pub struct KeyManagerConfig {
pub refresh_interval: Duration,
pub fetch_timeout: Duration,
pub pass_timeout: Duration,
pub page_limit: NonZeroUsize,
pub max_pages: NonZeroUsize,
pub max_age: Duration,
pub shutdown_timeout: Duration,
}Expand description
Credential-projection refresh timing and paging budgets.
Default gives a five-second refresh pause and per-call timeout, a
ten-second pass, 256 records a page, 1024 page calls a pass, a 30-second
max_age and a five-second shutdown timeout. validate
runs before the task starts (INVARIANTS.md 16). docs/CREDENTIAL_PROJECTION.md
covers sizing against revocation tolerance.
Fields§
§refresh_interval: DurationPause after each completed attempt. The first fetch starts immediately.
Bounds how soon a key added, rotated or removed at the source reaches
new verifications. Set it no longer than the snapshot
refresh_interval. Too long delays key changes; too short re-reads
the whole credential set more often. Must be positive, and
max_age must exceed refresh_interval + 2 * pass_timeout.
fetch_timeout: DurationBound on one page call to the key source. A timeout fails the pass
(counted in KeyManagerStats::timeouts, or in pass_timeouts when
the pass budget ran out first) and keeps the previous
projection. Set it above the source’s slowest legitimate page. Must
be positive and no longer than pass_timeout.
pass_timeout: DurationOne budget for every page, restart, and projection build.
Must cover reading the whole credential set, including revision
restarts, or no pass ever publishes (counted in
KeyManagerStats::pass_timeouts). Larger values also force a larger
max_age. Must be positive and at least fetch_timeout.
page_limit: NonZeroUsizeRecords requested per page call. Larger pages mean fewer calls per pass, each heavier. At most 4096.
max_pages: NonZeroUsizeTotal page calls per pass, including revision-conflict retries.
A catalogue that needs more pages than this never publishes (counted
in KeyManagerStats::page_budget_exceeded); size it above the
credential count divided by page_limit, with room for restarts.
max_age: DurationMaximum evidence lifetime, measured from fetch START, including I/O.
Every credential verified from a projection, including one cached in
a session, stops verifying at the earlier of its own expiry and the
fetch start plus this. It is therefore the revocation bound for
cached sessions and how long authentication survives a feed outage.
Too short withdraws readiness on any slow pass; too long lets a
removed key keep authenticating. Must strictly exceed
refresh_interval + 2 * pass_timeout, and the resulting deadline must
fit a Timestamp.
shutdown_timeout: DurationHow long KeyManager::shutdown waits for the task to stop before
reporting deadline_expired. Include it in the application’s
shutdown budget. Must be positive.
Implementations§
Source§impl KeyManagerConfig
impl KeyManagerConfig
Sourcepub fn validate(&self) -> Result<(), KeyManagerConfigError>
pub fn validate(&self) -> Result<(), KeyManagerConfigError>
Check the configuration without starting anything: every duration
positive and representable, page_limit at most 4096,
fetch_timeout <= pass_timeout, and
max_age > refresh_interval + 2 * pass_timeout, so the previous
pass, the pause and the next pass all fit inside one evidence window.
§Errors
The first rule the configuration breaks.