Expand description
Signed operator API (§16), durable replay and a gapless audit chain.
Adapters precheck headers and the signed envelope before reading a body,
hash wire bytes with BodyCapture, then dispatch through Engine for
exact-body verification. No keys means no routes.
Operator replay and audit share the deployment root and commit before success.
Automatic state, purge work and outbox events commit in their source partition;
the existing relay atomically appends the root audit and advances its watermark.
Structs§
- Audit
Relay Hook - Native relay hook: extend the actual atomic target apply after bounded reads.
- Audit
Reserve Hook - Worker relay hook reserves target-local SQL extension space without DO reads.
- Body
Capture - Incrementally hashes the complete wire body while retaining at most 1 MiB.
- Config
- Public operator keys and the deployment’s canonical signing origin.
- Engine
- Durable admin service over one deployment-wide metadata partition.
- Prepared
- A prepared operation committed together with its audit and replay result.
- Preserved
Piece - One verified canonical slice. No instance is stored in the admin ledger.
- Response
- A bounded raw Connect response, shared by the native and Workers adapters.
- System
Audit - Source-local audit enqueue planner. No target effect happens before commit.
Enums§
- Operation
Replay - A durable operation replay or an acceptance batch for a new operation.
- Reply
- An admin response whose streaming bytes never enter replay storage.
Constants§
- AUDIT_
PATH - Canonical audit export procedure.
- GET_
TAKEDOWN_ PATH - Restricted status lookup.
- HEADER_
NAMES - Required admin envelope headers, in canonical envelope field order.
- LIST_
TAKEDOWNS_ PATH - Restricted paginated status lookup.
- MAX_
BODY - Maximum admin body size, both on the wire and decoded.
- PREFIX
- Canonical admin path prefix; never rewrite paths before verification.
- PURGE_
PATH - Canonical manual purge procedure.
- READ_
PRESERVED_ PATH - Restricted streaming canonical copy read.
- SET_
LEGAL_ HOLD_ PATH - Audited preservation legal-hold change.
- TAKEDOWN_
PATH - Procedures in the lean takedown catalog.
Traits§
- Admin
Operations - Internal extension of the signed, audited operator lifecycle.
Functions§
- extend_
audit_ batch - Extend an existing relay target transaction using reads from that transaction. Dedup receipts, gapless chain entries, and relay watermarks commit atomically.
- plan_
operation - Plan persistent operation-id deduplication after authentication and role checks. A new action must commit this batch atomically with its audit and intent.
- plan_
system - Plan an automatic action’s audit append; combine this batch with the action acceptance batch and retry planning if any CAS guard loses.
- precheck
- Check mixed credentials and the eight single-value headers before body I/O.
- precheck_
envelope - Authenticate the signed envelope before an adapter reads or hashes its body.
The exact body digest is still checked by
Engineafter bounded capture.
Type Aliases§
- Headers
- Adapter headers, preserving duplicates and the original values.