Skip to main content

ferryman_edge_core/
lib.rs

1//! ferryman-edge-core — programmable mTLS L7 proxy primitives.
2//!
3//! Extends `ferryman-core` (P2) with:
4//!   - `tls`    : rustls 0.23 + aws-lc-rs mTLS server config + `ReloadingTls`
5//!     that swaps cert/key/ca on `SIGUSR1` without dropping live
6//!     connections.
7//!   - `jwt`    : `JwtVerifier` with a moka LRU cache (default 10k entries,
8//!     5 min TTL) keyed by the raw token string.
9//!   - `ratelimit`: keyed `governor` GCRA limiter; allocation-free on the
10//!     hot path.
11//!   - `route`  : the P2 routing table (Upstream, RouteTable, SharedTable).
12//!     Copied verbatim — P4 layers atop, does not modify.
13//!   - `health` : active probe loop (copied from P2).
14//!   - `config` : TOML schema extended with `tls`, `jwks_path`, per-tenant
15//!     rate-limit caps.
16//!
17//! The server crate composes these behind a `tokio-rustls` acceptor and a
18//! hyper service.
19
20pub mod config;
21pub mod health;
22pub mod jwt;
23pub mod ratelimit;
24pub mod route;
25pub mod tls;
26
27pub use config::{build_table, ConfigToml, JwtToml, RouteToml, TlsToml};
28pub use health::health_loop;
29pub use jwt::{Claims, JwtVerifier};
30pub use ratelimit::{build_limiter, check, spawn_gc, Limiter};
31pub use route::{RouteTable, SharedTable, Upstream};
32pub use tls::{build_mtls_config, ReloadingTls};