Expand description
Authentication state for protocol-v2 connections and administrator operations.
§How a temporary credential works
Nothing secret is stored per key. A temporary credential is derived from the root key, the server instance id, and the key id, so the server can verify a credential it holds no copy of, and a key id is all the state a key needs:
issue: root key + instance id + key id --HKDF--> credential handed to the client
verify: root key + instance id + key id --HKDF--> compare against what was presentedBecause the material is derived, invalidating every key at once is a matter of changing an input: a root rotation replaces the root key, a state reset replaces the instance id. Neither has to touch individual keys.
§Where the state lives
key_id = generation:slot
|
request ──> derive & compare ──> slots[slot] ── lifecycle: Free/Active/
│ Expired/Revoked, expires_at
│
Weak lease ──> Arc lease, owned by the actor's
^ timing wheel — the single place
│ a lease's lifetime ends
AuthContext (also Weak) ─────────────┘The slot table is a preallocated array indexed straight off the key id, so
verification costs an array index and churn does not grow memory. The
SlotState docs below cover the table’s layout, why generations exist, and
why dead rows linger. Leases (leases.rs) owns the three structures a
key’s lifetime spans; timing_wheel.rs schedules the expiries.
§Where mutations happen
AuthRuntime (facade) ──channel──> one actor ──> encrypted snapshot + WALEvery mutation is serialized through a single actor, so a request authorized before a root rotation cannot execute against the state that replaced it.
The facade and model types stay in this root module; runtime checks, actor mutations, persistence, expiry scheduling, and tests live in the children.
Structs§
- Auth
Config - Auth
Context - Auth
Failure - Auth
Lease - Auth
Runtime - Auth
Status - Generation
- Which tenant of a slot a credential belongs to. Bumped every time the row is reissued, and never reset, so a retired credential can never match the row that replaced it.
- Issued
Temporary Key - KeyId
- The identity a client presents: a
SlotIndexpaired with theGenerationof the row it was issued from. - KeyPage
- Legacy
Connection Guard - Slot
Index - Which row of the slot table a credential lives in.
- Temporary
KeyMetadata
Enums§
Constants§
- ADMIN_
KEY_ ID - The administrator, which owns no slot and never expires.
- ADMIN_
NAMESPACE - The namespace administrator connections operate in. Tenant namespaces are the
key id that owns them, so this mirrors
ADMIN_KEY_ID. - DEFAULT_
AUTH_ STATE_ DIR - DEFAULT_
MAX_ TEMP_ KEY_ TTL - DEFAULT_
TEMP_ KEY_ CAPACITY - MAX_
TEMP_ KEY_ CAPACITY - MAX_
TEMP_ KEY_ TTL - MIN_
TEMP_ KEY_ TTL
Functions§
- acquire_
state_ dir_ lock - default_
auth_ state_ dir - derive_
temporary_ key - discard_
staged_ admin_ key - Drop a staged candidate once the rotation it belongs to is durably recorded at the live key file.
- encrypted_
auth_ state_ exists - generate_
admin_ key - initialize_
admin_ key - stage_
admin_ key_ candidate - Write a root-rotation candidate to the staged sibling of
path, returning the staged path. - staged_
admin_ key_ path - The sibling path a root-rotation candidate is staged at, next to the live
administrator key file
path. - write_
admin_ key_ file