ferryman_edge_core/lib.rs
1//! ferryman-edge-core — programmable mTLS L7 proxy primitives.
2//!
3//! Extends `ferryman-core` (P2) with:
4//! - `tls` : rustls 0.23 + aws-lc-rs mTLS server config + `ReloadingTls`
5//! that swaps cert/key/ca on `SIGUSR1` without dropping live
6//! connections.
7//! - `jwt` : `JwtVerifier` with a moka LRU cache (default 10k entries,
8//! 5 min TTL) keyed by the raw token string.
9//! - `ratelimit`: keyed `governor` GCRA limiter; allocation-free on the
10//! hot path.
11//! - `route` : the P2 routing table (Upstream, RouteTable, SharedTable).
12//! Copied verbatim — P4 layers atop, does not modify.
13//! - `health` : active probe loop (copied from P2).
14//! - `config` : TOML schema extended with `tls`, `jwks_path`, per-tenant
15//! rate-limit caps.
16//!
17//! The server crate composes these behind a `tokio-rustls` acceptor and a
18//! hyper service.
19
20pub mod config;
21pub mod health;
22pub mod jwt;
23pub mod ratelimit;
24pub mod route;
25pub mod tls;
26
27pub use config::{build_table, ConfigToml, JwtToml, RouteToml, TlsToml};
28pub use health::health_loop;
29pub use jwt::{Claims, JwtVerifier};
30pub use ratelimit::{build_limiter, check, spawn_gc, Limiter};
31pub use route::{RouteTable, SharedTable, Upstream};
32pub use tls::{build_mtls_config, ReloadingTls};