pub struct HttpStoreConfig {
pub connect_timeout: Duration,
pub request_timeout: Duration,
pub root_ca_pem: Option<Vec<u8>>,
pub identity_pem: Option<Zeroizing<Vec<u8>>>,
pub bearer: Option<Arc<dyn BearerProvider>>,
}Expand description
Authentication and TLS settings for HttpStore. A custom CA replaces public roots. Identity PEM contains the certificate chain and private key.
Default gives a two-second connect timeout, a ten-second request
timeout, public roots, no client certificate and no bearer, which
tollgate-server refuses. Every rule is checked when the client is built,
by HttpStore::with_config and
HttpStore::reconfigure.
Fields§
§connect_timeout: DurationBound on establishing one connection to the server.
Too short fails calls across a slow network path; too long lets an
unreachable server consume most of request_timeout. Must be
positive and representable.
request_timeout: DurationBound on one whole call: obtaining the bearer credential, connecting,
sending, and reading the response body. Background components apply
their own per-call timeouts as well (store_call_timeout,
ingest_timeout, fetch_timeout), and the shorter bound wins. Set it
above the server’s slowest legitimate answer, a full ingest batch or
catalogue page included; too short turns slow answers into retried
storage errors. Must be positive and representable.
root_ca_pem: Option<Vec<u8>>PEM bundle of CA certificates that replace the public roots for
verifying the server. Must contain at least one certificate; not
allowed with plaintext http.
identity_pem: Option<Zeroizing<Vec<u8>>>PEM certificate chain and private key presenting this instance’s
client certificate for mutual TLS. Wiped from memory when dropped;
not allowed with plaintext http.
bearer: Option<Arc<dyn BearerProvider>>Source of the bearer credential sent on every call. None sends no
Authorization header.