pub enum TokenOp {
Issue {
ttl_hours: i64,
label: String,
account: Option<String>,
max_requests: Option<u64>,
max_tokens: Option<u64>,
rate_limit_per_minute: Option<u64>,
admin: bool,
github_repo: Vec<String>,
target: AuthTarget,
},
Rotate {
id: String,
ttl_hours: i64,
label: String,
max_requests: Option<u64>,
max_tokens: Option<u64>,
rate_limit_per_minute: Option<u64>,
account: Option<String>,
target: AuthTarget,
},
List {
json: bool,
target: AuthTarget,
},
Revoke {
id: String,
target: AuthTarget,
},
Expire {
id: String,
target: AuthTarget,
},
Show {
id: String,
json: bool,
target: AuthTarget,
},
RecoverAdmin {
revoke_others: bool,
ttl_hours: i64,
label: String,
json: bool,
target: AuthTarget,
},
}Variants§
Issue
Issue a new token and print it to stdout.
create and add are accepted too: creating something was tokens issue, providers add and clients setup — three verbs for one idea
(issue #314).
Fields
max_requests: Option<u64>Cap on the number of upstream requests this token may make. Omit for an unlimited token.
max_tokens: Option<u64>Cap on actual input plus output tokens reported by upstreams. Omit for unlimited spend.
admin: boolIssue an administrative token (scope: admin) that unlocks the
admin endpoints instead of only the inference proxy.
github_repo: Vec<String>Restrict this token’s GitHub proxy access to owner/repo. Repeat
for several repositories; omit for unrestricted access, which is
the default and what every existing token keeps.
target: AuthTargetRotate
Replace a token, preserving its controls, and revoke the old token.
Fields
rate_limit_per_minute: Option<u64>Replacement per-minute request rate; omitted keeps the existing one.
target: AuthTargetList
List all known tokens.
Fields
json: boolEmit JSON instead of the table.
Every list printed a table unconditionally and every show
printed JSON unconditionally, so neither could be asked for the
other form — and --json existed on two subcommands only
(issue #314).
target: AuthTargetRevoke
Revoke a token by id.
remove and delete are accepted too: destroying something was
providers remove, clients remove, server remove, tokens revoke
and tokens expire (issue #314).
Expire
Revoke a token by id — an alias of revoke, kept for scripts.
Both arms have always collapsed into the same call and printed
revoked <ID>, while the help promised a distinct operation
(issue #314). It is documented as the alias it is.
Show
Show metadata for one token.
Fields
json: boolAccepted for symmetry with list: show already emits JSON, so
this changes nothing (issue #314). A script should not have to know
which verb of a family takes the flag.
target: AuthTargetRecoverAdmin
Mint a replacement administrative token from the local token store.
The recovery path for a lost admin token. Every other verb in this family authenticates with the admin credential, so losing it left an operator who still owned the store, the volume and the machine with no way back in — and the standing advice was to destroy the deployment and discard every issued client token and the whole request log to recover from having misplaced one string (issue #573).
The admin token is a signed JWT and the store keeps only its metadata,
so the lost value cannot be re-read. What can be done is to sign a new
one: this reads TOKEN_SECRET and the store directly, exactly as the
server does at boot, and mints an admin token the running deployment
already accepts — no restart, and issued client tokens, provider
configuration and the request log are untouched.
Gated on local ownership rather than on a credential. Reading the store
is already equivalent to full control of the deployment, so this grants
no authority its caller lacks; it only makes existing authority usable.
For that reason it is never available over HTTP: with another router
selected it refuses and names the machine it would have acted on, the
same boundary auth import and auth clear draw.
Fields
revoke_others: boolRevoke every other admin token once the replacement is minted.
For a credential believed to be in someone else’s hands: recovery alone adds an administrator without removing the lost one.
target: AuthTargetImplementations§
Trait Implementations§
Source§impl FromArgMatches for TokenOp
impl FromArgMatches for TokenOp
Source§fn from_arg_matches(__clap_arg_matches: &ArgMatches) -> Result<Self, Error>
fn from_arg_matches(__clap_arg_matches: &ArgMatches) -> Result<Self, Error>
Source§fn from_arg_matches_mut(
__clap_arg_matches: &mut ArgMatches,
) -> Result<Self, Error>
fn from_arg_matches_mut( __clap_arg_matches: &mut ArgMatches, ) -> Result<Self, Error>
Source§fn update_from_arg_matches(
&mut self,
__clap_arg_matches: &ArgMatches,
) -> Result<(), Error>
fn update_from_arg_matches( &mut self, __clap_arg_matches: &ArgMatches, ) -> Result<(), Error>
ArgMatches to self.Source§fn update_from_arg_matches_mut<'b>(
&mut self,
__clap_arg_matches: &mut ArgMatches,
) -> Result<(), Error>
fn update_from_arg_matches_mut<'b>( &mut self, __clap_arg_matches: &mut ArgMatches, ) -> Result<(), Error>
ArgMatches to self.Source§impl Subcommand for TokenOp
impl Subcommand for TokenOp
Source§fn augment_subcommands<'b>(__clap_app: Command) -> Command
fn augment_subcommands<'b>(__clap_app: Command) -> Command
Source§fn augment_subcommands_for_update<'b>(__clap_app: Command) -> Command
fn augment_subcommands_for_update<'b>(__clap_app: Command) -> Command
Command so it can instantiate self via
FromArgMatches::update_from_arg_matches_mut Read moreSource§fn has_subcommand(__clap_name: &str) -> bool
fn has_subcommand(__clap_name: &str) -> bool
Self can parse a specific subcommandAuto Trait Implementations§
impl Freeze for TokenOp
impl RefUnwindSafe for TokenOp
impl Send for TokenOp
impl Sync for TokenOp
impl Unpin for TokenOp
impl UnsafeUnpin for TokenOp
impl UnwindSafe for TokenOp
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> Downcast for Twhere
T: Any,
impl<T> Downcast for Twhere
T: Any,
Source§fn into_any(self: Box<T>) -> Box<dyn Any>
fn into_any(self: Box<T>) -> Box<dyn Any>
Box<dyn Trait> (where Trait: Downcast) to Box<dyn Any>. Box<dyn Any> can
then be further downcast into Box<ConcreteType> where ConcreteType implements Trait.Source§fn into_any_rc(self: Rc<T>) -> Rc<dyn Any>
fn into_any_rc(self: Rc<T>) -> Rc<dyn Any>
Rc<Trait> (where Trait: Downcast) to Rc<Any>. Rc<Any> can then be
further downcast into Rc<ConcreteType> where ConcreteType implements Trait.Source§fn as_any(&self) -> &(dyn Any + 'static)
fn as_any(&self) -> &(dyn Any + 'static)
&Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot
generate &Any’s vtable from &Trait’s.Source§fn as_any_mut(&mut self) -> &mut (dyn Any + 'static)
fn as_any_mut(&mut self) -> &mut (dyn Any + 'static)
&mut Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot
generate &mut Any’s vtable from &mut Trait’s.Source§impl<T> DowncastSync for T
impl<T> DowncastSync for T
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more