pub struct CredentialDialer { /* private fields */ }Expand description
Reusable handle for the control plane’s CredentialService — the
admin-gated live enrollment, rotation, and revocation surface over State’s
credential authority.
Shares the AgentService endpoint — all these services are served on one
internal Connect port — so it is built from the same address. Every RPC on
this service requires the #803 admin service credential before it looks
at anything else in the request body, so unlike PersonaDialer this
dialer has no unauthenticated new: it is built ONLY through
Self::new_admin.
Implementations§
Source§impl CredentialDialer
impl CredentialDialer
Sourcepub fn new_admin(addr: &str, bearer: &str) -> Result<Self, DialError>
pub fn new_admin(addr: &str, bearer: &str) -> Result<Self, DialError>
Build a dialer pointed at addr, presenting bearer as the #803
admin service credential (Authorization: Bearer pc_<id>_<secret>,
a current record in State’s credential authority carrying admin
access) every CredentialService RPC checks before it will even look
at the request body.
§Errors
Returns DialError::InvalidAddress if addr isn’t a valid URI,
DialError::InvalidBearer if bearer can’t be encoded as an HTTP
header value, or DialError::Tls if an https endpoint’s TLS setup
fails.
Sourcepub async fn list_credentials_page(
&self,
after: Option<&str>,
) -> Result<CredentialSummaryPage, DialError>
pub async fn list_credentials_page( &self, after: Option<&str>, ) -> Result<CredentialSummaryPage, DialError>
One bounded page of stored records: id, principal, namespaces, and each key’s id, lifecycle state, and expiry. Never any secret material — the control plane refuses to send a salt, digest, or public key (INV-C3).
§Errors
Returns DialError::Connect for any transport/encoding error,
including permission_denied for a missing or invalid admin bearer.
Sourcepub async fn list_credentials(
&self,
) -> Result<Vec<CredentialRecordSummary>, DialError>
pub async fn list_credentials( &self, ) -> Result<Vec<CredentialRecordSummary>, DialError>
Reads every bounded page in canonical order.
The protocol remains paginated, so no response can exceed the credential-family wire bound. This convenience method is itself bounded by State’s deployment-wide credential-count limit.
§Errors
Returns DialError::Connect for any page transport/encoding error.
Sourcepub async fn enroll_credential(
&self,
enrollment: CredentialEnrollment,
) -> Result<EnrolledCredential, DialError>
pub async fn enroll_credential( &self, enrollment: CredentialEnrollment, ) -> Result<EnrolledCredential, DialError>
Create a record with its first key from an operator-supplied
verifier. Refuses (already_exists) if edge_id is already enrolled
— add a key to rotate an existing record instead.
grants_edge admits the record at the control plane’s transport gate
and lets its keys sign a turn’s identity envelope; grants_admin
makes it an admin service credential. A record needs at least one, and
a credential that must reach a doubly-gated RPC — every
PersonaService admin verb, RoutineService.FireRoutine — needs
both, since one presented bearer clears two independent checks.
§Errors
Returns DialError::Connect for any transport/encoding error,
including invalid_argument when neither capability is granted.
Sourcepub async fn add_credential_key(
&self,
operation_id: &str,
edge_id: &str,
key: CredentialVerifier,
) -> Result<AddedCredentialKey, DialError>
pub async fn add_credential_key( &self, operation_id: &str, edge_id: &str, key: CredentialVerifier, ) -> Result<AddedCredentialKey, DialError>
Append a new active key to edge_id — step 2 of a rotation. The
key(s) currently active drop to retiring and keep verifying until
Self::retire_credential_key names them (INV-C2): there is no
instant in which a correctly-configured caller is refused.
§Errors
Returns DialError::Connect for any transport/encoding error,
including not_found for an unknown edge_id.
Sourcepub async fn retire_credential_key(
&self,
operation_id: &str,
edge_id: &str,
kid: &str,
) -> Result<RetiredCredentialKey, DialError>
pub async fn retire_credential_key( &self, operation_id: &str, edge_id: &str, kid: &str, ) -> Result<RetiredCredentialKey, DialError>
Mark a retiring key revoked — step 5 of a rotation. It never verifies again.
§Errors
Returns DialError::Connect for any transport/encoding error,
including failed_precondition when kid isn’t currently retiring.
Sourcepub async fn revoke_credential(
&self,
operation_id: &str,
edge_id: &str,
) -> Result<RevokedCredential, DialError>
pub async fn revoke_credential( &self, operation_id: &str, edge_id: &str, ) -> Result<RevokedCredential, DialError>
Kill a whole credential immediately. Every one of its keys stops verifying and the record is removed from the store, so a restart cannot bring it back (INV-C1).
§Errors
Returns DialError::Connect for any transport/encoding error,
including not_found for an unknown edge_id.
Trait Implementations§
Source§impl Clone for CredentialDialer
impl Clone for CredentialDialer
Source§fn clone(&self) -> CredentialDialer
fn clone(&self) -> CredentialDialer
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreAuto Trait Implementations§
impl !RefUnwindSafe for CredentialDialer
impl !UnwindSafe for CredentialDialer
impl Freeze for CredentialDialer
impl Send for CredentialDialer
impl Sync for CredentialDialer
impl Unpin for CredentialDialer
impl UnsafeUnpin for CredentialDialer
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> FutureExt for T
impl<T> FutureExt for T
Source§fn with_context(self, otel_cx: Context) -> WithContext<Self> ⓘ
fn with_context(self, otel_cx: Context) -> WithContext<Self> ⓘ
Source§fn with_current_context(self) -> WithContext<Self> ⓘ
fn with_current_context(self) -> WithContext<Self> ⓘ
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§impl<T> IntoRequest<T> for T
impl<T> IntoRequest<T> for T
Source§fn into_request(self) -> Request<T>
fn into_request(self) -> Request<T>
T in a tonic::Request