Expand description
Zero-I/O, clock-free domain layer for quota admission and accounting.
This crate is the request hot path. Its rules, in order:
- No I/O, no clock reads. Every operation is a function of its
arguments; callers pass
now. This is what makes the layer benchmarkable in isolation and embeddable in a service whose whole request budget is a few microseconds. - Fail closed. Unknown, expired, exhausted, or overflowing states deny; nothing here ever falls back to a slower path, because there is no slower path to fall back to.
- Checked arithmetic only. Cost math never wraps (INVARIANTS.md GL-11).
- Domain-agnostic. Cost units, operations, and permissions are generic; consumers (e.g. FerroRisk) map their own vocabulary onto them at startup.
The pieces compose in request order: an AccountSnapshot admits the
principal, a CostTable quotes the work, a LocalLease reserves the
units, and the resulting Reservation either commits at execution start
or releases for zero charge — producing a UsageEvent only when
committed. See INVARIANTS.md at the workspace root.
Tollgate releases the workspace as one unit: every published crate carries the same version, and the crates depend on each other at exactly that version.
Re-exports§
pub use budget::BalanceExhaustion;pub use budget::BalanceShortfall;pub use budget::BudgetSchedule;pub use budget::BudgetView;pub use budget::Period;pub use budget::Rollover;pub use cost_table::CostQuote;pub use cost_table::CostTable;pub use cost_table::CostTableBuilder;pub use cost_table::OpIndex;pub use cost_table::QuoteError;pub use deny::DenyReason;pub use deny::Retry;pub use ids::AccountId;pub use ids::FencingToken;pub use ids::Generation;pub use ids::KeyId;pub use ids::LeaseId;pub use ids::ParseIdError;pub use ids::PolicyRevision;pub use ids::Principal;pub use ids::RequestId;pub use lease::AccountOverage;pub use lease::LeaseGrant;pub use lease::LocalLease;pub use lease::RefillSignal;pub use lease::RefillVerdict;pub use reservation::CancelHandle;pub use reservation::CancelOutcome;pub use reservation::CommitError;pub use reservation::CommitFunding;pub use reservation::Reservation;pub use sharding::LocalSharding;pub use sharding::Locality;pub use sharding::ShardOccupancy;pub use snapshot::AccountRatePolicy;pub use snapshot::AccountSnapshot;pub use snapshot::AccountSnapshotBuilder;pub use snapshot::AccountStatus;pub use snapshot::CapacityClass;pub use snapshot::EnforcementMode;pub use snapshot::PermissionBits;pub use snapshot::PublishableSnapshot;pub use snapshot::RequestRateLimit;pub use snapshot::ResolvedLimits;pub use snapshot::ResolvedLimitsError;pub use snapshot::SnapshotValidationError;pub use snapshot::WeightedRateLimit;pub use units::CostUnits;pub use usage::DiscardedUsage;pub use usage::DiscardedUsageSlot;pub use usage::UsageEvent;pub use usage::UsageSlot;pub use usage::UsageSource;
Modules§
- budget
- Periodic allowances: what an account is granted each period, and what happens to what it did not spend.
- cost_
table - Direct index-addressed cost table, compiled once at startup.
- deny
- The single vocabulary of admission denials.
- ids
- Identifier newtypes.
- lease
- Local quota leases: centrally allocated capacity, locally decremented.
- reservation
- The reservation state machine:
pending → committed-at-execution-startorpending → released. - sharding
- Request-local affinity for opt-in instance-local sharding.
- snapshot
- Compiled account snapshots: the immutable, admission-ready form of an account’s policy.
- units
- Generic cost units with checked arithmetic.
- usage
- Usage events: the billing record.