Skip to main content

Crate tollgate_core

Crate tollgate_core 

Source
Expand description

Zero-I/O, clock-free domain layer for quota admission and accounting.

This crate is the request hot path. Its rules, in order:

  • No I/O, no clock reads. Every operation is a function of its arguments; callers pass now. This is what makes the layer benchmarkable in isolation and embeddable in a service whose whole request budget is a few microseconds.
  • Fail closed. Unknown, expired, exhausted, or overflowing states deny; nothing here ever falls back to a slower path, because there is no slower path to fall back to.
  • Checked arithmetic only. Cost math never wraps (INVARIANTS.md GL-11).
  • Domain-agnostic. Cost units, operations, and permissions are generic; consumers (e.g. FerroRisk) map their own vocabulary onto them at startup.

The pieces compose in request order: an AccountSnapshot admits the principal, a CostTable quotes the work, a LocalLease reserves the units, and the resulting Reservation either commits at execution start or releases for zero charge — producing a UsageEvent only when committed. See INVARIANTS.md at the workspace root.

Tollgate releases the workspace as one unit: every published crate carries the same version, and the crates depend on each other at exactly that version.

Re-exports§

pub use budget::BalanceExhaustion;
pub use budget::BalanceShortfall;
pub use budget::BudgetSchedule;
pub use budget::BudgetView;
pub use budget::Period;
pub use budget::Rollover;
pub use cost_table::CostQuote;
pub use cost_table::CostTable;
pub use cost_table::CostTableBuilder;
pub use cost_table::OpIndex;
pub use cost_table::QuoteError;
pub use deny::DenyReason;
pub use deny::Retry;
pub use ids::AccountId;
pub use ids::FencingToken;
pub use ids::Generation;
pub use ids::KeyId;
pub use ids::LeaseId;
pub use ids::ParseIdError;
pub use ids::PolicyRevision;
pub use ids::Principal;
pub use ids::RequestId;
pub use lease::AccountOverage;
pub use lease::LeaseGrant;
pub use lease::LocalLease;
pub use lease::RefillSignal;
pub use lease::RefillVerdict;
pub use reservation::CancelHandle;
pub use reservation::CancelOutcome;
pub use reservation::CommitError;
pub use reservation::CommitFunding;
pub use reservation::Reservation;
pub use reservation::SharedCharge;
pub use sharding::LocalSharding;
pub use sharding::Locality;
pub use sharding::ShardOccupancy;
pub use snapshot::AccountRatePolicy;
pub use snapshot::AccountSnapshot;
pub use snapshot::AccountSnapshotBuilder;
pub use snapshot::AccountStatus;
pub use snapshot::CapacityClass;
pub use snapshot::EnforcementMode;
pub use snapshot::PermissionBits;
pub use snapshot::PublishableSnapshot;
pub use snapshot::RequestRateLimit;
pub use snapshot::ResolvedLimits;
pub use snapshot::ResolvedLimitsError;
pub use snapshot::SnapshotValidationError;
pub use snapshot::WeightedRateLimit;
pub use units::CostUnits;
pub use usage::DiscardedUsage;
pub use usage::DiscardedUsageSlot;
pub use usage::UsageEvent;
pub use usage::UsageSlot;
pub use usage::UsageSource;

Modules§

budget
Periodic allowances: what an account is granted each period, and what happens to what it did not spend.
cost_table
Direct index-addressed cost table, compiled once at startup.
deny
The single vocabulary of admission denials.
ids
Identifier newtypes.
lease
Local quota leases: centrally allocated capacity, locally decremented.
reservation
The reservation state machine: pending → committed-at-execution-start or pending → released.
sharding
Request-local affinity for opt-in instance-local sharding.
snapshot
Compiled account snapshots: the immutable, admission-ready form of an account’s policy.
units
Generic cost units with checked arithmetic.
usage
Usage events: the billing record.