pub struct ServiceAccountConfig {
pub secret_env: String,
pub roles: Vec<String>,
pub scopes: Vec<String>,
pub tenant: Option<String>,
pub static_enriched: HashMap<String, Value>,
}Expand description
A [service_accounts.<name>] config block. Holds only non-secret material — the
secret plaintext lives in the environment variable named by secret_env.
Fields§
§secret_env: StringName of the environment variable holding the plaintext bearer secret. The secret is never inlined; the config holds only this name.
roles: Vec<String>The run_as ceiling — roles granted. Empty ⇒ no role authority.
scopes: Vec<String>The run_as ceiling — scopes granted. Empty ⇒ no scope authority.
tenant: Option<String>Optional tenant pin. Omitted ⇒ global / NULL tenant.
static_enriched: HashMap<String, Value>Optional server-injected fraiseql.enriched.* fields, the only sanctioned
deviation from uniform enrichment (ADR-0016 decision 6 / ADR-0018 decision 5) —
for a daemon with no natural actor row. Server-injected, never token-asserted.
Trait Implementations§
Source§impl Clone for ServiceAccountConfig
impl Clone for ServiceAccountConfig
Source§fn clone(&self) -> ServiceAccountConfig
fn clone(&self) -> ServiceAccountConfig
Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
Performs copy-assignment from
source. Read moreSource§impl Debug for ServiceAccountConfig
impl Debug for ServiceAccountConfig
Source§impl<'de> Deserialize<'de> for ServiceAccountConfig
impl<'de> Deserialize<'de> for ServiceAccountConfig
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
Deserialize this value from the given Serde deserializer. Read more
Auto Trait Implementations§
impl Freeze for ServiceAccountConfig
impl RefUnwindSafe for ServiceAccountConfig
impl Send for ServiceAccountConfig
impl Sync for ServiceAccountConfig
impl Unpin for ServiceAccountConfig
impl UnsafeUnpin for ServiceAccountConfig
impl UnwindSafe for ServiceAccountConfig
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more