pub struct KeyManager { /* private fields */ }Expand description
Owner of the credential-projection refresh task.
Reads the active credential set from a read-only KeySource, builds an
HMAC verification table from it, and publishes that table to its
KeyVerifier with a bounded lifetime. Retain it beside the
InstanceRuntime and shut it down with the
application; dropping it aborts the task and withdraws the table.
Implementations§
Source§impl KeyManager
impl KeyManager
Sourcepub fn spawn(
source: Arc<dyn KeySource>,
secret: &[u8],
clock: Arc<dyn Clock>,
config: KeyManagerConfig,
) -> Result<Self, KeyManagerConfigError>
pub fn spawn( source: Arc<dyn KeySource>, secret: &[u8], clock: Arc<dyn Clock>, config: KeyManagerConfig, ) -> Result<Self, KeyManagerConfigError>
Validate config and secret, then start the refresh task. The first
pass starts immediately. secret is the HMAC secret the credential
issuer uses, at least 32 bytes; it is copied and wiped when the task
ends. Must be called within a Tokio runtime.
§Errors
KeyManagerConfigError for an invalid configuration, a secret
shorter than 32 bytes, or a max_age whose deadline would not fit a
Timestamp. Nothing is started.
Sourcepub fn verifier(&self) -> KeyVerifier
pub fn verifier(&self) -> KeyVerifier
The verification capability for HTTP authentication state. Use it
with tollgate_auth::SessionCredential; it verifies nothing before
the first successful pass or after the task ends.
Sourcepub fn monitor(&self) -> KeyManagerMonitor
pub fn monitor(&self) -> KeyManagerMonitor
A read-only monitor for readiness and metrics state.
Sourcepub async fn shutdown(self) -> KeyManagerShutdownReport
pub async fn shutdown(self) -> KeyManagerShutdownReport
Signal the task to stop, cancelling any pending fetch, and wait up to
shutdown_timeout for it. Owns no leases or usage, so it can run
concurrently with the runtime’s shutdown. Cancelling this future
aborts the task.