pub struct PolicySupport { /* private fields */ }Expand description
The policy set one serving tier implements, plus the set an operator has asserted is enforced in front of it.
Constructed at startup by whichever binary is about to serve, so the claim lives next to the code that makes it true rather than in a doc.
Implementations§
Source§impl PolicySupport
impl PolicySupport
Sourcepub fn new(tier: impl Into<String>) -> Self
pub fn new(tier: impl Into<String>) -> Self
A tier that enforces nothing. tier names the binary/subcommand as an
operator would type it (mesofact serve), since that is the thing they
have to change.
Sourcepub fn enforces(self, policy: RoutePolicy) -> Self
pub fn enforces(self, policy: RoutePolicy) -> Self
Advertise a policy this tier implements itself.
Sourcepub fn delegate(self, policy: RoutePolicy) -> Self
pub fn delegate(self, policy: RoutePolicy) -> Self
Record an operator’s assertion that something in front of this process
enforces policy (an authenticating edge, a CDN). Distinct from
enforces so the startup log can say which of the two
is carrying a route — “we do this” and “someone says they do this” are
not the same claim and should not print the same.
pub fn tier(&self) -> &str
pub fn covers(&self, policy: RoutePolicy) -> bool
pub fn is_delegated(&self, policy: RoutePolicy) -> bool
Sourcepub fn enforced(&self) -> impl Iterator<Item = RoutePolicy> + '_
pub fn enforced(&self) -> impl Iterator<Item = RoutePolicy> + '_
Policies this tier implements, for the startup log.
Sourcepub fn delegated(&self) -> impl Iterator<Item = RoutePolicy> + '_
pub fn delegated(&self) -> impl Iterator<Item = RoutePolicy> + '_
Policies covered only by an operator assertion, for the startup log.