Skip to main content

TokenOp

Enum TokenOp 

Source
pub enum TokenOp {
    Issue {
        ttl_hours: i64,
        label: String,
        account: Option<String>,
        max_requests: Option<u64>,
        max_tokens: Option<u64>,
        rate_limit_per_minute: Option<u64>,
        admin: bool,
        github_repo: Vec<String>,
        target: AuthTarget,
    },
    Rotate {
        id: String,
        ttl_hours: i64,
        label: String,
        max_requests: Option<u64>,
        max_tokens: Option<u64>,
        rate_limit_per_minute: Option<u64>,
        account: Option<String>,
        target: AuthTarget,
    },
    List {
        json: bool,
        target: AuthTarget,
    },
    Revoke {
        id: String,
        target: AuthTarget,
    },
    Expire {
        id: String,
        target: AuthTarget,
    },
    Show {
        id: String,
        json: bool,
        target: AuthTarget,
    },
    RecoverAdmin {
        revoke_others: bool,
        ttl_hours: i64,
        label: String,
        json: bool,
        target: AuthTarget,
    },
}

Variants§

§

Issue

Issue a new token and print it to stdout.

create and add are accepted too: creating something was tokens issue, providers add and clients setup — three verbs for one idea (issue #314).

Fields

§ttl_hours: i64
§label: String
§account: Option<String>
§max_requests: Option<u64>

Cap on the number of upstream requests this token may make. Omit for an unlimited token.

§max_tokens: Option<u64>

Cap on actual input plus output tokens reported by upstreams. Omit for unlimited spend.

§rate_limit_per_minute: Option<u64>

Maximum requests admitted per one-minute window.

§admin: bool

Issue an administrative token (scope: admin) that unlocks the admin endpoints instead of only the inference proxy.

§github_repo: Vec<String>

Restrict this token’s GitHub proxy access to owner/repo. Repeat for several repositories; omit for unrestricted access, which is the default and what every existing token keeps.

§target: AuthTarget
§

Rotate

Replace a token, preserving its controls, and revoke the old token.

Fields

§id: String

Subject id (sub) of the token being replaced.

§ttl_hours: i64
§label: String
§max_requests: Option<u64>

Replacement request cap; omitted keeps the existing one.

§max_tokens: Option<u64>

Replacement token spend cap; omitted keeps the existing one.

§rate_limit_per_minute: Option<u64>

Replacement per-minute request rate; omitted keeps the existing one.

§account: Option<String>

Replacement account pin; omitted keeps the existing one.

§target: AuthTarget
§

List

List all known tokens.

Fields

§json: bool

Emit JSON instead of the table.

Every list printed a table unconditionally and every show printed JSON unconditionally, so neither could be asked for the other form — and --json existed on two subcommands only (issue #314).

§target: AuthTarget
§

Revoke

Revoke a token by id.

remove and delete are accepted too: destroying something was providers remove, clients remove, server remove, tokens revoke and tokens expire (issue #314).

Fields

§target: AuthTarget
§

Expire

Revoke a token by id — an alias of revoke, kept for scripts.

Both arms have always collapsed into the same call and printed revoked <ID>, while the help promised a distinct operation (issue #314). It is documented as the alias it is.

Fields

§target: AuthTarget
§

Show

Show metadata for one token.

Fields

§json: bool

Accepted for symmetry with list: show already emits JSON, so this changes nothing (issue #314). A script should not have to know which verb of a family takes the flag.

§target: AuthTarget
§

RecoverAdmin

Mint a replacement administrative token from the local token store.

The recovery path for a lost admin token. Every other verb in this family authenticates with the admin credential, so losing it left an operator who still owned the store, the volume and the machine with no way back in — and the standing advice was to destroy the deployment and discard every issued client token and the whole request log to recover from having misplaced one string (issue #573).

The admin token is a signed JWT and the store keeps only its metadata, so the lost value cannot be re-read. What can be done is to sign a new one: this reads TOKEN_SECRET and the store directly, exactly as the server does at boot, and mints an admin token the running deployment already accepts — no restart, and issued client tokens, provider configuration and the request log are untouched.

Gated on local ownership rather than on a credential. Reading the store is already equivalent to full control of the deployment, so this grants no authority its caller lacks; it only makes existing authority usable. For that reason it is never available over HTTP: with another router selected it refuses and names the machine it would have acted on, the same boundary auth import and auth clear draw.

Fields

§revoke_others: bool

Revoke every other admin token once the replacement is minted.

For a credential believed to be in someone else’s hands: recovery alone adds an administrator without removing the lost one.

§ttl_hours: i64
§label: String
§json: bool

Emit the stable JSON envelope instead of human-readable output.

§target: AuthTarget

Implementations§

Source§

impl TokenOp

Source

pub const fn target(&self) -> &AuthTarget

Which router this token operation acts on.

Trait Implementations§

Source§

impl Debug for TokenOp

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl FromArgMatches for TokenOp

Source§

fn from_arg_matches(__clap_arg_matches: &ArgMatches) -> Result<Self, Error>

Instantiate Self from ArgMatches, parsing the arguments as needed. Read more
Source§

fn from_arg_matches_mut( __clap_arg_matches: &mut ArgMatches, ) -> Result<Self, Error>

Instantiate Self from ArgMatches, parsing the arguments as needed. Read more
Source§

fn update_from_arg_matches( &mut self, __clap_arg_matches: &ArgMatches, ) -> Result<(), Error>

Assign values from ArgMatches to self.
Source§

fn update_from_arg_matches_mut<'b>( &mut self, __clap_arg_matches: &mut ArgMatches, ) -> Result<(), Error>

Assign values from ArgMatches to self.
Source§

impl Subcommand for TokenOp

Source§

fn augment_subcommands<'b>(__clap_app: Command) -> Command

Append to Command so it can instantiate Self via FromArgMatches::from_arg_matches_mut Read more
Source§

fn augment_subcommands_for_update<'b>(__clap_app: Command) -> Command

Append to Command so it can instantiate self via FromArgMatches::update_from_arg_matches_mut Read more
Source§

fn has_subcommand(__clap_name: &str) -> bool

Test whether Self can parse a specific subcommand

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> Downcast for T
where T: Any,

Source§

fn into_any(self: Box<T>) -> Box<dyn Any>

Convert Box<dyn Trait> (where Trait: Downcast) to Box<dyn Any>. Box<dyn Any> can then be further downcast into Box<ConcreteType> where ConcreteType implements Trait.
Source§

fn into_any_rc(self: Rc<T>) -> Rc<dyn Any>

Convert Rc<Trait> (where Trait: Downcast) to Rc<Any>. Rc<Any> can then be further downcast into Rc<ConcreteType> where ConcreteType implements Trait.
Source§

fn as_any(&self) -> &(dyn Any + 'static)

Convert &Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot generate &Any’s vtable from &Trait’s.
Source§

fn as_any_mut(&mut self) -> &mut (dyn Any + 'static)

Convert &mut Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot generate &mut Any’s vtable from &mut Trait’s.
Source§

impl<T> DowncastSync for T
where T: Any + Send + Sync,

Source§

fn into_any_arc(self: Arc<T>) -> Arc<dyn Any + Send + Sync>

Convert Arc<Trait> (where Trait: Downcast) to Arc<Any>. Arc<Any> can then be further downcast into Arc<ConcreteType> where ConcreteType implements Trait.
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more