URL. Defaults to Let’s Encrypt staging so a misconfiguration can’t burn the strict production rate limits; switch to production explicitly.

§cache_dir: String

Directory for the cached ACME account key (so renewals reuse the same account).

§accept_tos: bool

You must set this to true to signify acceptance of the ACME provider’s Terms of Service; EdgeGuard refuses to register otherwise.

§budget_enabled: bool

Refuse to send an order the CA’s published rate limits would reject, instead of finding out by being refused. On by default. See crate::acme_budget.

Only recognised CAs are budgeted — an unknown directory URL gets no profile and no guard, because holding a private CA to Let’s Encrypt’s numbers would refuse orders it would have accepted. Turn this off only if the budget is wrong about your CA and you would rather have the CA be the one that says no.

This governs this edge’s own ledger only. In managed mode the control plane still issues the fleet-wide issuance lease, because limits the CA applies across every edge under one registered domain are not this edge’s to opt out of — one box turning this off would otherwise be able to spend the whole fleet’s weekly allowance.

Trait Implementations§

Source§

impl Clone for AcmeCfg

Source§

fn clone(&self) -> AcmeCfg

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for AcmeCfg

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for AcmeCfg

Source§

fn default() -> Self

Returns the “default value” for a type. Read more
Source§

impl<'de> Deserialize<'de> for AcmeCfg

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> FromRef<T> for T
where T: Clone,

Source§

fn from_ref(input: &T) -> T

Converts to this type from a reference to the input type.
Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more