Skip to main content

Provisioner

Struct Provisioner 

Source
pub struct Provisioner { /* private fields */ }

Implementations§

Source§

impl Provisioner

Source

pub fn new(setup_token: String, account_id: String, zone_id: String) -> Self

Source

pub async fn verify(&self) -> Result<String>

Confirms the token works and returns its id, which is also the S3 access key id if this token is ever used against R2 directly.

Source

pub async fn ensure_app_cache( &self, app_hostname: &str, replaced_app_hostname: Option<&str>, mint_writing_token: bool, ) -> Result<()>

Source

pub async fn ensure_app_dns_record( &self, app_hostname: &str, origin_hostname: &str, replaced_app_hostname: Option<&str>, mint_writing_token: bool, ) -> Result<()>

Points the app hostname at the worker fleet and takes the record the project used to answer on back out of the zone.

The record is proxied. An Origin CA certificate is trusted by Cloudflare’s edge and by nothing else, so a grey-clouded record reaches the fleet and fails the handshake.

Removing the replaced record is not tidying: it points at fn0 by name, and any project that registers that hostname next inherits the traffic.

Source

pub async fn run_managed( &self, project_id: &str, app_origin: &str, app_hostname: &str, ) -> Result<(ProvisionedResources, ConnectCredentials, MintedCredentialIds)>

The convenient path: one API Tokens -> Edit token, everything else minted here and the provisioning token revoked on the way out.

Source

pub async fn run_manual( &self, project_id: &str, app_origin: &str, app_hostname: &str, ) -> Result<ProvisionedResources>

The careful path: provision with the token as given, mint nothing. The caller’s token is expected to be unable to create tokens, which is the whole reason to choose this.

Source

pub async fn revoke_minted_credentials(&self, ids: &MintedCredentialIds)

Best effort, and reported rather than swallowed: unlike the provisioning token these carry no expiry, so one left behind stays until the user finds it.

Source

pub async fn issue_origin_certificate( &self, hostname: &str, mint_signing_token: bool, ) -> Result<IssuedCertificate>

Signs an origin certificate for hostname through the zone owner’s own Origin CA.

The key pair is generated here and the private key is sent to fn0 alongside the certificate, because the worker has to present it during the TLS handshake. Nothing that can sign another one is: the token that did the signing is revoked before this returns.

Source

pub async fn put_app_cors( &self, project_id: &str, app_origin: &str, mint_writing_token: bool, ) -> Result<()>

Repoints the buckets’ CORS at a domain the project has moved to. Provisioning writes the same rules for the domain the project starts with; this is how they follow it afterwards.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more