Skip to main content

Crate tollgate_store

Crate tollgate_store 

Source
Expand description

Storage abstraction for tollgate.

Narrow traits separate the data plane from lifecycle authority:

  • LeaseAllocator — atomically debit an account’s balance into fenced, TTL-bounded leases; settle them by release or expiry reclaim.
  • SnapshotSource — fetch compiled account snapshots and subscribe to pushes.
  • UsageSink — idempotent, fencing-checked batch ingest of usage events.
  • KeySource — validated, revisioned pages of active credential digests.
  • KeyDirectory — durable credential lifecycle; instances do not need this mutation authority.

Every method takes now as an argument: the store, like the core, never reads a clock. That keeps backends deterministic under test and puts the clock decision in exactly one place (the client runtime / server).

MemoryStore is the reference implementation: it exists to prove the traits aren’t secretly shaped like any particular database, to make the correctness suite run without infrastructure, and to serve as executable documentation of the settlement rules a real backend must reproduce.

Re-exports§

pub use audit::AdminAuthority;
pub use audit::AdminReceipt;
pub use audit::AdminState;
pub use clock::Clock;
pub use clock::ManualClock;
pub use clock::SystemClock;
pub use credentials::CredentialRecord;
pub use credentials::CredentialSet;
pub use credentials::DEFAULT_KEY_PAGE_LIMIT;
pub use credentials::KeyPage;
pub use credentials::KeySource;
pub use credentials::MAX_KEY_PAGE_LIMIT;
pub use credentials::MAX_KEY_REVISION;
pub use credentials::validate_key_page_limit;
pub use memory::MemoryStore;
pub use memory::StoredRecords;
pub use traits::AccountConfig;
pub use traits::AccountView;
pub use traits::AdminStore;
pub use traits::AllocateError;
pub use traits::Allocation;
pub use traits::BudgetError;
pub use traits::Conservation;
pub use traits::CreateAccountError;
pub use traits::CredentialActivity;
pub use traits::CredentialActivityState;
pub use traits::DEFAULT_RECLAIM_BATCH_LIMIT;
pub use traits::DEFAULT_ROLLOVER_BATCH_LIMIT;
pub use traits::GrantPolicy;
pub use traits::GrantPolicyError;
pub use traits::IngestError;
pub use traits::IngestReport;
pub use traits::KeyDirectory;
pub use traits::KeyError;
pub use traits::KeyRecord;
pub use traits::KeySnapshotError;
pub use traits::KeySummary;
pub use traits::LeaseAllocator;
pub use traits::MAX_INGEST_BATCH;
pub use traits::PUSH_CHANNEL_CAPACITY;
pub use traits::PublishSnapshotError;
pub use traits::ReclaimBatch;
pub use traits::ReclaimedLease;
pub use traits::Revocation;
pub use traits::RolledAccount;
pub use traits::RolloverBatch;
pub use traits::SetStatusError;
pub use traits::SnapshotPush;
pub use traits::SnapshotResolution;
pub use traits::SnapshotSource;
pub use traits::StatusChange;
pub use traits::StoreError;
pub use traits::StoreHealth;
pub use traits::UsageSink;
pub use traits::pushes_exceed_capacity;

Modules§

audit
Evidence returned by administrative mutations, captured at their serialization point. The HTTP boundary supplies identity and time; a second store read must never be substituted for the state this operation actually replaced.
clock
The single place wall-clock time enters the system.
credentials
Read-only, revisioned credential pages. Lifecycle authority stays in KeyDirectory.
memory
The in-memory reference backend.
traits
The storage traits and their shared vocabulary.
wire
The HTTP wire contract between tollgate-server and tollgate-client’s HTTP transport. One place, versioned by API_PREFIX on the server.