Skip to main content

SecurityLoader

Struct SecurityLoader 

Source
pub struct SecurityLoader { /* private fields */ }
Expand description

Loader state retains Google keys for at most one hour after a successful fetch. Failures retry after five minutes and never extend that deadline.

The credential issuer is fixed when the loader starts. A later manifest naming a different issuer (added, removed or changed) still installs its transport and control-plane credentials, but the live issuer is kept and the change is reported as pending until restart: credentials already issued verify only where verifiers hold the secret that minted them, so switching authority under running verifiers would strand every new credential.

Implementations§

Source§

impl SecurityLoader

Source

pub fn new(path: impl Into<PathBuf>) -> Self

A loader for the JSON manifest at path. Nothing is read until load; relative paths inside the manifest resolve against its directory.

Source

pub fn start( &mut self, loaded: LoadedSecurity, ) -> Result<Arc<ServerSecurity>, SecurityError>

Mark only after installation succeeds. A failed replacement must remain eligible for retry even if the source files have not changed again.

This is the only place the credential issuer is set.

Source

pub fn install( &mut self, loaded: LoadedSecurity, security: &ServerSecurity, ) -> Result<(), SecurityError>

Replaces transport and control-plane credentials. A differing issuer is never applied; it is reported once per distinct staged value and remains visible through Self::issuer_change_pending.

Source

pub fn issuer(&self) -> Option<Arc<dyn CredentialIssuer + Send + Sync>>

The durable customer-credential issuer from the manifest’s issuer entry, fixed at Self::start. None before start or when the manifest configures none; issuance then answers 501.

Source

pub fn issuer_change_pending(&self) -> bool

True while the most recently installed manifest names a different issuer than the live one. Only a restart applies it.

Source

pub async fn load( &mut self, now: Timestamp, ) -> Result<Option<LoadedSecurity>, SecurityError>

Reads the manifest and every file it references, validates them, and stages a complete generation without making it live.

Each load builds a fresh control-plane bearer verifier keyed by a new random secret, so only HMAC digests of the static tokens are retained. When the manifest configures Google identity, this also refreshes Google’s signing keys if a refresh is due: after a successful fetch, at half the key set’s lifetime, clamped between five seconds and five minutes; after a failure, five minutes later. A fetched key set is usable until now plus the lifetime its Cache-Control/Age headers allow: five minutes without cache metadata, and never more than one hour. A failed fetch keeps the previous keys and their original expiry, or fails the load when there are none. A fetched key set that fails validation fails the load and also leaves the previous keys in place.

Returns Ok(None) when the manifest, every referenced file, and any signing keys and their expiry are unchanged since the generation last passed to start or install.

§Errors

Returns a SecurityError for an unreadable file, unknown manifest fields, a malformed or out-of-bounds credential, a duplicate credential mapping, an issuer secret that is malformed or equal to a bearer token, invalid TLS material, or unavailable signing keys. The live generation is unaffected.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<A, B, T> HttpServerConnExec<A, B> for T
where B: Body,

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more