Skip to main content

Module connect

Module connect 

Source
Expand description

The mkit.transport.v1 Connect binding (feature connect, SPEC-TRANSPORT-CONNECT): service mounts TransportService and grpc.health.v1.Health over a Pipeline, behind the AuthInterceptor. It is runtime-agnostic and wasm-clean (connectrpc without its server and zstd features), so the native adapter serves it through axum and the Workers adapter through its fetch bridge, both unchanged.

Every RPC runs pipeline stage 0 in the interceptor, which sees the exact unary request bytes (the auth v2 body commitment), and hands the handler an Authenticated bound to the procedure called. A handler decodes its message with the shared wire helpers (crate::refs, crate::upload), calls one pipeline entry point inside crate::send_wrap and encodes the answer. Errors cross the wire only through From<ServerError> for ConnectError: public message, code, HTTP status, response headers and typed details.

grpc.health.v1.Health is not authenticated: Check reports whether both stores answer their probe (SERVING or NOT_SERVING), for load balancers and kubelet probes.

A connect-timeout-ms header makes connectrpc compute a deadline with Instant::now(), which panics on wasm32. The Workers adapter strips the header before dispatch (mkit_worker_common::adapter::is_deadline_header); this binding does not.

An upload is read message by message and stops at the last chunk. connectrpc 0.9.1 then drains at most 1 MiB (and, natively, 5 s) more of the request body before it resets the stream (RUSTSEC-2026-0304), so a client cannot hold the handler open with trailing bytes.

Modules§

proto
Shared generated transport and health messages and service traits. Shared transport and health wire types and Connect service traits.

Structs§

AuthInterceptor
Runs Pipeline::authenticate once per call, before any message reaches a handler, and stores the resulting crate::pipeline::Authenticated (with its test directives under test-faults) in the request extensions. A unary call is checked against its exact request bytes; a client stream against its headers only; DownloadPack’s single request envelope is buffered, verified over its reconstructed framed body (0x00‖be32(len)‖message, R-129) and re-injected.
ConnectHealth
Check answers for the whole server ("") and for mkit.transport.v1.TransportService: SERVING when both stores answer their probe, else NOT_SERVING. Any other name is not_found. Watch is unimplemented, which tells a Watch-capable client not to retry.
ConnectTransport
TransportService over a Pipeline. Each handler takes the Authenticated that super::AuthInterceptor stored for existing RPCs; GetServerInfo is deliberately unauthenticated. The M2 RPCs remain explicit stubs until their implementing WPs land.

Functions§

from_upload_error
An UploadPack framing error on the Connect wire: its code and mkit-transport-connect’s message.
router
TransportService and Health over pipeline, without the interceptor: every authenticated transport RPC then fails unauthenticated; the M1 stub RPCs answer unimplemented. Mount service unless another layer installs AuthInterceptor.
service
router behind AuthInterceptor: what an adapter mounts. Apply deployment limits with ConnectRpcService::with_limits.