Expand description
Admin API module
This module provides the AdminApi trait and types for managing IAM users, policies, groups, service accounts, and cluster operations.
Re-exports§
pub use tier::ManualTransitionRunReport;pub use tier::ManualTransitionRunRequest;pub use tier::ManualTransitionRunResponse;pub use tier::TierAliyun;pub use tier::TierAzure;pub use tier::TierConfig;pub use tier::TierCreds;pub use tier::TierGCS;pub use tier::TierHuaweicloud;pub use tier::TierMinIO;pub use tier::TierR2;pub use tier::TierRustFS;pub use tier::TierS3;pub use tier::TierTencent;pub use tier::TierType;
Modules§
- tier
- Tier configuration types for remote storage tiering
Structs§
- Access
KeyDetails - Common details shared by users, service accounts, and STS credentials.
- Access
KeyInfo - General access key information returned by the RustFS Admin API.
- Access
KeyRecord - A safe projection of one key returned by RustFS.
- Backend
Info - Backend information
- Bucket
Metadata Archive - An owned archive whose storage is cleared when dropped.
- Bucket
Quota - Bucket quota information returned by Admin API
- Buckets
Info - Bucket count information
- Bulk
Access KeyQuery - One bounded bulk-list request.
- Capability
Entry - One normalized capability row shown by the CLI.
- Capability
Report - Aggregate capability discovery result.
- Client
Devnull Request - Validated limits for one bounded client-to-server devnull probe.
- Client
Devnull Result - Validated aggregate result from a client-to-server devnull probe.
- Cluster
Component Snapshot - Cluster
Component Snapshots - Cluster
Info - Complete cluster information response
- Cluster
Listing Snapshot - Cluster
Snapshot Document - Envelope returned by
/v4/cluster/snapshot. - Cluster
Snapshot Metadata - Metadata from
/v4/cluster/snapshotwithout exposing server internals. - Cluster
Snapshot Summary - Typed summary returned inside a cluster snapshot.
- Cluster
Usage Snapshot - Config
Change - Config
Diff - Config
Document - A server configuration document. Its contents are intentionally omitted from debug output.
- Config
Help - Config
Help Entry - Config
History Entry - Config
Mutation Result - Create
Service Account Request - Request to create a service account
- Decommission
Pool Status - Decommission operation status for a single pool.
- Decommission
Status - Decommission status response.
- Detailed
Health Snapshot - Detailed authenticated RustFS health snapshot.
- Diagnostic
Capability Guard Error - Error returned when a diagnostic operation is not explicitly available.
- Diagnostic
Cluster Snapshot - Full read-only cluster snapshot with unstable subtrees preserved verbatim.
- Diagnostic
Cluster Summary - Disk
Info - Disk information
- Encrypted
Inspect Archive - Encrypted response staged in private temporary storage.
- Extension
Metadata - Extension metadata advertised by RustFS.
- Extensions
Catalog - Typed subset of
/v4/extensions/catalog. - Group
- Represents an IAM group
- Group
Policy Entities - Direct policy mappings for one group.
- Heal
Drive Info - Information about a single heal drive
- Heal
Drive Infos - Collection of heal drive infos
- Heal
Result Item - Result of a heal operation on a single item
- Heal
Start Request - Request to start a heal operation
- Heal
Status - Status of a heal operation
- Heal
Task Request - Request to inspect or stop a token-scoped heal task
- Healing
Disk Info - Healing disk information
- Health
CpuSnapshot - Health
Drive Snapshot - Health
Memory Snapshot - Health
OsSnapshot - Health
Process Snapshot - IamArchive
Import Result - Secret-safe typed summary of an IAM import.
- IamArchive
Import Section - A failed IAM entity. Error text is intentionally discarded at the client boundary because a backend error may include credential material.
- IamArchive
Inventory - Names contained in an IAM archive, used for conflict preflight.
- IamArchive
Result Entities - One category in RustFS’s structured IAM import report.
- Inspect
Archive Cancellation - Cooperative cancellation shared with blocking decryption and validation.
- Inspect
Archive Capability Contract - Exact capability fields required before invoking the archive route.
- Inspect
Archive Key - Opaque RSA private key used only for local archive decryption.
- Inspect
Archive Manifest - Inspect
Archive Transport Request - Sanitized transport request. It intentionally has no
Debugimplementation. - KmsCache
Summary - Non-secret KMS cache configuration.
- KmsCancel
KeyDeletion Result - Result returned after cancelling scheduled KMS key deletion.
- KmsConfig
Summary - Non-secret KMS configuration summary returned by RustFS.
- KmsCreate
KeyRequest - Metadata used to create a KMS key without exposing key material.
- KmsCreate
KeyResult - Result returned after creating a KMS key.
- KmsDelete
KeyRequest - Request to schedule or immediately delete a KMS key.
- KmsDelete
KeyResult - Result returned after requesting KMS key deletion.
- KmsKey
- A normalized KMS key returned by list or describe operations.
- KmsKey
Page - One page of KMS keys.
- KmsLocal
Configure Request - Strict Local backend configuration accepted by RustFS beta.10.
- KmsRound
Trip Error - Sanitized failure that preserves exit-code classification and cleanup state.
- KmsRound
Trip Report - Successful diagnostic result. Temporary names and content are intentionally absent.
- KmsRound
Trip Timings - Safe timing metadata for a completed diagnostic.
- KmsStatus
- KMS health and configuration state.
- KmsVault
Kv2Configure Request - Strict Vault KV2 backend configuration accepted by RustFS beta.10.
- KmsVault
Transit Configure Request - Strict Vault Transit backend configuration accepted by RustFS beta.10.
- Ldap
Access KeyInfo - Identity-specific LDAP access key details.
- MemStats
- Memory statistics
- Metric
Group - One scope-specific metrics object kept in its native JSON shape.
- Metric
Groups - Scope groups carried by a RustFS realtime metrics snapshot.
- Metrics
Batch - Fully bounded result of a RustFS metrics query.
- Metrics
Query - Bounded realtime metrics request.
- Module
Switches - Objects
Info - Object count information
- Oidc
Mutation Request - Complete provider document accepted by RustFS’ OIDC upsert endpoint.
- Oidc
Mutation Result - Result returned after a retry-safe OIDC provider upsert.
- Oidc
Provider - Secret-free view of one effective RustFS OIDC provider.
- Oidc
Provider List - Effective OIDC provider collection and restart state.
- Oidc
Validation Request - Secret-free OIDC discovery validation request.
- Oidc
Validation Result - Result of a live, non-mutating OIDC discovery validation.
- Open
IdAccess KeyInfo - Identity-specific OpenID access key details.
- Peer
Site Spec - A peer site definition for
site-replication/add. - Policy
- Represents an IAM policy
- Policy
Detach Request - A validated, retry-safe builtin policy detach request.
- Policy
Detach Result - Normalized outcome for an idempotent builtin policy detach.
- Policy
Entities - Users and groups attached to one policy.
- Policy
Entities Query - Filters for a policy-entity inspection request.
- Policy
Entities Result - Policy mappings returned by RustFS.
- Policy
Info - Summary information about a policy (without the full document)
- Pool
Decommission Info - Decommission state and progress for a server pool.
- Pool
Erasure SetInfo - Pool erasure set metrics returned by cluster information.
- Pool
Status - Status of a server pool.
- Pool
Target - Request targeting a storage pool by command line or numeric ID.
- Published
Inspect Archive - Safe metadata returned after atomic publication.
- Realtime
Metrics - One JSON Lines record from
/rustfs/admin/v3/metrics. - Rebalance
Cleanup Warnings - Cleanup warnings recorded for a rebalanced pool.
- Rebalance
Pool Progress - Rebalance progress for a single pool.
- Rebalance
Pool Status - Rebalance status for a single pool.
- Rebalance
Start Result - Response from starting a rebalance operation.
- Rebalance
Status - Cluster-wide rebalance status.
- Replicate
Edit Status - Typed response from
site-replication/edit. - Replication
Count Size - Replication
Diff - A bounded, on-demand scan of object versions that have not replicated.
- Replication
Diff Entry - One pending or failed object version returned by a replication diff.
- Replication
Latency Metric - Replication
Metrics - Replication
Mrf - Replication
MrfTarget - Replication
Queue Metric - Replication
Target Metric - Replication
Transfer Rate - Runtime
Capabilities Snapshot - Typed subset of the RustFS runtime capability response.
- Runtime
Capabilities Summary - Summary fields provided by
/v4/runtime/capabilities. - Runtime
Capability Status - A typed status from a RustFS runtime snapshot.
- Scanner
Cycle Schedule - Effective scanner cycle scheduling information.
- Scanner
Freshness - Scanner freshness metadata calculated by RustFS.
- Scanner
Metrics - Typed operational fields from the scanner report, with future fields retained.
- Scanner
Runtime Config - Typed subset of scanner runtime settings.
- Scanner
Runtime Config Value - One scanner runtime setting and the source selected by RustFS.
- Scanner
Status - RustFS scanner status response.
- Server
Info - Server information representing a RustFS node
- Service
Account - Represents a service account (access key pair)
- Service
Account Create Response - Service
Account Credentials - Service
Action Result - Response from
POST /service?action=.... - SetPolicy
Request - Request to set/attach policies
- Site
Remove Spec - Request body for
site-replication/remove. - Site
Replication Info - Typed site replication information with server credentials discarded.
- Site
Replication Peer - Complete editable peer snapshot returned by
site-replication/info. - Site
Replication Repair Capability Contract - Capability contract advertised by
/rustfs/admin/v4/runtime/capabilities. - Site
Replication Repair Family Status - Per-family task counts and checkpoints.
- Site
Replication Repair Operation Status - Durable execute/status snapshot.
- Site
Replication Repair Preflight - Dry-run response containing the server-issued preflight token.
- Site
Replication Repair Request - Request body for dry-run and execute repair operations.
- Site
Replication Repair Site Status - Per-site repair plan or operation status.
- Site
Replication Repair Task Status - One durable task checkpoint.
- Site
Replication Resync Bucket Status - Per-bucket result returned by a site replication resync operation.
- Site
Replication Resync Status - Typed response from
site-replication/resync/op. - Site
Status Options - Options for
site-replication/status. - Storage
Backend - Storage backend topology and erasure coding configuration.
- Storage
Disk - One disk returned by RustFS storage information.
- Storage
Disk Metrics - Per-operation disk counters from storage information.
- Storage
Info - RustFS storage information response body.
- Update
Group Members Request - Request to update group members
- Update
Service Account Request - Request to update an existing service account
- Usage
Info - Cluster usage statistics
- User
- Represents an IAM user
- User
Policy Entities - Direct and inherited policy mappings for one user.
- Verified
Inspect Archive - Fully authenticated and structurally validated plaintext archive.
Enums§
- Access
KeyKind - Access-key class represented by a RustFS bulk response.
- Access
KeyList Type - Server-side access-key class filter.
- Access
KeyProvider - Identity provider owning an access key.
- Backend
Type - Storage backend type
- Capability
Availability - Effective availability of an Admin API capability.
- Diagnostic
Capability - A diagnostic operation whose support must be known before it is invoked.
- Group
Status - Group status indicating whether the group is enabled or disabled
- Heal
Runtime State - Heal
Scan Mode - Heal operation mode
- KmsBackend
Kind - Configured KMS backend family.
- KmsConfigure
Request - Sensitive KMS configuration request. It intentionally cannot be formatted with Debug.
- KmsKey
State - KMS key state.
- KmsKey
Usage - KMS key usage.
- KmsRound
Trip Error Class - Stable error class retained after adapter diagnostics are discarded.
- KmsRound
Trip Phase - Safe phase identifier for a failed diagnostic.
- KmsService
State - Runtime state of the RustFS KMS service.
- KmsVault
Auth Method - Vault authentication configuration. This type intentionally has no Debug implementation.
- Metrics
Scope - RustFS realtime metrics selector bits from beta.10.
- Oidc
Provider Source - Source that owns an effective OIDC provider configuration.
- Policy
Detach Entity - A builtin IAM entity affected by a policy mutation.
- Policy
Entity - Entity type for policy attachment
- Replication
Metric Scope - Scope of a replication observation. Unknown values are retained for forward compatibility.
- Runtime
Capability State - RustFS capability state returned by runtime snapshot endpoints.
- Scanner
Health - Effective scanner condition presented by the CLI.
- Site
Replication Resync Operation - Operation accepted by
site-replication/resync/op. - Storage
Backend Kind - RustFS storage backend kind.
- User
Status - User status indicating whether the user is enabled or disabled
Constants§
- BUCKET_
METADATA_ CAPABILITY - Runtime capability required by bucket-metadata archive commands.
- DEFAULT_
CLIENT_ DEVNULL_ BYTES - Default bytes uploaded by each client-devnull request.
- DEFAULT_
CLIENT_ DEVNULL_ CONCURRENCY - Default number of concurrent client-devnull requests.
- DEFAULT_
CLIENT_ DEVNULL_ TIMEOUT - Default active probe timeout.
- IAM_
ACCESS_ KEYS_ BULK_ CAPABILITY - Capability for the builtin bulk access-key route.
- IAM_
ACCESS_ KEYS_ BULK_ LDAP_ CAPABILITY - Capability for the LDAP-scoped bulk access-key route.
- IAM_
ACCESS_ KEYS_ BULK_ OPENID_ CAPABILITY - Capability for the OpenID-scoped bulk access-key route.
- IAM_
POLICY_ DETACH_ CAPABILITY - Capability name used to guard builtin policy detach mutations.
- IAM_
POLICY_ ENTITIES_ CAPABILITY - Capability name used to guard policy-entity inspection.
- INSPECT_
ARCHIVE_ CAPABILITY - INSPECT_
ARCHIVE_ COMPLETION - INSPECT_
ARCHIVE_ CONTENT_ TYPE - INSPECT_
ARCHIVE_ ENCRYPTION - INSPECT_
ARCHIVE_ ROUTE - INSPECT_
ARCHIVE_ VERSION - KMS_
DIAGNOSTIC_ CONTENT_ BYTES - Fixed upper bound for internally generated diagnostic plaintext.
- MAX_
BUCKET_ METADATA_ ARCHIVE_ BYTES - RustFS server limit for both exported and imported bucket-metadata archives.
- MAX_
CLIENT_ DEVNULL_ AGGREGATE_ BYTES - Maximum bytes uploaded across all concurrent client-devnull requests.
- MAX_
CLIENT_ DEVNULL_ CONCURRENCY - Maximum number of concurrent client-devnull requests.
- MAX_
CLIENT_ DEVNULL_ TIMEOUT - Maximum active probe timeout.
- MAX_
DIAGNOSTIC_ RESPONSE_ BYTES - Maximum encoded size accepted for one diagnostic response.
- MAX_
IAM_ ACCESS_ KEYS_ RESPONSE_ BYTES - Maximum encoded response accepted from one bulk route.
- MAX_
IAM_ ACCESS_ KEY_ RESULTS - Maximum number of decoded keys accepted from one server response.
- MAX_
IAM_ ACCESS_ KEY_ SELECTORS - Maximum selectors accepted by one logical command.
- MAX_
IAM_ ACCESS_ KEY_ SELECTOR_ BYTES - Maximum UTF-8 byte length of one parent selector.
- MAX_
IAM_ ARCHIVE_ BYTES - Maximum accepted IAM archive size. This matches RustFS’s import body limit.
- MAX_
IAM_ IMPORT_ RESPONSE_ BYTES - Maximum accepted structured response from an IAM import.
- MAX_
IAM_ POLICY_ DETACH_ POLICIES - Maximum number of policies accepted by one detach request.
- MAX_
IAM_ POLICY_ DETACH_ REQUEST_ BYTES - Maximum encoded size sent for one policy detach request.
- MAX_
IAM_ POLICY_ DETACH_ RESPONSE_ BYTES - Maximum encoded size accepted for one policy detach response.
- MAX_
IAM_ POLICY_ DETACH_ SELECTOR_ BYTES - Maximum UTF-8 byte length accepted for a detach selector.
- MAX_
IAM_ POLICY_ ENTITIES_ RESPONSE_ BYTES - Maximum encoded size accepted for one policy-entity response.
- MAX_
IAM_ POLICY_ ENTITY_ SELECTORS - Maximum number of selectors accepted in a single request.
- MAX_
IAM_ POLICY_ ENTITY_ SELECTOR_ BYTES - Maximum UTF-8 byte length accepted for one selector.
- MAX_
INSPECT_ ARCHIVE_ BYTES - MAX_
INSPECT_ ARCHIVE_ DURATION - MAX_
INSPECT_ ARCHIVE_ METADATA_ BYTES_ PER_ DRIVE - MAX_
METRICS_ LINE_ BYTES - Maximum encoded size of one NDJSON metrics record.
- MAX_
METRICS_ RESPONSE_ BYTES - Maximum encoded size accepted for an entire metrics response.
- MAX_
METRICS_ SAMPLES - Maximum number of snapshots accepted from one metrics request.
- MAX_
OIDC_ RESPONSE_ BYTES - Maximum encoded size accepted for one OIDC administration response.
- MAX_
REPLICATION_ DIFF_ RESPONSE_ BYTES - Maximum encoded size accepted for one replication diff response.
- MAX_
REPLICATION_ INSPECTION_ RESPONSE_ BYTES - Maximum encoded size accepted for metrics and MRF responses.
- MAX_
SITE_ REPLICATION_ CA_ CERT_ BYTES - Maximum custom CA bundle accepted by the CLI.
- MAX_
SITE_ REPLICATION_ ERROR_ RESPONSE_ BYTES - Maximum site replication error response accepted from the server.
- MAX_
SITE_ REPLICATION_ REPAIR_ RESPONSE_ BYTES - Maximum preflight/operation response accepted from the repair routes.
- MAX_
SITE_ REPLICATION_ REQUEST_ BYTES - Maximum serialized site replication edit request.
- MAX_
SITE_ REPLICATION_ SUCCESS_ RESPONSE_ BYTES - Maximum successful site replication response accepted from the server.
- SITE_
REPLICATION_ REPAIR_ CAPABILITY - Stable capability name for the durable site-replication repair lifecycle.
Traits§
- Admin
Api - Admin API trait for IAM and cluster management operations
- Bucket
Metadata Api - Bulk
Access KeyApi - Typed access-key bulk operations.
- Capability
Api - Read-only RustFS runtime capability discovery.
- Config
Api - RustFS Admin API configuration operations.
- Diagnostic
Api - Bounded active RustFS diagnostic probes.
- Diagnostic
Read Api - Read-only diagnostic adapter boundary.
- IamArchive
Api - Bounded RustFS IAM archive transport.
- IamMutation
Api - Typed builtin IAM mutation operations.
- IamRead
Api - Read-only RustFS IAM policy-entity operations.
- Inspect
Archive Api - Transport boundary implemented by the RustFS Admin API adapter.
- KmsApi
- RustFS KMS administration operations.
- KmsDiagnostic
Store - Adapter boundary for the three sensitive object operations used by the diagnostic.
- Observability
Api - Read-only scanner, storage, and metrics Admin API boundary.
- Oidc
Mutation Api - Oidc
Read Api - Replication
Diff Api - Read-only RustFS replication diff operations.
- Replication
Inspection Api - Site
Replication Repair Api - Durable site-replication repair transport.
Functions§
- config_
document_ fields - Return subsystem/key pairs without exposing configuration values.
- config_
import_ diff - Build a client-side preflight diff for a full configuration replacement.
- config_
mutation_ diff - Build a client-side preflight diff for a set or delete mutation.
- decrypt_
and_ validate_ inspect_ archive - Decrypt, authenticate, and validate an encrypted archive without publishing plaintext.
- decrypt_
and_ validate_ inspect_ archive_ with_ cancel - publish_
inspect_ archive - Atomically publish a verified archive without replacing an existing destination.
- redact_
config_ document - Redact secret-bearing fields in a RustFS line-oriented configuration document.
- run_
kms_ round_ trip - Run one bounded SSE-KMS write/read/verify/delete diagnostic.
- validate_
config_ directive - Validate the syntax accepted by the RustFS config mutation endpoints.
- validate_
config_ import - Reject redacted placeholders before a full replacement can overwrite live secrets.
- validate_
inspect_ archive_ output_ directory - Reject output directories containing symbolic links or parent traversal.
- validate_
site_ replication_ ca_ bundle - Validate a bounded certificate-only PEM bundle for site replication edits.
- validate_
site_ replication_ repair_ operation_ id - Validate the canonical UUID syntax required for durable operation identifiers.
- validate_
site_ replication_ repair_ token - Validate the opaque HMAC-SHA256 v1 preflight token without inspecting its contents.