#[non_exhaustive]pub struct PipelineConfig {Show 38 fields
pub addressing: Addressing,
pub sharding: Sharding,
pub inspection_mode: bool,
pub auth: AuthMode,
pub grants: Option<GrantConfig>,
pub authority_fence: Option<AuthorityFence>,
pub write_policy: WritePolicy,
pub default_repo_visibility: RepoVisibility,
pub authorizer_role: AuthorizerRole,
pub list_repos_authority_full: bool,
pub upload_limits: UploadLimits,
pub single_upload_max_bytes: Option<u64>,
pub part_size: u64,
pub max_parts: u32,
pub max_list_refs_page_size: u32,
pub begin_upload_threshold_bytes: u64,
pub ticket_keys: Option<TicketKeys>,
pub scanner_retrieval: Option<Arc<RetrievalConfig>>,
pub url_tokens: Option<UrlTokenConfig>,
pub admin_keys: Vec<[u8; 32]>,
pub receipt_publication: Option<PublicationConfig>,
pub purge: Option<PurgeConfig>,
pub ticket_ttl_ms: u64,
pub ticket_caps: TicketCaps,
pub download_chunk_max: usize,
pub write_quota: Option<QuotaLimits>,
pub list_page_limit: u32,
pub max_apply_window: Duration,
pub epoch_lease_ms: u64,
pub lease_margin_ms: u64,
pub min_lease_budget_ms: u64,
pub redactor: Redactor,
pub admission_credential_headers: Vec<String>,
pub outbox_backlog_cap: Option<OutboxBacklogCap>,
pub indexed: Option<IndexedConfig>,
pub takedown_denial: bool,
pub ref_policy: Option<RefPolicy>,
pub http_objects: Option<HttpObjectsConfig>,
}Expand description
A deployment’s pipeline settings. Start from PipelineConfig::new.
Fields (Non-exhaustive)§
This struct is marked as non-exhaustive
Struct { .. } syntax; cannot be matched against without a wildcard ..; and struct update syntax will not work.addressing: AddressingHow requests map to a repository (M0: Single).
sharding: ShardingHow metadata partitions are routed.
inspection_mode: boolDurable inspection mode, default-off and reserved for asynchronous inspection wiring.
auth: AuthModeHow requests authenticate.
grants: Option<GrantConfig>Owner-signed write grant verifier for Multi/Owner deployments.
Independent deployment-authority fence, optional and default-off.
write_policy: WritePolicyWrite authorization policy; Open for Single, Owner for Multi.
default_repo_visibility: RepoVisibilityVisibility of repositories without an explicit stored setting (default public).
Role of the authorizer hook, defaulting to an additional check.
Opt in to namespace-wide ListRepos authority grants, requiring returned writer view.
Default false: non-owner authority callers receive only the public listing.
upload_limits: UploadLimitsUpload caps, supplied by the binding (used by M0-05b).
single_upload_max_bytes: Option<u64>Optional tighter cap for legacy single-part UploadPack requests.
part_size: u64Resumable upload part size: a power of two in 8–32 MiB.
max_parts: u32Largest number of parts, sufficient to reach the upload byte cap.
max_list_refs_page_size: u32Largest requested ListRefs page, in 1..=10,000. The default 1000
refs with at most 512-byte names fit STC §7.9’s 2 MiB page bound.
begin_upload_threshold_bytes: u64Packs smaller than this may skip BeginUpload; u64::MAX means never
required. Advertised as zero with Multi addressing or admission.
ticket_keys: Option<TicketKeys>Accepted deployment upload MAC keys; first key signs.
scanner_retrieval: Option<Arc<RetrievalConfig>>Default-off private raw-pack scanner retrieval, with dedicated keys.
url_tokens: Option<UrlTokenConfig>URL-token key set and lifetime for IssueObjectUrl
(SPEC-WRITE-GRANTS §9.4); None answers unimplemented.
admin_keys: Vec<[u8; 32]>Dedicated role keys, forbidden for client and owner authorization.
receipt_publication: Option<PublicationConfig>Receipt role key publication required by enabled takedown, without issuing receipts.
purge: Option<PurgeConfig>Durable invalidation; absent keeps launch purge machinery inert.
ticket_ttl_ms: u64Ticket lifetime, positive and strictly below seven days.
ticket_caps: TicketCapsOpen-ticket bounds in each ref shard.
download_chunk_max: usizeLargest download chunk (used by M0-05b).
write_quota: Option<QuotaLimits>The default write quota: Some(DEFAULT_WRITE_QUOTA) for auth v2
deployments (vcs-worker parity). Under D34 it counts per ref shard;
Multi-addressing deployments also use it as the default namespace cap.
list_page_limit: u32ListRefs scan page size, at least 1.
max_apply_window: DurationCommit deadline window; see MAX_APPLY_WINDOW.
epoch_lease_ms: u64Coordinator epoch lease duration, in milliseconds.
lease_margin_ms: u64Safety margin in milliseconds. It must exceed the maximum clock skew between every pipeline instance (grant, renewal and revoke), the sweep driver, and every storage backend. The constructor cannot verify this.
min_lease_budget_ms: u64Minimum useful lease budget before renewing, in milliseconds.
redactor: RedactorExtra header names never to log.
admission_credential_headers: Vec<String>Extra request credential names passed to admission, in addition to payment defaults.
outbox_backlog_cap: Option<OutboxBacklogCap>Soft per-shard cap on undelivered outcomes, events and purges.
indexed: Option<IndexedConfig>Indexed ingestion and pre-receive verification, off by default.
takedown_denial: boolGlobal takedown proofs; the Worker launch enables them with preservation.
ref_policy: Option<RefPolicy>Per-ref allowed signers and fast-forward-only rules (SPEC-SERVER
§9.7). Native embedders and the Worker launch can configure them. A
fast-forward-only rule needs indexed.
http_objects: Option<HttpObjectsConfig>HTTP object serving (SPEC-HTTP-OBJECTS), off by default and
explicitly configured by the adapter. Requires Self::indexed.
Implementations§
Source§impl PipelineConfig
impl PipelineConfig
Sourcepub fn new(
addressing: Addressing,
auth: AuthMode,
upload_limits: UploadLimits,
) -> Self
pub fn new( addressing: Addressing, auth: AuthMode, upload_limits: UploadLimits, ) -> Self
Defaults for auth: the default write quota only for auth v2.
Sourcepub fn advertised_namespace_policy(&self) -> &'static str
pub fn advertised_namespace_policy(&self) -> &'static str
The namespace policy advertised by GetServerInfo (STC §2.1).