Skip to main content

Crate tuff_console

Crate tuff_console 

Source
Expand description

The Tuff console server (RFC-108): stores the reports that tuff console publish sends and serves them over HTTP.

store owns the SQLite file: schema and migrations, report ingest with deduplication, the audit events and inventory computed on ingest, and publish keys. oidc verifies the GitHub Actions tokens that publish without a secret. server owns the HTTP API and the rules for which address the server may bind, and ui embeds the web pages it serves at /. views shapes stored reports for those pages and demo generates the sample data of --demo. The tuff binary wires them to tuff console serve and tuff console key.

Re-exports§

pub use oidc::Trust;
pub use oidc::Verifier;
pub use server::ServeConfig;
pub use server::ServerOptions;
pub use server::check_bind;
pub use server::router;
pub use server::run;
pub use server::serve;
pub use store::EventFilter;
pub use store::EventRow;
pub use store::IngestOutcome;
pub use store::KeyGrant;
pub use store::KeyInfo;
pub use store::ProjectRow;
pub use store::Store;
pub use store::default_data_dir;

Modules§

demo
Sample projects for tuff console serve --demo.
events
What a report says about a project, flattened, and the audit events that follow from comparing two of them (RFC-108 D7).
oidc
Publishing from GitHub Actions without a secret (RFC-108 D5).
server
The console’s HTTP API (RFC-108 D5 and D9) and the rules for where it may listen.
store
The console’s SQLite file (RFC-108 D6).
ui
The console’s web UI: three static files compiled into the binary. They call the JSON API under /api/v1 and load nothing from elsewhere.
views
The read side of the API (RFC-108 D9): what the latest report of every project says, grouped the way each UI view needs it.