Expand description
Storage abstraction for tollgate.
Narrow traits separate the data plane from lifecycle authority:
LeaseAllocator— atomically debit an account’s balance into fenced, TTL-bounded leases; settle them by release or expiry reclaim.SnapshotSource— fetch compiled account snapshots and subscribe to pushes.UsageSink— idempotent, fencing-checked batch ingest of usage events.KeySource— validated, revisioned pages of active credential digests.KeyDirectory— durable credential lifecycle; instances do not need this mutation authority.
Every method takes now as an argument: the store, like the core, never
reads a clock. That keeps backends deterministic under test and puts the
clock decision in exactly one place (the client runtime / server).
MemoryStore is the reference implementation: it exists to prove the
traits aren’t secretly shaped like any particular database, to make the
correctness suite run without infrastructure, and to serve as executable
documentation of the settlement rules a real backend must reproduce.
Re-exports§
pub use audit::AdminAuthority;pub use audit::AdminReceipt;pub use audit::AdminState;pub use clock::Clock;pub use clock::ManualClock;pub use clock::SystemClock;pub use credentials::CredentialRecord;pub use credentials::CredentialSet;pub use credentials::DEFAULT_KEY_PAGE_LIMIT;pub use credentials::KeyPage;pub use credentials::KeySource;pub use credentials::MAX_KEY_PAGE_LIMIT;pub use credentials::MAX_KEY_REVISION;pub use credentials::validate_key_page_limit;pub use memory::MemoryStore;pub use memory::StoredRecords;pub use traits::AccountConfig;pub use traits::AccountView;pub use traits::AdminStore;pub use traits::AllocateError;pub use traits::Allocation;pub use traits::BudgetError;pub use traits::Conservation;pub use traits::CreateAccountError;pub use traits::CredentialActivity;pub use traits::CredentialActivityState;pub use traits::DEFAULT_RECLAIM_BATCH_LIMIT;pub use traits::DEFAULT_ROLLOVER_BATCH_LIMIT;pub use traits::GrantPolicy;pub use traits::GrantPolicyError;pub use traits::IngestError;pub use traits::IngestReport;pub use traits::KeyDirectory;pub use traits::KeyError;pub use traits::KeyRecord;pub use traits::KeySnapshotError;pub use traits::KeySummary;pub use traits::LeaseAllocator;pub use traits::MAX_INGEST_BATCH;pub use traits::PUSH_CHANNEL_CAPACITY;pub use traits::PublishSnapshotError;pub use traits::ReclaimBatch;pub use traits::ReclaimedLease;pub use traits::Revocation;pub use traits::RolledAccount;pub use traits::RolloverBatch;pub use traits::SetStatusError;pub use traits::SnapshotPush;pub use traits::SnapshotResolution;pub use traits::SnapshotSource;pub use traits::StatusChange;pub use traits::StoreError;pub use traits::StoreHealth;pub use traits::UsageSink;pub use traits::pushes_exceed_capacity;
Modules§
- audit
- Evidence returned by administrative mutations, captured at their serialization point. The HTTP boundary supplies identity and time; a second store read must never be substituted for the state this operation actually replaced.
- clock
- The single place wall-clock time enters the system.
- credentials
- Read-only, revisioned credential pages. Lifecycle authority stays in
KeyDirectory. - memory
- The in-memory reference backend.
- traits
- The storage traits and their shared vocabulary.
- wire
- The HTTP wire contract between
tollgate-serverandtollgate-client’s HTTP transport. One place, versioned byAPI_PREFIXon the server.