pub struct MediatorReadinessConfig {
pub enabled: bool,
pub retry_secs: u64,
pub backoff_cap_secs: u64,
pub max_wait_secs: u64,
pub on_timeout: ReadinessTimeoutPolicy,
pub reconnect: bool,
pub reconnect_backoff_cap_secs: u64,
pub reconnect_max_elapsed_secs: u64,
}Expand description
Startup readiness gate for the mediator DIDComm connection.
On cold start a VTA can initiate its outbound mediator handshake before its own DID document is resolvable — the DID host hasn’t published it, or the load-balancer target fronting it isn’t healthy yet. The mediator authenticates the VTA by resolving that DID itself, so it can’t get the key to decrypt the authcrypt handshake and rejects it, producing a burst of 403s.
This gate makes the VTA wait until its own DID fully resolves over the
network — through the configured resolver, so it exercises the same path
the mediator takes — before connecting. Only network-resolved methods
(did:webvh, did:web) are gated; a did:key VTA resolves from its own
identifier with no network fetch and skips the wait.
Fields§
§enabled: boolEnable the gate. Default true.
retry_secs: u64Base (initial) seconds between probe attempts. The actual wait uses
capped exponential backoff with full jitter — attempt n sleeps a
random duration in [0, min(backoff_cap_secs, retry_secs * 2^n)] — so a
fleet of VTAs coming up together doesn’t probe in lock-step. Default 5.
backoff_cap_secs: u64Upper bound on the per-attempt backoff interval (the “cap” in the exponential-backoff-with-jitter scheme). The jittered wait never exceeds this. Default 30.
max_wait_secs: u64Maximum seconds the gate waits before applying on_timeout. The wait is
cancellable: a shutdown signal abandons it immediately rather than
holding the process open for the remainder. Default 300.
on_timeout: ReadinessTimeoutPolicyWhat to do when the gate times out. Default skip.
reconnect: boolPersistent reconnect supervisor. After the self-readiness gate passes,
the mediator connect can still fail — most commonly because the
mediator’s own resolver holds a negative-cache entry for the VTA host
and can’t fetch our DID document to complete the authcrypt handshake
(a NetworkError{status_code:None} → 403). That clears itself once the
mediator’s negative cache expires, so rather than give up until the next
restart, keep retrying with capped exponential backoff + full jitter.
Each attempt first re-confirms the VTA can resolve its own DID, so the
mediator is never touched while the VTA is unresolvable.
This also covers an established session whose inbound loop ends: the
supervisor tears the session down and reconnects, instead of leaving the
VTA silently deaf until an operator restarts it. Setting this false
restores the legacy single-shot behaviour (one attempt, then nothing
until the next restart). Default true.
reconnect_backoff_cap_secs: u64Upper bound on the reconnect backoff interval (seconds) — the “cap” for
the persistent-reconnect scheme. The jittered retry wait never exceeds
this. Larger than backoff_cap_secs (the gate’s cap) because the
reconnect horizon must comfortably outlast a resolver negative-cache TTL,
which can be many minutes. Default 60.
reconnect_max_elapsed_secs: u64Give up reconnecting after this many seconds of continuous failure.
0 = never give up (retry forever at the capped, jittered interval).
A bounded retry rate is safe to run indefinitely and lets the VTA
self-heal without any operator restart.
The clock is measured from the start of the current run of failures, not from process start, and resets after any session that stayed up long enough to count as healthy — so a VTA that ran for a week and then dropped gets the full budget rather than one it exhausted days ago. Default 0.
Trait Implementations§
Source§impl Clone for MediatorReadinessConfig
impl Clone for MediatorReadinessConfig
Source§fn clone(&self) -> MediatorReadinessConfig
fn clone(&self) -> MediatorReadinessConfig
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more