pub enum ManagedPolicyDecision {
PassThrough {
policy_id: String,
op: PolicyOp,
},
Allow {
entry_id: String,
entry_version: u64,
op: PolicyOp,
matched_action: String,
matched_resource: String,
evidence: EvidenceRequirement,
},
Deny {
entry_id: String,
entry_version: u64,
op: PolicyOp,
matched_action: String,
matched_resource: String,
reason: DenyReason,
},
}Expand description
Outcome of a managed-policy mutation check.
Variants§
PassThrough
Policy id is not governed by a managed registry entry. Caller should proceed with ordinary IAM checks.
Allow
Policy is managed and the caller satisfied the policy gate. Caller may proceed; the returned evidence requirement tells the Control Event Ledger how much detail to persist.
Fields
§
evidence: EvidenceRequirementDeny
Policy is managed and the caller failed one of the gates. Carries enough metadata for Control Event / audit emission.
Implementations§
Trait Implementations§
Source§impl Clone for ManagedPolicyDecision
impl Clone for ManagedPolicyDecision
Source§fn clone(&self) -> ManagedPolicyDecision
fn clone(&self) -> ManagedPolicyDecision
Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
Performs copy-assignment from
source. Read moreSource§impl Debug for ManagedPolicyDecision
impl Debug for ManagedPolicyDecision
impl Eq for ManagedPolicyDecision
Source§impl PartialEq for ManagedPolicyDecision
impl PartialEq for ManagedPolicyDecision
impl StructuralPartialEq for ManagedPolicyDecision
Auto Trait Implementations§
impl Freeze for ManagedPolicyDecision
impl RefUnwindSafe for ManagedPolicyDecision
impl Send for ManagedPolicyDecision
impl Sync for ManagedPolicyDecision
impl Unpin for ManagedPolicyDecision
impl UnsafeUnpin for ManagedPolicyDecision
impl UnwindSafe for ManagedPolicyDecision
Blanket Implementations§
Source§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
Source§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
Compare self to
key and return true if they are equal.Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
Converts
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§impl<T> IntoRequest<T> for T
impl<T> IntoRequest<T> for T
Source§fn into_request(self) -> Request<T>
fn into_request(self) -> Request<T>
Wrap the input message
T in a tonic::Request