pub struct SecurityLoader { /* private fields */ }Expand description
Loader state retains Google keys for at most one hour after a successful fetch. Failures retry after five minutes and never extend that deadline.
The credential issuer is fixed when the loader starts. A later manifest naming a different issuer (added, removed or changed) still installs its transport and control-plane credentials, but the live issuer is kept and the change is reported as pending until restart: credentials already issued verify only where verifiers hold the secret that minted them, so switching authority under running verifiers would strand every new credential.
Implementations§
Source§impl SecurityLoader
impl SecurityLoader
Sourcepub fn new(path: impl Into<PathBuf>) -> Self
pub fn new(path: impl Into<PathBuf>) -> Self
A loader for the JSON manifest at path. Nothing is read until
load; relative paths inside the manifest resolve
against its directory.
Sourcepub fn start(
&mut self,
loaded: LoadedSecurity,
) -> Result<Arc<ServerSecurity>, SecurityError>
pub fn start( &mut self, loaded: LoadedSecurity, ) -> Result<Arc<ServerSecurity>, SecurityError>
Mark only after installation succeeds. A failed replacement must remain eligible for retry even if the source files have not changed again.
This is the only place the credential issuer is set.
Sourcepub fn install(
&mut self,
loaded: LoadedSecurity,
security: &ServerSecurity,
) -> Result<(), SecurityError>
pub fn install( &mut self, loaded: LoadedSecurity, security: &ServerSecurity, ) -> Result<(), SecurityError>
Replaces transport and control-plane credentials. A differing issuer is
never applied; it is reported once per distinct staged value and
remains visible through Self::issuer_change_pending.
Sourcepub fn issuer(&self) -> Option<Arc<dyn CredentialIssuer + Send + Sync>>
pub fn issuer(&self) -> Option<Arc<dyn CredentialIssuer + Send + Sync>>
The durable customer-credential issuer from the manifest’s issuer
entry, fixed at Self::start. None before start or when the
manifest configures none; issuance then answers 501.
Sourcepub fn issuer_change_pending(&self) -> bool
pub fn issuer_change_pending(&self) -> bool
True while the most recently installed manifest names a different issuer than the live one. Only a restart applies it.
Sourcepub async fn load(
&mut self,
now: Timestamp,
) -> Result<Option<LoadedSecurity>, SecurityError>
pub async fn load( &mut self, now: Timestamp, ) -> Result<Option<LoadedSecurity>, SecurityError>
Reads the manifest and every file it references, validates them, and stages a complete generation without making it live.
Each load builds a fresh control-plane bearer verifier keyed by a new
random secret, so only HMAC digests of the static tokens are retained.
When the manifest configures Google identity, this also refreshes
Google’s signing keys if a refresh is due: after a successful fetch,
at half the key set’s lifetime, clamped between five seconds and five
minutes; after a failure, five minutes later. A fetched key set is
usable until now plus the lifetime its Cache-Control/Age
headers allow: five minutes without cache metadata, and never more
than one hour. A failed fetch keeps
the previous keys and their original expiry, or fails the load when
there are none. A fetched key set that fails validation fails the
load and also leaves the previous keys in place.
Returns Ok(None) when the manifest, every referenced file, and any
signing keys and their expiry are unchanged since the generation last passed to
start or install.
§Errors
Returns a SecurityError for an unreadable file, unknown manifest
fields, a malformed or out-of-bounds credential, a duplicate
credential mapping, an issuer secret that is malformed or equal to a
bearer token, invalid TLS material, or unavailable signing keys. The
live generation is unaffected.