Expand description
The mkit.transport.v1 Connect binding (feature connect,
SPEC-TRANSPORT-CONNECT): service mounts TransportService and
grpc.health.v1.Health over a Pipeline, behind the
AuthInterceptor. It is runtime-agnostic and wasm-clean (connectrpc
without its server and zstd features), so the native adapter serves
it through axum and the Workers adapter through its fetch bridge, both
unchanged.
Every RPC runs pipeline stage 0 in the interceptor, which sees the exact
unary request bytes (the auth v2 body commitment), and hands the
handler an Authenticated bound to the procedure called. A handler
decodes its message with the shared wire helpers (crate::refs,
crate::upload), calls one pipeline entry point inside
crate::send_wrap and encodes the answer. Errors cross the wire only
through From<ServerError> for ConnectError: public message, code,
HTTP status, response headers and typed details.
grpc.health.v1.Health is not authenticated: Check reports whether
both stores answer their probe (SERVING or NOT_SERVING), for load
balancers and kubelet probes.
A connect-timeout-ms header makes connectrpc compute a deadline with
Instant::now(), which panics on wasm32. The Workers adapter strips the
header before dispatch (mkit_worker_common::adapter::is_deadline_header);
this binding does not.
An upload is read message by message and stops at the last chunk.
connectrpc 0.9.1 then drains at most 1 MiB (and, natively, 5 s) more of
the request body before it resets the stream (RUSTSEC-2026-0304), so a
client cannot hold the handler open with trailing bytes.
Modules§
- proto
- Shared generated transport and health messages and service traits. Shared transport and health wire types and Connect service traits.
Structs§
- Auth
Interceptor - Runs
Pipeline::authenticateonce per call, before any message reaches a handler, and stores the resultingcrate::pipeline::Authenticated(with its test directives undertest-faults) in the request extensions. A unary call is checked against its exact request bytes; a client stream against its headers only;DownloadPack’s single request envelope is buffered, verified over its reconstructed framed body (0x00‖be32(len)‖message, R-129) and re-injected. - Connect
Health Checkanswers for the whole server ("") and formkit.transport.v1.TransportService:SERVINGwhen both stores answer their probe, elseNOT_SERVING. Any other name isnot_found.Watchisunimplemented, which tells a Watch-capable client not to retry.- Connect
Transport TransportServiceover aPipeline. Each handler takes theAuthenticatedthatsuper::AuthInterceptorstored for existing RPCs;GetServerInfois deliberately unauthenticated. The M2 RPCs remain explicit stubs until their implementing WPs land.
Functions§
- from_
upload_ error - An
UploadPackframing error on the Connect wire: its code andmkit-transport-connect’s message. - router
TransportServiceandHealthoverpipeline, without the interceptor: every authenticated transport RPC then failsunauthenticated; the M1 stub RPCs answerunimplemented. Mountserviceunless another layer installsAuthInterceptor.- service
routerbehindAuthInterceptor: what an adapter mounts. Apply deployment limits withConnectRpcService::with_limits.