Skip to main content

Crate tollgate_client

Crate tollgate_client 

Source
Expand description

Instance-side quota runtime.

Background tasks run off the request path (INVARIANTS.md GL-6): a LeaseManager task keeps an account’s LeaseSlot stocked from a LeaseAllocator, and a UsageWriter task drains a bounded channel of usage events into a UsageSink in idempotent batches. The request path touches published state (lock-free loads) and the channel (permit reservation) — when the channel is full, admission sheds before work is accepted (INVARIANTS.md GL-8) via UsageRecorder::try_reserve.

Timestamps come from a Clock so every behavior is testable with a manual clock; production uses SystemClock.

InstanceRuntime owns discovery, stable account slots, dynamically supervised lease managers, and the bounded usage writer. Its cloneable RuntimeHandle provides staged admission, readiness, and reports; retain the unique runtime owner and await its shutdown. Lower-level managers remain available for specialized embeddings. Direct-store applications with budget schedules also own a PeriodRoller beside the admission runtime. Its monitor reports rollover health and confirmed progress; its shutdown is independent of usage and lease cleanup. HTTP-backed applications leave period maintenance to tollgate-server. Own a KeyManager beside the runtime to refresh customer credentials from a read-only KeySource. Use its KeyVerifier with tollgate_auth::SessionCredential, combine both monitors’ readiness, and include key-manager shutdown in the application’s budget. Refresh runs on the snapshot cadence; cached evidence expires within the configured key freshness window even when a key is removed or the feed becomes unavailable.

The runtime enforces one total shutdown deadline. It closes accounting admission, pauses refills, drains issued permits and guards, and releases account leases concurrently. Embedders stop their HTTP listeners when they request runtime shutdown and bound their own request-task quiescence by the returned deadline.

Graceful shutdown has one safe order: stop admitting, quiesce the request tasks still holding permits or committed tollgate_admission::Committed guards, await UsageWriter::shutdown (which refuses new reservations, then drains outstanding permits under its configured deadline and reports anything unresolved), and only then shut the LeaseManager down — usage events must land while their lease is live (INVARIANTS.md GL-12).

Re-exports§

pub use key_manager::KeyManager;
pub use key_manager::KeyManagerConfig;
pub use key_manager::KeyManagerConfigError;
pub use key_manager::KeyManagerHealth;
pub use key_manager::KeyManagerMonitor;
pub use key_manager::KeyManagerReport;
pub use key_manager::KeyManagerShutdownReport;
pub use key_manager::KeyManagerStats;
pub use key_manager::KeyVerifier;
pub use period_roller::PeriodRoller;
pub use period_roller::PeriodRollerConfig;
pub use period_roller::PeriodRollerConfigError;
pub use period_roller::PeriodRollerHealth;
pub use period_roller::PeriodRollerMonitor;
pub use period_roller::PeriodRollerReport;
pub use period_roller::PeriodRollerShutdownReport;
pub use period_roller::PeriodRollerStats;
pub use runtime::RuntimeFundingReport;
pub use runtime::AccountPhase;
pub use runtime::AccountReport;
pub use runtime::ContentionReport;
pub use runtime::InstanceRuntime;
pub use runtime::InstanceRuntimeConfig;
pub use runtime::InstanceRuntimeConfigError;
pub use runtime::RuntimeHandle;
pub use runtime::RuntimeReadiness;
pub use runtime::RuntimeReport;
pub use runtime::RuntimeShutdownReport;
pub use runtime::RuntimeWriterError;
pub use http::HttpStore;
pub use http_security::BearerProvider;
pub use http_security::BearerToken;
pub use http_security::GoogleIdentity;
pub use http_security::HttpStoreConfig;
pub use http_security::StaticBearer;
pub use lease_manager::AccountLeaseConfig;
pub use lease_manager::LeaseCounters;
pub use lease_manager::LeaseManager;
pub use lease_manager::LeaseManagerConfig;
pub use lease_manager::LeaseManagerConfigError;
pub use lease_manager::LeaseManagerReport;
pub use lease_manager::LeaseStats;
pub use snapshot_manager::SlotRegistry;
pub use snapshot_manager::SnapshotCounters;
pub use snapshot_manager::SnapshotManager;
pub use snapshot_manager::SnapshotManagerConfig;
pub use snapshot_manager::SnapshotManagerConfigError;
pub use snapshot_manager::SnapshotManagerReport;
pub use snapshot_manager::SnapshotStats;
pub use snapshot_manager::TrackedPrincipals;
pub use usage_writer::UsagePermit;
pub use usage_writer::UsageRecorder;
pub use usage_writer::UsageWriter;
pub use usage_writer::UsageWriterConfig;
pub use usage_writer::UsageWriterConfigError;
pub use usage_writer::WriterCounters;
pub use usage_writer::WriterHealth;
pub use usage_writer::WriterShutdownError;
pub use usage_writer::WriterStats;

Modules§

http
HTTP implementations of the store traits against a tollgate-server.
http_security
Credentials and validated transport configuration for background HTTP calls.
key_manager
Owned, bounded refresh of a read-only credential projection.
lease_manager
Background lease refill: the only code that talks to the allocator on an instance’s behalf.
period_roller
Periodic allowance maintenance for direct-store embeddings (GL-107).
runtime
Supported instance lifecycle. All maps, timers, supervision, and reports here are control-plane work. RuntimeHandle::begin delegates directly to the staged engine; usage permits remain the shutdown/admission barrier.
snapshot_manager
Background snapshot distribution: initial load, push subscription with lag recovery, periodic refresh, and revocation (review finding GL-5).
usage_writer
The batched usage writer.

Structs§

ManualClock
Deterministic test clock: starts where you set it, moves when you say so.
SystemClock
Production clock.

Traits§

Clock
Supplies now to the background planes. The core and admission layers take timestamps as arguments; implementations of this trait are the only code that decides what those timestamps are.