pub enum ConfigError {
MissingToken,
PartialTlsFiles,
PartialTlsAcme,
BothTlsModes,
TrustedIpHeaderWithTls,
TlsRequired,
NoAcmeDomains,
WildcardAcmeDomain(String),
InvalidFlag {
var: &'static str,
value: String,
},
}Expand description
Why the server cannot start.
Variants§
MissingToken
Mirrors the Node server’s refusal to start without auth — a server reachable from the internet with no token is not a degraded mode worth supporting.
PartialTlsFiles
RECALL_TLS_CERT and RECALL_TLS_KEY name one file each; half a
pair is almost always a typo in one of the two variable names.
PartialTlsAcme
RECALL_TLS_ACME_DOMAINS and RECALL_TLS_ACME_EMAIL are the same
kind of pair, for the same reason.
BothTlsModes
The two TLS modes are mutually exclusive: each picks its own certificate source, and a config with both is ambiguous about which one wins rather than a config this server can just run.
TrustedIpHeaderWithTls
With direct TLS there is no ingress, so the socket’s own peer address is the only client IP that is not the client’s own choice. Setting this variable anyway is either a no-op or, if it is ever read, a way for a client to buy itself an unlimited number of token guesses by rotating whatever header it names, so refusing to start beats silently ignoring the setting.
An explicitly empty value is the one exception: it means “trust no
header”, which is exactly what TLS forces anyway, so
deploy/docker-compose.direct.yml sets it that way as a second
guard, in case its TLS variables ever go missing and the server
comes up as plain HTTP instead.
TlsRequired
RECALL_TLS_REQUIRED is set, but neither TLS mode is configured.
A deployment that publishes its port straight to the internet
(deploy/docker-compose.direct.yml) must never come up as plain
HTTP just because its certificate variables went missing or empty:
that would put the bearer token on the wire in clear text.
NoAcmeDomains
RECALL_TLS_ACME_DOMAINS was set but named no domain at all (only
commas or whitespace). There is nothing to ask a certificate for,
and a server with no certificate fails every handshake.
WildcardAcmeDomain(String)
TLS-ALPN-01, the only challenge this server answers, cannot prove control of a wildcard name (Let’s Encrypt requires DNS-01 for those), so an order for one could only ever fail, over and over, on the ACME directory’s rate limit.
InvalidFlag
A yes/no setting whose value is neither. Unlike the numeric tunables, which fall back to a default on a typo, these two decide whether the server may run without TLS and which certificate authority it trusts, so guessing either way would be wrong somewhere.
Trait Implementations§
Source§impl Clone for ConfigError
impl Clone for ConfigError
Source§impl Debug for ConfigError
impl Debug for ConfigError
Source§impl Display for ConfigError
impl Display for ConfigError
Source§impl Error for ConfigError
impl Error for ConfigError
1.30.0 · Source§fn source(&self) -> Option<&(dyn Error + 'static)>
fn source(&self) -> Option<&(dyn Error + 'static)>
1.0.0 · Source§fn description(&self) -> &str
fn description(&self) -> &str
use the Display impl or to_string()
Auto Trait Implementations§
impl Freeze for ConfigError
impl RefUnwindSafe for ConfigError
impl Send for ConfigError
impl Sync for ConfigError
impl Unpin for ConfigError
impl UnsafeUnpin for ConfigError
impl UnwindSafe for ConfigError
Blanket Implementations§
Source§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
Source§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
Source§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more