pub struct Admin { /* private fields */ }Expand description
Administrator RPCs. Constructed via super::Client::admin.
Implementations§
Source§impl Admin
impl Admin
Sourcepub async fn request(&self, request: AdminRequest) -> Result<AdminResponse>
pub async fn request(&self, request: AdminRequest) -> Result<AdminResponse>
One-shot administrator RPC. CLI output rendering can call this directly.
Sourcepub async fn request_with_timeout(
&self,
request: AdminRequest,
io_timeout: Duration,
) -> Result<AdminResponse>
pub async fn request_with_timeout( &self, request: AdminRequest, io_timeout: Duration, ) -> Result<AdminResponse>
Self::request with an explicit I/O bound, covering the connect as well
as the exchange.
Sourcepub async fn issue_key(
&self,
ttl: Duration,
label: Option<String>,
) -> Result<IssuedKey>
pub async fn issue_key( &self, ttl: Duration, label: Option<String>, ) -> Result<IssuedKey>
Mint a temporary credential valid for ttl.
Sourcepub async fn show_key(&self, key_id: u64) -> Result<IssuedKey>
pub async fn show_key(&self, key_id: u64) -> Result<IssuedKey>
Metadata for one credential, without its secret.
Sourcepub async fn reveal_key(&self, key_id: u64) -> Result<IssuedKey>
pub async fn reveal_key(&self, key_id: u64) -> Result<IssuedKey>
Metadata for one credential, with its secret.
Sourcepub async fn renew_key(&self, key_id: u64, ttl: Duration) -> Result<IssuedKey>
pub async fn renew_key(&self, key_id: u64, ttl: Duration) -> Result<IssuedKey>
Extend a credential’s lifetime to ttl from now.
Sourcepub async fn revoke_key(&self, key_id: u64) -> Result<KeyMetadata>
pub async fn revoke_key(&self, key_id: u64) -> Result<KeyMetadata>
Revoke a credential, taking effect on the relay immediately.
Sourcepub async fn auth_status(&self) -> Result<AuthStatusInfo>
pub async fn auth_status(&self) -> Result<AuthStatusInfo>
The relay’s credential-subsystem snapshot.
Sourcepub async fn gc_keys(&self) -> Result<u64>
pub async fn gc_keys(&self) -> Result<u64>
Drop expired and revoked credentials, returning how many were removed.
Sourcepub async fn reset_auth_state(&self) -> Result<()>
pub async fn reset_auth_state(&self) -> Result<()>
Erase the relay’s credential state. Every temporary credential stops authenticating; the administrator key is unaffected.
Sourcepub async fn set_legacy_protocol(&self, policy: LegacyProtocol) -> Result<()>
pub async fn set_legacy_protocol(&self, policy: LegacyProtocol) -> Result<()>
Allow or deny pre-v2 framing on new connections.
Sourcepub async fn list_keys(&self, page: u32, page_size: u16) -> Result<KeyListPage>
pub async fn list_keys(&self, page: u32, page_size: u16) -> Result<KeyListPage>
One page of temporary credentials.
Sourcepub async fn list_services(
&self,
key_id: Option<u64>,
page: u32,
page_size: u16,
) -> Result<ServicePage>
pub async fn list_services( &self, key_id: Option<u64>, page: u32, page_size: u16, ) -> Result<ServicePage>
One page of registered services, optionally scoped to one credential.
Sourcepub async fn list_connections(
&self,
key_id: Option<u64>,
page: u32,
page_size: u16,
) -> Result<ConnectionPage>
pub async fn list_connections( &self, key_id: Option<u64>, page: u32, page_size: u16, ) -> Result<ConnectionPage>
One page of live connections, optionally scoped to one credential.
Sourcepub async fn retire_connections(
&self,
key_id: Option<u64>,
service_name: String,
conn_id: Option<u32>,
) -> Result<u32>
pub async fn retire_connections( &self, key_id: Option<u64>, service_name: String, conn_id: Option<u32>, ) -> Result<u32>
Drop registered control connections the relay is still holding for a service, returning how many it dropped.
conn_id of None retires every connection the service has, which is
what frees a connection quota filled by connections that should have
gone away. A registration whose client is still healthy simply
reconnects, so this is a nudge rather than a shutdown.
Sourcepub async fn list_keys_all(&self) -> Result<Vec<KeyMetadata>>
pub async fn list_keys_all(&self) -> Result<Vec<KeyMetadata>>
Every temporary credential, paging until the relay stops handing back a cursor.
Sourcepub async fn list_services_all(
&self,
key_id: Option<u64>,
) -> Result<Vec<ServiceInfo>>
pub async fn list_services_all( &self, key_id: Option<u64>, ) -> Result<Vec<ServiceInfo>>
Every registered service, optionally scoped to one credential.
Sourcepub async fn list_connections_all(
&self,
key_id: Option<u64>,
) -> Result<Vec<ConnectionInfo>>
pub async fn list_connections_all( &self, key_id: Option<u64>, ) -> Result<Vec<ConnectionInfo>>
Every live connection, optionally scoped to one credential.
Sourcepub async fn rotate_root_key(&self, new_key: Option<String>) -> Result<String>
pub async fn rotate_root_key(&self, new_key: Option<String>) -> Result<String>
Rotate the relay’s administrator key, returning the key now in force.
Generates a key when new_key is None. Rotation is not idempotent, so a
caller who never learns the outcome cannot retry safely: if the relay
committed the change and the response was lost, only the new key still
authenticates. When the SDK generated that key, losing it locks the
operator out — so any inconclusive result is reported as
Error::RootRotationUncertain, which carries the candidate. A caller
who supplied new_key already holds it and gets the underlying error
unchanged.
Prefer Admin::rotate_root_key_to_file, which persists the candidate
before the request is ever sent.
Sourcepub async fn rotate_root_key_to_file(
&self,
path: &Path,
new_key: Option<String>,
) -> Result<String>
pub async fn rotate_root_key_to_file( &self, path: &Path, new_key: Option<String>, ) -> Result<String>
Rotate the root key and persist it to path.
The candidate is staged at a sibling file before the request is sent, and
path is only replaced once the relay has accepted the rotation and the new
key has passed a post-rotation status check. A rotation that fails after the
relay may have committed it therefore leaves both keys on disk rather than a
path holding a key the relay never installed.
An unresolved candidate from an earlier attempt is never overwritten — see
stage_admin_key_candidate — so this fails until the operator establishes
which of the two keys the relay accepts. Retrying with the same new_key
is allowed.
Trait Implementations§
Auto Trait Implementations§
impl !RefUnwindSafe for Admin
impl !UnwindSafe for Admin
impl Freeze for Admin
impl Send for Admin
impl Sync for Admin
impl Unpin for Admin
impl UnsafeUnpin for Admin
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more