Expand description
Instance-side quota runtime.
Background tasks run off the request path (INVARIANTS.md GL-6): a
LeaseManager task keeps an account’s LeaseSlot stocked from a
LeaseAllocator, and a UsageWriter task drains a bounded channel of
usage events into a UsageSink in idempotent batches. The request path
touches published state (lock-free loads) and the channel (permit
reservation) — when the channel is full, admission sheds before work is
accepted (INVARIANTS.md GL-8) via UsageRecorder::try_reserve.
Timestamps come from a Clock so every behavior is testable with a
manual clock; production uses SystemClock.
InstanceRuntime owns discovery, stable account slots, dynamically
supervised lease managers, and the bounded usage writer. Its cloneable
RuntimeHandle provides staged admission, readiness, and reports; retain
the unique runtime owner and await its shutdown. Lower-level managers remain
available for specialized embeddings.
Direct-store applications with budget schedules also own a PeriodRoller
beside the admission runtime. Its monitor reports rollover health and
confirmed progress; its shutdown is independent of usage and lease cleanup.
HTTP-backed applications leave period maintenance to tollgate-server.
Own a KeyManager beside the runtime to refresh customer credentials from
a read-only KeySource. Use its KeyVerifier with
tollgate_auth::SessionCredential, combine both monitors’ readiness, and
include key-manager shutdown in the application’s budget. Refresh runs on
the snapshot cadence; cached evidence expires within the configured key
freshness window even when a key is removed or the feed becomes unavailable.
The runtime enforces one total shutdown deadline. It closes accounting admission, pauses refills, drains issued permits and guards, and releases account leases concurrently. Embedders stop their HTTP listeners when they request runtime shutdown and bound their own request-task quiescence by the returned deadline.
Graceful shutdown has one safe order: stop admitting, quiesce the request
tasks still holding permits or committed
tollgate_admission::Committed guards, await
UsageWriter::shutdown (which refuses new reservations, then drains
outstanding permits under its configured deadline and reports anything
unresolved), and only then shut the LeaseManager down — usage events
must land while their lease is live (INVARIANTS.md GL-12).
Re-exports§
pub use key_manager::KeyManager;pub use key_manager::KeyManagerConfig;pub use key_manager::KeyManagerConfigError;pub use key_manager::KeyManagerHealth;pub use key_manager::KeyManagerMonitor;pub use key_manager::KeyManagerReport;pub use key_manager::KeyManagerShutdownReport;pub use key_manager::KeyManagerStats;pub use key_manager::KeyVerifier;pub use period_roller::PeriodRoller;pub use period_roller::PeriodRollerConfig;pub use period_roller::PeriodRollerConfigError;pub use period_roller::PeriodRollerHealth;pub use period_roller::PeriodRollerMonitor;pub use period_roller::PeriodRollerReport;pub use period_roller::PeriodRollerShutdownReport;pub use period_roller::PeriodRollerStats;pub use runtime::RuntimeFundingReport;pub use runtime::AccountPhase;pub use runtime::AccountReport;pub use runtime::ContentionReport;pub use runtime::InstanceRuntime;pub use runtime::InstanceRuntimeConfig;pub use runtime::InstanceRuntimeConfigError;pub use runtime::RuntimeHandle;pub use runtime::RuntimeReadiness;pub use runtime::RuntimeReport;pub use runtime::RuntimeShutdownReport;pub use runtime::RuntimeWriterError;pub use http::HttpStore;pub use http_security::BearerProvider;pub use http_security::BearerToken;pub use http_security::GoogleIdentity;pub use http_security::HttpStoreConfig;pub use http_security::StaticBearer;pub use lease_manager::AccountLeaseConfig;pub use lease_manager::LeaseCounters;pub use lease_manager::LeaseManager;pub use lease_manager::LeaseManagerConfig;pub use lease_manager::LeaseManagerConfigError;pub use lease_manager::LeaseManagerReport;pub use lease_manager::LeaseStats;pub use snapshot_manager::SlotRegistry;pub use snapshot_manager::SnapshotCounters;pub use snapshot_manager::SnapshotManager;pub use snapshot_manager::SnapshotManagerConfig;pub use snapshot_manager::SnapshotManagerConfigError;pub use snapshot_manager::SnapshotManagerReport;pub use snapshot_manager::SnapshotStats;pub use snapshot_manager::TrackedPrincipals;pub use usage_writer::UsagePermit;pub use usage_writer::UsageRecorder;pub use usage_writer::UsageWriter;pub use usage_writer::UsageWriterConfig;pub use usage_writer::UsageWriterConfigError;pub use usage_writer::WriterCounters;pub use usage_writer::WriterHealth;pub use usage_writer::WriterShutdownError;pub use usage_writer::WriterStats;
Modules§
- http
- HTTP implementations of the store traits against a
tollgate-server. - http_
security - Credentials and validated transport configuration for background HTTP calls.
- key_
manager - Owned, bounded refresh of a read-only credential projection.
- lease_
manager - Background lease refill: the only code that talks to the allocator on an instance’s behalf.
- period_
roller - Periodic allowance maintenance for direct-store embeddings (GL-107).
- runtime
- Supported instance lifecycle. All maps, timers, supervision, and reports
here are control-plane work.
RuntimeHandle::begindelegates directly to the staged engine; usage permits remain the shutdown/admission barrier. - snapshot_
manager - Background snapshot distribution: initial load, push subscription with lag recovery, periodic refresh, and revocation (review finding GL-5).
- usage_
writer - The batched usage writer.
Structs§
- Manual
Clock - Deterministic test clock: starts where you set it, moves when you say so.
- System
Clock - Production clock.
Traits§
- Clock
- Supplies
nowto the background planes. The core and admission layers take timestamps as arguments; implementations of this trait are the only code that decides what those timestamps are.