Expand description
The Tuff console server (RFC-108): stores the reports that
tuff console publish sends and serves them over HTTP.
store owns the SQLite file: schema and migrations, report ingest with
deduplication, the audit events and inventory computed on ingest, and
publish keys. oidc verifies the GitHub Actions tokens that publish
without a secret. server owns the HTTP API and the rules for which
address the server may bind, and ui embeds the web pages it serves
at /. views shapes stored reports for those pages and demo
generates the sample data of --demo. The tuff binary wires them to
tuff console serve and tuff console key.
Re-exports§
pub use oidc::Trust;pub use oidc::Verifier;pub use server::ServeConfig;pub use server::ServerOptions;pub use server::check_bind;pub use server::router;pub use server::run;pub use server::serve;pub use store::EventFilter;pub use store::EventRow;pub use store::IngestOutcome;pub use store::KeyGrant;pub use store::KeyInfo;pub use store::ProjectRow;pub use store::Store;pub use store::default_data_dir;
Modules§
- demo
- Sample projects for
tuff console serve --demo. - events
- What a report says about a project, flattened, and the audit events that follow from comparing two of them (RFC-108 D7).
- oidc
- Publishing from GitHub Actions without a secret (RFC-108 D5).
- server
- The console’s HTTP API (RFC-108 D5 and D9) and the rules for where it may listen.
- store
- The console’s SQLite file (RFC-108 D6).
- ui
- The console’s web UI: three static files compiled into the binary. They
call the JSON API under
/api/v1and load nothing from elsewhere. - views
- The read side of the API (RFC-108 D9): what the latest report of every project says, grouped the way each UI view needs it.