Skip to main content

PipelineConfig

Struct PipelineConfig 

Source
#[non_exhaustive]
pub struct PipelineConfig {
Show 38 fields pub addressing: Addressing, pub sharding: Sharding, pub inspection_mode: bool, pub auth: AuthMode, pub grants: Option<GrantConfig>, pub authority_fence: Option<AuthorityFence>, pub write_policy: WritePolicy, pub default_repo_visibility: RepoVisibility, pub authorizer_role: AuthorizerRole, pub list_repos_authority_full: bool, pub upload_limits: UploadLimits, pub single_upload_max_bytes: Option<u64>, pub part_size: u64, pub max_parts: u32, pub max_list_refs_page_size: u32, pub begin_upload_threshold_bytes: u64, pub ticket_keys: Option<TicketKeys>, pub scanner_retrieval: Option<Arc<RetrievalConfig>>, pub url_tokens: Option<UrlTokenConfig>, pub admin_keys: Vec<[u8; 32]>, pub receipt_publication: Option<PublicationConfig>, pub purge: Option<PurgeConfig>, pub ticket_ttl_ms: u64, pub ticket_caps: TicketCaps, pub download_chunk_max: usize, pub write_quota: Option<QuotaLimits>, pub list_page_limit: u32, pub max_apply_window: Duration, pub epoch_lease_ms: u64, pub lease_margin_ms: u64, pub min_lease_budget_ms: u64, pub redactor: Redactor, pub admission_credential_headers: Vec<String>, pub outbox_backlog_cap: Option<OutboxBacklogCap>, pub indexed: Option<IndexedConfig>, pub takedown_denial: bool, pub ref_policy: Option<RefPolicy>, pub http_objects: Option<HttpObjectsConfig>,
}
Expand description

A deployment’s pipeline settings. Start from PipelineConfig::new.

Fields (Non-exhaustive)§

This struct is marked as non-exhaustive
Non-exhaustive structs could have additional fields added in future. Therefore, non-exhaustive structs cannot be constructed in external crates using the traditional Struct { .. } syntax; cannot be matched against without a wildcard ..; and struct update syntax will not work.
§addressing: Addressing

How requests map to a repository (M0: Single).

§sharding: Sharding

How metadata partitions are routed.

§inspection_mode: bool

Durable inspection mode, default-off and reserved for asynchronous inspection wiring.

§auth: AuthMode

How requests authenticate.

§grants: Option<GrantConfig>

Owner-signed write grant verifier for Multi/Owner deployments.

§authority_fence: Option<AuthorityFence>

Independent deployment-authority fence, optional and default-off.

§write_policy: WritePolicy

Write authorization policy; Open for Single, Owner for Multi.

§default_repo_visibility: RepoVisibility

Visibility of repositories without an explicit stored setting (default public).

§authorizer_role: AuthorizerRole

Role of the authorizer hook, defaulting to an additional check.

§list_repos_authority_full: bool

Opt in to namespace-wide ListRepos authority grants, requiring returned writer view. Default false: non-owner authority callers receive only the public listing.

§upload_limits: UploadLimits

Upload caps, supplied by the binding (used by M0-05b).

§single_upload_max_bytes: Option<u64>

Optional tighter cap for legacy single-part UploadPack requests.

§part_size: u64

Resumable upload part size: a power of two in 8–32 MiB.

§max_parts: u32

Largest number of parts, sufficient to reach the upload byte cap.

§max_list_refs_page_size: u32

Largest requested ListRefs page, in 1..=10,000. The default 1000 refs with at most 512-byte names fit STC §7.9’s 2 MiB page bound.

§begin_upload_threshold_bytes: u64

Packs smaller than this may skip BeginUpload; u64::MAX means never required. Advertised as zero with Multi addressing or admission.

§ticket_keys: Option<TicketKeys>

Accepted deployment upload MAC keys; first key signs.

§scanner_retrieval: Option<Arc<RetrievalConfig>>

Default-off private raw-pack scanner retrieval, with dedicated keys.

§url_tokens: Option<UrlTokenConfig>

URL-token key set and lifetime for IssueObjectUrl (SPEC-WRITE-GRANTS §9.4); None answers unimplemented.

§admin_keys: Vec<[u8; 32]>

Dedicated role keys, forbidden for client and owner authorization.

§receipt_publication: Option<PublicationConfig>

Receipt role key publication required by enabled takedown, without issuing receipts.

§purge: Option<PurgeConfig>

Durable invalidation; absent keeps launch purge machinery inert.

§ticket_ttl_ms: u64

Ticket lifetime, positive and strictly below seven days.

§ticket_caps: TicketCaps

Open-ticket bounds in each ref shard.

§download_chunk_max: usize

Largest download chunk (used by M0-05b).

§write_quota: Option<QuotaLimits>

The default write quota: Some(DEFAULT_WRITE_QUOTA) for auth v2 deployments (vcs-worker parity). Under D34 it counts per ref shard; Multi-addressing deployments also use it as the default namespace cap.

§list_page_limit: u32

ListRefs scan page size, at least 1.

§max_apply_window: Duration

Commit deadline window; see MAX_APPLY_WINDOW.

§epoch_lease_ms: u64

Coordinator epoch lease duration, in milliseconds.

§lease_margin_ms: u64

Safety margin in milliseconds. It must exceed the maximum clock skew between every pipeline instance (grant, renewal and revoke), the sweep driver, and every storage backend. The constructor cannot verify this.

§min_lease_budget_ms: u64

Minimum useful lease budget before renewing, in milliseconds.

§redactor: Redactor

Extra header names never to log.

§admission_credential_headers: Vec<String>

Extra request credential names passed to admission, in addition to payment defaults.

§outbox_backlog_cap: Option<OutboxBacklogCap>

Soft per-shard cap on undelivered outcomes, events and purges.

§indexed: Option<IndexedConfig>

Indexed ingestion and pre-receive verification, off by default.

§takedown_denial: bool

Global takedown proofs; the Worker launch enables them with preservation.

§ref_policy: Option<RefPolicy>

Per-ref allowed signers and fast-forward-only rules (SPEC-SERVER §9.7). Native embedders and the Worker launch can configure them. A fast-forward-only rule needs indexed.

§http_objects: Option<HttpObjectsConfig>

HTTP object serving (SPEC-HTTP-OBJECTS), off by default and explicitly configured by the adapter. Requires Self::indexed.

Implementations§

Source§

impl PipelineConfig

Source

pub fn new( addressing: Addressing, auth: AuthMode, upload_limits: UploadLimits, ) -> Self

Defaults for auth: the default write quota only for auth v2.

Source

pub fn advertised_namespace_policy(&self) -> &'static str

The namespace policy advertised by GetServerInfo (STC §2.1).

Trait Implementations§

Source§

impl Clone for PipelineConfig

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for PipelineConfig

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl From<&PipelineConfig> for LeaseParams

Source§

fn from(cfg: &PipelineConfig) -> Self

Converts to this type from the input type.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> MaybeSend for T
where T: Send + ?Sized,

Source§

impl<T> MaybeSync for T
where T: Sync + ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more