Skip to main content

Module admin

Module admin 

Source
Expand description

Admin API module

This module provides the AdminApi trait and types for managing IAM users, policies, groups, service accounts, and cluster operations.

Re-exports§

pub use tier::ManualTransitionRunReport;
pub use tier::ManualTransitionRunRequest;
pub use tier::ManualTransitionRunResponse;
pub use tier::TierAliyun;
pub use tier::TierAzure;
pub use tier::TierConfig;
pub use tier::TierCreds;
pub use tier::TierGCS;
pub use tier::TierHuaweicloud;
pub use tier::TierMinIO;
pub use tier::TierR2;
pub use tier::TierRustFS;
pub use tier::TierS3;
pub use tier::TierTencent;
pub use tier::TierType;

Modules§

tier
Tier configuration types for remote storage tiering

Structs§

AccessKeyDetails
Common details shared by users, service accounts, and STS credentials.
AccessKeyInfo
General access key information returned by the RustFS Admin API.
AccessKeyRecord
A safe projection of one key returned by RustFS.
BackendInfo
Backend information
BucketMetadataArchive
An owned archive whose storage is cleared when dropped.
BucketQuota
Bucket quota information returned by Admin API
BucketsInfo
Bucket count information
BulkAccessKeyQuery
One bounded bulk-list request.
CapabilityEntry
One normalized capability row shown by the CLI.
CapabilityReport
Aggregate capability discovery result.
ClientDevnullRequest
Validated limits for one bounded client-to-server devnull probe.
ClientDevnullResult
Validated aggregate result from a client-to-server devnull probe.
ClusterComponentSnapshot
ClusterComponentSnapshots
ClusterInfo
Complete cluster information response
ClusterListingSnapshot
ClusterSnapshotDocument
Envelope returned by /v4/cluster/snapshot.
ClusterSnapshotMetadata
Metadata from /v4/cluster/snapshot without exposing server internals.
ClusterSnapshotSummary
Typed summary returned inside a cluster snapshot.
ClusterUsageSnapshot
ConfigChange
ConfigDiff
ConfigDocument
A server configuration document. Its contents are intentionally omitted from debug output.
ConfigHelp
ConfigHelpEntry
ConfigHistoryEntry
ConfigMutationResult
CreateServiceAccountRequest
Request to create a service account
DecommissionPoolStatus
Decommission operation status for a single pool.
DecommissionStatus
Decommission status response.
DetailedHealthSnapshot
Detailed authenticated RustFS health snapshot.
DiagnosticCapabilityGuardError
Error returned when a diagnostic operation is not explicitly available.
DiagnosticClusterSnapshot
Full read-only cluster snapshot with unstable subtrees preserved verbatim.
DiagnosticClusterSummary
DiskInfo
Disk information
EncryptedInspectArchive
Encrypted response staged in private temporary storage.
ExtensionMetadata
Extension metadata advertised by RustFS.
ExtensionsCatalog
Typed subset of /v4/extensions/catalog.
Group
Represents an IAM group
GroupPolicyEntities
Direct policy mappings for one group.
HealDriveInfo
Information about a single heal drive
HealDriveInfos
Collection of heal drive infos
HealResultItem
Result of a heal operation on a single item
HealStartRequest
Request to start a heal operation
HealStatus
Status of a heal operation
HealTaskRequest
Request to inspect or stop a token-scoped heal task
HealingDiskInfo
Healing disk information
HealthCpuSnapshot
HealthDriveSnapshot
HealthMemorySnapshot
HealthOsSnapshot
HealthProcessSnapshot
IamArchiveImportResult
Secret-safe typed summary of an IAM import.
IamArchiveImportSection
A failed IAM entity. Error text is intentionally discarded at the client boundary because a backend error may include credential material.
IamArchiveInventory
Names contained in an IAM archive, used for conflict preflight.
IamArchiveResultEntities
One category in RustFS’s structured IAM import report.
InspectArchiveCancellation
Cooperative cancellation shared with blocking decryption and validation.
InspectArchiveCapabilityContract
Exact capability fields required before invoking the archive route.
InspectArchiveKey
Opaque RSA private key used only for local archive decryption.
InspectArchiveManifest
InspectArchiveTransportRequest
Sanitized transport request. It intentionally has no Debug implementation.
KmsCacheSummary
Non-secret KMS cache configuration.
KmsCancelKeyDeletionResult
Result returned after cancelling scheduled KMS key deletion.
KmsConfigSummary
Non-secret KMS configuration summary returned by RustFS.
KmsCreateKeyRequest
Metadata used to create a KMS key without exposing key material.
KmsCreateKeyResult
Result returned after creating a KMS key.
KmsDeleteKeyRequest
Request to schedule or immediately delete a KMS key.
KmsDeleteKeyResult
Result returned after requesting KMS key deletion.
KmsKey
A normalized KMS key returned by list or describe operations.
KmsKeyPage
One page of KMS keys.
KmsLocalConfigureRequest
Strict Local backend configuration accepted by RustFS beta.10.
KmsRoundTripError
Sanitized failure that preserves exit-code classification and cleanup state.
KmsRoundTripReport
Successful diagnostic result. Temporary names and content are intentionally absent.
KmsRoundTripTimings
Safe timing metadata for a completed diagnostic.
KmsStatus
KMS health and configuration state.
KmsVaultKv2ConfigureRequest
Strict Vault KV2 backend configuration accepted by RustFS beta.10.
KmsVaultTransitConfigureRequest
Strict Vault Transit backend configuration accepted by RustFS beta.10.
LdapAccessKeyInfo
Identity-specific LDAP access key details.
MemStats
Memory statistics
MetricGroup
One scope-specific metrics object kept in its native JSON shape.
MetricGroups
Scope groups carried by a RustFS realtime metrics snapshot.
MetricsBatch
Fully bounded result of a RustFS metrics query.
MetricsQuery
Bounded realtime metrics request.
ModuleSwitches
ObjectsInfo
Object count information
OidcMutationRequest
Complete provider document accepted by RustFS’ OIDC upsert endpoint.
OidcMutationResult
Result returned after a retry-safe OIDC provider upsert.
OidcProvider
Secret-free view of one effective RustFS OIDC provider.
OidcProviderList
Effective OIDC provider collection and restart state.
OidcValidationRequest
Secret-free OIDC discovery validation request.
OidcValidationResult
Result of a live, non-mutating OIDC discovery validation.
OpenIdAccessKeyInfo
Identity-specific OpenID access key details.
PeerSiteSpec
A peer site definition for site-replication/add.
Policy
Represents an IAM policy
PolicyDetachRequest
A validated, retry-safe builtin policy detach request.
PolicyDetachResult
Normalized outcome for an idempotent builtin policy detach.
PolicyEntities
Users and groups attached to one policy.
PolicyEntitiesQuery
Filters for a policy-entity inspection request.
PolicyEntitiesResult
Policy mappings returned by RustFS.
PolicyInfo
Summary information about a policy (without the full document)
PoolDecommissionInfo
Decommission state and progress for a server pool.
PoolErasureSetInfo
Pool erasure set metrics returned by cluster information.
PoolStatus
Status of a server pool.
PoolTarget
Request targeting a storage pool by command line or numeric ID.
PublishedInspectArchive
Safe metadata returned after atomic publication.
RealtimeMetrics
One JSON Lines record from /rustfs/admin/v3/metrics.
RebalanceCleanupWarnings
Cleanup warnings recorded for a rebalanced pool.
RebalancePoolProgress
Rebalance progress for a single pool.
RebalancePoolStatus
Rebalance status for a single pool.
RebalanceStartResult
Response from starting a rebalance operation.
RebalanceStatus
Cluster-wide rebalance status.
ReplicateEditStatus
Typed response from site-replication/edit.
ReplicationCountSize
ReplicationDiff
A bounded, on-demand scan of object versions that have not replicated.
ReplicationDiffEntry
One pending or failed object version returned by a replication diff.
ReplicationLatencyMetric
ReplicationMetrics
ReplicationMrf
ReplicationMrfTarget
ReplicationQueueMetric
ReplicationTargetMetric
ReplicationTransferRate
RuntimeCapabilitiesSnapshot
Typed subset of the RustFS runtime capability response.
RuntimeCapabilitiesSummary
Summary fields provided by /v4/runtime/capabilities.
RuntimeCapabilityStatus
A typed status from a RustFS runtime snapshot.
ScannerCycleSchedule
Effective scanner cycle scheduling information.
ScannerFreshness
Scanner freshness metadata calculated by RustFS.
ScannerMetrics
Typed operational fields from the scanner report, with future fields retained.
ScannerRuntimeConfig
Typed subset of scanner runtime settings.
ScannerRuntimeConfigValue
One scanner runtime setting and the source selected by RustFS.
ScannerStatus
RustFS scanner status response.
ServerInfo
Server information representing a RustFS node
ServiceAccount
Represents a service account (access key pair)
ServiceAccountCreateResponse
ServiceAccountCredentials
ServiceActionResult
Response from POST /service?action=....
SetPolicyRequest
Request to set/attach policies
SiteRemoveSpec
Request body for site-replication/remove.
SiteReplicationInfo
Typed site replication information with server credentials discarded.
SiteReplicationPeer
Complete editable peer snapshot returned by site-replication/info.
SiteReplicationRepairCapabilityContract
Capability contract advertised by /rustfs/admin/v4/runtime/capabilities.
SiteReplicationRepairFamilyStatus
Per-family task counts and checkpoints.
SiteReplicationRepairOperationStatus
Durable execute/status snapshot.
SiteReplicationRepairPreflight
Dry-run response containing the server-issued preflight token.
SiteReplicationRepairRequest
Request body for dry-run and execute repair operations.
SiteReplicationRepairSiteStatus
Per-site repair plan or operation status.
SiteReplicationRepairTaskStatus
One durable task checkpoint.
SiteReplicationResyncBucketStatus
Per-bucket result returned by a site replication resync operation.
SiteReplicationResyncStatus
Typed response from site-replication/resync/op.
SiteStatusOptions
Options for site-replication/status.
StorageBackend
Storage backend topology and erasure coding configuration.
StorageDisk
One disk returned by RustFS storage information.
StorageDiskMetrics
Per-operation disk counters from storage information.
StorageInfo
RustFS storage information response body.
UpdateGroupMembersRequest
Request to update group members
UpdateServiceAccountRequest
Request to update an existing service account
UsageInfo
Cluster usage statistics
User
Represents an IAM user
UserPolicyEntities
Direct and inherited policy mappings for one user.
VerifiedInspectArchive
Fully authenticated and structurally validated plaintext archive.

Enums§

AccessKeyKind
Access-key class represented by a RustFS bulk response.
AccessKeyListType
Server-side access-key class filter.
AccessKeyProvider
Identity provider owning an access key.
BackendType
Storage backend type
CapabilityAvailability
Effective availability of an Admin API capability.
DiagnosticCapability
A diagnostic operation whose support must be known before it is invoked.
GroupStatus
Group status indicating whether the group is enabled or disabled
HealRuntimeState
HealScanMode
Heal operation mode
KmsBackendKind
Configured KMS backend family.
KmsConfigureRequest
Sensitive KMS configuration request. It intentionally cannot be formatted with Debug.
KmsKeyState
KMS key state.
KmsKeyUsage
KMS key usage.
KmsRoundTripErrorClass
Stable error class retained after adapter diagnostics are discarded.
KmsRoundTripPhase
Safe phase identifier for a failed diagnostic.
KmsServiceState
Runtime state of the RustFS KMS service.
KmsVaultAuthMethod
Vault authentication configuration. This type intentionally has no Debug implementation.
MetricsScope
RustFS realtime metrics selector bits from beta.10.
OidcProviderSource
Source that owns an effective OIDC provider configuration.
PolicyDetachEntity
A builtin IAM entity affected by a policy mutation.
PolicyEntity
Entity type for policy attachment
ReplicationMetricScope
Scope of a replication observation. Unknown values are retained for forward compatibility.
RuntimeCapabilityState
RustFS capability state returned by runtime snapshot endpoints.
ScannerHealth
Effective scanner condition presented by the CLI.
SiteReplicationResyncOperation
Operation accepted by site-replication/resync/op.
StorageBackendKind
RustFS storage backend kind.
UserStatus
User status indicating whether the user is enabled or disabled

Constants§

BUCKET_METADATA_CAPABILITY
Runtime capability required by bucket-metadata archive commands.
DEFAULT_CLIENT_DEVNULL_BYTES
Default bytes uploaded by each client-devnull request.
DEFAULT_CLIENT_DEVNULL_CONCURRENCY
Default number of concurrent client-devnull requests.
DEFAULT_CLIENT_DEVNULL_TIMEOUT
Default active probe timeout.
IAM_ACCESS_KEYS_BULK_CAPABILITY
Capability for the builtin bulk access-key route.
IAM_ACCESS_KEYS_BULK_LDAP_CAPABILITY
Capability for the LDAP-scoped bulk access-key route.
IAM_ACCESS_KEYS_BULK_OPENID_CAPABILITY
Capability for the OpenID-scoped bulk access-key route.
IAM_POLICY_DETACH_CAPABILITY
Capability name used to guard builtin policy detach mutations.
IAM_POLICY_ENTITIES_CAPABILITY
Capability name used to guard policy-entity inspection.
INSPECT_ARCHIVE_CAPABILITY
INSPECT_ARCHIVE_COMPLETION
INSPECT_ARCHIVE_CONTENT_TYPE
INSPECT_ARCHIVE_ENCRYPTION
INSPECT_ARCHIVE_ROUTE
INSPECT_ARCHIVE_VERSION
KMS_DIAGNOSTIC_CONTENT_BYTES
Fixed upper bound for internally generated diagnostic plaintext.
MAX_BUCKET_METADATA_ARCHIVE_BYTES
RustFS server limit for both exported and imported bucket-metadata archives.
MAX_CLIENT_DEVNULL_AGGREGATE_BYTES
Maximum bytes uploaded across all concurrent client-devnull requests.
MAX_CLIENT_DEVNULL_CONCURRENCY
Maximum number of concurrent client-devnull requests.
MAX_CLIENT_DEVNULL_TIMEOUT
Maximum active probe timeout.
MAX_DIAGNOSTIC_RESPONSE_BYTES
Maximum encoded size accepted for one diagnostic response.
MAX_IAM_ACCESS_KEYS_RESPONSE_BYTES
Maximum encoded response accepted from one bulk route.
MAX_IAM_ACCESS_KEY_RESULTS
Maximum number of decoded keys accepted from one server response.
MAX_IAM_ACCESS_KEY_SELECTORS
Maximum selectors accepted by one logical command.
MAX_IAM_ACCESS_KEY_SELECTOR_BYTES
Maximum UTF-8 byte length of one parent selector.
MAX_IAM_ARCHIVE_BYTES
Maximum accepted IAM archive size. This matches RustFS’s import body limit.
MAX_IAM_IMPORT_RESPONSE_BYTES
Maximum accepted structured response from an IAM import.
MAX_IAM_POLICY_DETACH_POLICIES
Maximum number of policies accepted by one detach request.
MAX_IAM_POLICY_DETACH_REQUEST_BYTES
Maximum encoded size sent for one policy detach request.
MAX_IAM_POLICY_DETACH_RESPONSE_BYTES
Maximum encoded size accepted for one policy detach response.
MAX_IAM_POLICY_DETACH_SELECTOR_BYTES
Maximum UTF-8 byte length accepted for a detach selector.
MAX_IAM_POLICY_ENTITIES_RESPONSE_BYTES
Maximum encoded size accepted for one policy-entity response.
MAX_IAM_POLICY_ENTITY_SELECTORS
Maximum number of selectors accepted in a single request.
MAX_IAM_POLICY_ENTITY_SELECTOR_BYTES
Maximum UTF-8 byte length accepted for one selector.
MAX_INSPECT_ARCHIVE_BYTES
MAX_INSPECT_ARCHIVE_DURATION
MAX_INSPECT_ARCHIVE_METADATA_BYTES_PER_DRIVE
MAX_METRICS_LINE_BYTES
Maximum encoded size of one NDJSON metrics record.
MAX_METRICS_RESPONSE_BYTES
Maximum encoded size accepted for an entire metrics response.
MAX_METRICS_SAMPLES
Maximum number of snapshots accepted from one metrics request.
MAX_OIDC_RESPONSE_BYTES
Maximum encoded size accepted for one OIDC administration response.
MAX_REPLICATION_DIFF_RESPONSE_BYTES
Maximum encoded size accepted for one replication diff response.
MAX_REPLICATION_INSPECTION_RESPONSE_BYTES
Maximum encoded size accepted for metrics and MRF responses.
MAX_SITE_REPLICATION_CA_CERT_BYTES
Maximum custom CA bundle accepted by the CLI.
MAX_SITE_REPLICATION_ERROR_RESPONSE_BYTES
Maximum site replication error response accepted from the server.
MAX_SITE_REPLICATION_REPAIR_RESPONSE_BYTES
Maximum preflight/operation response accepted from the repair routes.
MAX_SITE_REPLICATION_REQUEST_BYTES
Maximum serialized site replication edit request.
MAX_SITE_REPLICATION_SUCCESS_RESPONSE_BYTES
Maximum successful site replication response accepted from the server.
SITE_REPLICATION_REPAIR_CAPABILITY
Stable capability name for the durable site-replication repair lifecycle.

Traits§

AdminApi
Admin API trait for IAM and cluster management operations
BucketMetadataApi
BulkAccessKeyApi
Typed access-key bulk operations.
CapabilityApi
Read-only RustFS runtime capability discovery.
ConfigApi
RustFS Admin API configuration operations.
DiagnosticApi
Bounded active RustFS diagnostic probes.
DiagnosticReadApi
Read-only diagnostic adapter boundary.
IamArchiveApi
Bounded RustFS IAM archive transport.
IamMutationApi
Typed builtin IAM mutation operations.
IamReadApi
Read-only RustFS IAM policy-entity operations.
InspectArchiveApi
Transport boundary implemented by the RustFS Admin API adapter.
KmsApi
RustFS KMS administration operations.
KmsDiagnosticStore
Adapter boundary for the three sensitive object operations used by the diagnostic.
ObservabilityApi
Read-only scanner, storage, and metrics Admin API boundary.
OidcMutationApi
OidcReadApi
ReplicationDiffApi
Read-only RustFS replication diff operations.
ReplicationInspectionApi
SiteReplicationRepairApi
Durable site-replication repair transport.

Functions§

config_document_fields
Return subsystem/key pairs without exposing configuration values.
config_import_diff
Build a client-side preflight diff for a full configuration replacement.
config_mutation_diff
Build a client-side preflight diff for a set or delete mutation.
decrypt_and_validate_inspect_archive
Decrypt, authenticate, and validate an encrypted archive without publishing plaintext.
decrypt_and_validate_inspect_archive_with_cancel
publish_inspect_archive
Atomically publish a verified archive without replacing an existing destination.
redact_config_document
Redact secret-bearing fields in a RustFS line-oriented configuration document.
run_kms_round_trip
Run one bounded SSE-KMS write/read/verify/delete diagnostic.
validate_config_directive
Validate the syntax accepted by the RustFS config mutation endpoints.
validate_config_import
Reject redacted placeholders before a full replacement can overwrite live secrets.
validate_inspect_archive_output_directory
Reject output directories containing symbolic links or parent traversal.
validate_site_replication_ca_bundle
Validate a bounded certificate-only PEM bundle for site replication edits.
validate_site_replication_repair_operation_id
Validate the canonical UUID syntax required for durable operation identifiers.
validate_site_replication_repair_token
Validate the opaque HMAC-SHA256 v1 preflight token without inspecting its contents.