Skip to main content

Module admin

Module admin 

Source
Expand description

Signed operator API (§16), durable replay and a gapless audit chain.

Adapters precheck headers and the signed envelope before reading a body, hash wire bytes with BodyCapture, then dispatch through Engine for exact-body verification. No keys means no routes. Operator replay and audit share the deployment root and commit before success. Automatic state, purge work and outbox events commit in their source partition; the existing relay atomically appends the root audit and advances its watermark.

Structs§

AuditRelayHook
Native relay hook: extend the actual atomic target apply after bounded reads.
AuditReserveHook
Worker relay hook reserves target-local SQL extension space without DO reads.
BodyCapture
Incrementally hashes the complete wire body while retaining at most 1 MiB.
Config
Public operator keys and the deployment’s canonical signing origin.
Engine
Durable admin service over one deployment-wide metadata partition.
Prepared
A prepared operation committed together with its audit and replay result.
PreservedPiece
One verified canonical slice. No instance is stored in the admin ledger.
Response
A bounded raw Connect response, shared by the native and Workers adapters.
SystemAudit
Source-local audit enqueue planner. No target effect happens before commit.

Enums§

OperationReplay
A durable operation replay or an acceptance batch for a new operation.
Reply
An admin response whose streaming bytes never enter replay storage.

Constants§

AUDIT_PATH
Canonical audit export procedure.
GET_TAKEDOWN_PATH
Restricted status lookup.
HEADER_NAMES
Required admin envelope headers, in canonical envelope field order.
LIST_TAKEDOWNS_PATH
Restricted paginated status lookup.
MAX_BODY
Maximum admin body size, both on the wire and decoded.
PREFIX
Canonical admin path prefix; never rewrite paths before verification.
PURGE_PATH
Canonical manual purge procedure.
READ_PRESERVED_PATH
Restricted streaming canonical copy read.
SET_LEGAL_HOLD_PATH
Audited preservation legal-hold change.
TAKEDOWN_PATH
Procedures in the lean takedown catalog.

Traits§

AdminOperations
Internal extension of the signed, audited operator lifecycle.

Functions§

extend_audit_batch
Extend an existing relay target transaction using reads from that transaction. Dedup receipts, gapless chain entries, and relay watermarks commit atomically.
plan_operation
Plan persistent operation-id deduplication after authentication and role checks. A new action must commit this batch atomically with its audit and intent.
plan_system
Plan an automatic action’s audit append; combine this batch with the action acceptance batch and retry planning if any CAS guard loses.
precheck
Check mixed credentials and the eight single-value headers before body I/O.
precheck_envelope
Authenticate the signed envelope before an adapter reads or hashes its body. The exact body digest is still checked by Engine after bounded capture.

Type Aliases§

Headers
Adapter headers, preserving duplicates and the original values.