pub struct Provisioner { /* private fields */ }Implementations§
Source§impl Provisioner
impl Provisioner
pub fn new(setup_token: String, account_id: String, zone_id: String) -> Self
Sourcepub async fn verify(&self) -> Result<String>
pub async fn verify(&self) -> Result<String>
Confirms the token works and returns its id, which is also the S3 access key id if this token is ever used against R2 directly.
pub async fn ensure_app_cache( &self, app_hostname: &str, replaced_app_hostname: Option<&str>, mint_writing_token: bool, ) -> Result<()>
Sourcepub async fn ensure_app_dns_record(
&self,
app_hostname: &str,
origin_hostname: &str,
replaced_app_hostname: Option<&str>,
mint_writing_token: bool,
) -> Result<()>
pub async fn ensure_app_dns_record( &self, app_hostname: &str, origin_hostname: &str, replaced_app_hostname: Option<&str>, mint_writing_token: bool, ) -> Result<()>
Points the app hostname at the worker fleet and takes the record the project used to answer on back out of the zone.
The record is proxied. An Origin CA certificate is trusted by Cloudflare’s edge and by nothing else, so a grey-clouded record reaches the fleet and fails the handshake.
Removing the replaced record is not tidying: it points at fn0 by name, and any project that registers that hostname next inherits the traffic.
Sourcepub async fn run_managed(
&self,
project_id: &str,
app_origin: &str,
app_hostname: &str,
) -> Result<(ProvisionedResources, ConnectCredentials, MintedCredentialIds)>
pub async fn run_managed( &self, project_id: &str, app_origin: &str, app_hostname: &str, ) -> Result<(ProvisionedResources, ConnectCredentials, MintedCredentialIds)>
The convenient path: one API Tokens -> Edit token, everything else
minted here and the provisioning token revoked on the way out.
Sourcepub async fn run_manual(
&self,
project_id: &str,
app_origin: &str,
app_hostname: &str,
) -> Result<ProvisionedResources>
pub async fn run_manual( &self, project_id: &str, app_origin: &str, app_hostname: &str, ) -> Result<ProvisionedResources>
The careful path: provision with the token as given, mint nothing. The caller’s token is expected to be unable to create tokens, which is the whole reason to choose this.
Sourcepub async fn revoke_minted_credentials(&self, ids: &MintedCredentialIds)
pub async fn revoke_minted_credentials(&self, ids: &MintedCredentialIds)
Best effort, and reported rather than swallowed: unlike the provisioning token these carry no expiry, so one left behind stays until the user finds it.
Sourcepub async fn issue_origin_certificate(
&self,
hostname: &str,
mint_signing_token: bool,
) -> Result<IssuedCertificate>
pub async fn issue_origin_certificate( &self, hostname: &str, mint_signing_token: bool, ) -> Result<IssuedCertificate>
Signs an origin certificate for hostname through the zone owner’s own
Origin CA.
The key pair is generated here and the private key is sent to fn0 alongside the certificate, because the worker has to present it during the TLS handshake. Nothing that can sign another one is: the token that did the signing is revoked before this returns.