Skip to main content

Module security

Module security 

Source
Expand description

Control-plane identities, route authorization, and operator-approved provisioner policies.

Structs§

ControlIdentity
A stable, non-secret audit identity chosen by the deployment.
ProvisionerLimits
What a provisioner identity may grant beyond its fixed route scope.
ProvisionerPolicyTemplate
The exact policy an operator permits a provisioner to publish.
SecurityError
A refused security configuration, credential file, TLS material or key set.
SecurityPolicy
An immutable, validated mapping. Publish verification and authorization together; rotating one without the other would temporarily assign old credentials new roles.
ServerSecurity
Shared by the listener and router. A request pins one complete generation.

Enums§

Role
Roles are disjoint. An operator credential cannot fund an instance, and a provisioner reaches only the self-service subset of the admin API (#39).