pub struct BundleSlot {Show 13 fields
pub bucket: String,
pub account: Option<String>,
pub name: Option<String>,
pub machines: Vec<String>,
pub runtime_version: Option<String>,
pub serve_bins: BTreeMap<String, PathBuf>,
pub serve_build: Option<BinBuild>,
pub lifecycle: BundleLifecycle,
pub port: Option<u16>,
pub env: BTreeMap<String, String>,
pub revalidate: Option<RevalidateSlot>,
pub zone: Option<String>,
pub verify_serving: bool,
}Expand description
Parsed [providers.bundle] slot — everything the sync arm needs that is
declared rather than derived.
[providers.bundle]
use = "cloudflare" # R2 credentials resolve via this provider
bucket = "yah-dev-bundles" # the append-only bundle store
machines = ["us-east-001"] # explicit placement (or `required = {…}`)
name = "yah-marketing" # stable workload handle; defaults to the service name
lifecycle = "keep-alive" # or "on-demand"
idle_ttl_ms = 300000 # on-demand only
runtime_version = "0.8.20" # vanilla bundles only (no serve binary)
serve_bins = { x86_64-unknown-linux-musl = "target/…/mesofact-serve" }
# …or, instead of naming pre-built paths, name the recipe that builds them:
# [providers.bundle.serve_build]
# pipeline = "mesofact-musl"
# binary = "mesofact"
# triples = ["x86_64-unknown-linux-musl"]
zone = "yah.dev" # front door to serving-verify; defaults
# to the service's own domain
verify_serving = true # default; see the field docs
# Environment for the serve process, as source URIs resolved at deploy
# (R556-T12). An SSR route reading a private source needs this or it gets
# a credential-less server on the node.
[providers.bundle.env]
ANALYTICS_R2_ACCESS_KEY = "vault:cloudflare-r2-access-key-id"
ANALYTICS_R2_BUCKET = "yah-analytics" # bare literal: not a secretFields§
§bucket: StringR2 bucket holding the bundle store. Append-only, blob-deduped.
account: Option<String>Cloudflare account id override. None → resolve from the workspace’s
cloudflare provider config / CF_ACCOUNT_ID.
name: Option<String>Stable operator-facing workload name. yubaba requires one for a bundle
deploy: the digest is the content and changes on every rebuild, so it
is not a usable handle for list / stop.
machines: Vec<String>Explicitly named target machines, in deploy order. Empty → fall back to
the slot’s required = {…} placement spec.
runtime_version: Option<String>Stock runtime version recorded as runtime = "mesofact/<version>" for a
vanilla bundle. Ignored when serve_bins is non-empty. None → the
caller’s own version.
serve_bins: BTreeMap<String, PathBuf><triple> → <path to serve binary>. Any entry makes this a
runtime = "self" bundle that carries its own serve binaries.
serve_build: Option<BinBuild>Build the serve binaries on demand instead of naming pre-built paths
(R746-F2). Mutually exclusive with serve_bins; either one makes this a
runtime = "self" bundle.
lifecycle: BundleLifecycleHow kamaji supervises the served bundle.
port: Option<u16>Port the served bundle listens on (R599-F12). None → kamaji’s
node-wide default (8080), which is only correct while the node hosts a
single bundle; declare one per workload to put several on a node.
env: BTreeMap<String, String>[providers.bundle.env] — environment for the serve process, as
NAME → source URI (R556-T12).
Values are the source declaration, kept verbatim and resolved
deploy-side by yah cloud apply — vault:<slot>, env:<VAR>, a
pipe-joined fallback chain of either, or a bare literal for a
known-non-secret value. Same grammar ~/.yah/qed/secrets.toml uses, so
there is one source-URI vocabulary in the camp rather than two.
Parsing stays here and resolution does not: this crate is offline by
construction (a misconfigured mirror must fail before a build runs), and
only the syncing machine has the vault. The RevalidateSlot::mirror_key_env
→ RevalidateSlot::to_workload_payload split is the same shape one
level down.
revalidate: Option<RevalidateSlot>Optional revalidate receiver config (R330-F12). Some → the deploy
also stands up a mesofact serve --revalidate process.
zone: Option<String>Public zone whose front door is checked after a deploy (R703-T7).
None → the service’s own domain, which is the shape every mirror in
tree uses; declare one only when the bundle serves a zone that isn’t it.
Unlike [providers.static], this is optional: the static slot’s zone
is load-bearing for the Worker route and cache purge, whereas here it
only names what to probe.
verify_serving: boolWhether a deploy is checked against the live front door (R703-T7).
Defaults to true, and the only reason to turn it off is a deliberately in-flight front-door migration — with a comment naming the ticket. It is declared in config rather than passed as a CLI flag for the same reason the static slot’s is: switching it off should be a reviewable diff, not an invocation habit that quietly becomes permanent.
Implementations§
Source§impl BundleSlot
impl BundleSlot
Sourcepub fn parse(mirror: &MirrorConfig, service: &str, env: &str) -> Result<Self>
pub fn parse(mirror: &MirrorConfig, service: &str, env: &str) -> Result<Self>
Parse the mirror’s [providers.bundle] slot.
Every failure names the offending field plus the service and env, so the operator gets a file to open rather than a type error. Validation is total and offline — nothing here touches the network, so a misconfigured mirror fails before a build runs (R330-B5 fail-fast discipline).
Sourcepub fn serving_zone<'a>(&'a self, service_domain: &'a str) -> &'a str
pub fn serving_zone<'a>(&'a self, service_domain: &'a str) -> &'a str
The zone whose front door a deploy of this bundle is checked against:
the slot’s zone, else the service’s own domain.
Sourcepub fn workload_name<'a>(&'a self, service: &'a str) -> &'a str
pub fn workload_name<'a>(&'a self, service: &'a str) -> &'a str
Stable workload handle: the slot’s name, else the service name.
Sourcepub fn is_self_contained(&self) -> bool
pub fn is_self_contained(&self) -> bool
True when the assembled bundle carries its own serve binaries
(runtime = "self") rather than resolving a stock node runtime asset.
Keyed on the declaration, not on what is on disk: a serve_build slot
is self-contained before its binary has ever been built, because the
mirror said so. Deriving the shape from disk state instead is the bug
this relay exists to remove — it makes a bundle’s shape depend on which
machine ran the sync.
Sourcepub fn serve_bundle(
&self,
digest: &str,
runtime: &str,
env: BTreeMap<String, String>,
) -> MesofactServeBundle
pub fn serve_bundle( &self, digest: &str, runtime: &str, env: BTreeMap<String, String>, ) -> MesofactServeBundle
Build the {digest, runtime, lifecycle} triple a mesofact-static
workload carries once its bundle is published.
runtime wire-mirrors yah_mesofact_bundle::BundleRuntime, so it is
taken from the manifest the assembler actually wrote rather than
re-derived here — the manifest is what the node will verify against.
env is the resolved serve environment, passed in rather than read
off self.env: this crate holds source URIs, and only the syncing
machine can turn a vault:<slot> into a value. Same by-value handoff
RevalidateSlot::to_workload_payload takes, for the same reason —
the node must never see a keystore slot name (R556-T12).
Trait Implementations§
Source§impl Clone for BundleSlot
impl Clone for BundleSlot
Source§fn clone(&self) -> BundleSlot
fn clone(&self) -> BundleSlot
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Debug for BundleSlot
impl Debug for BundleSlot
impl Eq for BundleSlot
Source§impl PartialEq for BundleSlot
impl PartialEq for BundleSlot
impl StructuralPartialEq for BundleSlot
Auto Trait Implementations§
impl Freeze for BundleSlot
impl RefUnwindSafe for BundleSlot
impl Send for BundleSlot
impl Sync for BundleSlot
impl Unpin for BundleSlot
impl UnsafeUnpin for BundleSlot
impl UnwindSafe for BundleSlot
Blanket Implementations§
impl<T> Allocation for T
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> Downcast for Twhere
T: Any,
impl<T> Downcast for Twhere
T: Any,
Source§fn into_any(self: Box<T>) -> Box<dyn Any>
fn into_any(self: Box<T>) -> Box<dyn Any>
Box<dyn Trait> (where Trait: Downcast) to Box<dyn Any>. Box<dyn Any> can
then be further downcast into Box<ConcreteType> where ConcreteType implements Trait.Source§fn into_any_rc(self: Rc<T>) -> Rc<dyn Any>
fn into_any_rc(self: Rc<T>) -> Rc<dyn Any>
Rc<Trait> (where Trait: Downcast) to Rc<Any>. Rc<Any> can then be
further downcast into Rc<ConcreteType> where ConcreteType implements Trait.Source§fn as_any(&self) -> &(dyn Any + 'static)
fn as_any(&self) -> &(dyn Any + 'static)
&Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot
generate &Any’s vtable from &Trait’s.Source§fn as_any_mut(&mut self) -> &mut (dyn Any + 'static)
fn as_any_mut(&mut self) -> &mut (dyn Any + 'static)
&mut Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot
generate &mut Any’s vtable from &mut Trait’s.Source§impl<T> Downcast for Twhere
T: Any,
impl<T> Downcast for Twhere
T: Any,
Source§fn into_any(self: Box<T>) -> Box<dyn Any>
fn into_any(self: Box<T>) -> Box<dyn Any>
Box<dyn Trait> (where Trait: Downcast) to Box<dyn Any>, which can then be
downcast into Box<dyn ConcreteType> where ConcreteType implements Trait.Source§fn into_any_rc(self: Rc<T>) -> Rc<dyn Any>
fn into_any_rc(self: Rc<T>) -> Rc<dyn Any>
Rc<Trait> (where Trait: Downcast) to Rc<Any>, which can then be further
downcast into Rc<ConcreteType> where ConcreteType implements Trait.Source§fn as_any(&self) -> &(dyn Any + 'static)
fn as_any(&self) -> &(dyn Any + 'static)
&Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot
generate &Any’s vtable from &Trait’s.Source§fn as_any_mut(&mut self) -> &mut (dyn Any + 'static)
fn as_any_mut(&mut self) -> &mut (dyn Any + 'static)
&mut Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot
generate &mut Any’s vtable from &mut Trait’s.Source§impl<T> DowncastSend for T
impl<T> DowncastSend for T
Source§impl<T> DowncastSync for T
impl<T> DowncastSync for T
Source§impl<T> DowncastSync for T
impl<T> DowncastSync for T
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<K, Q> Equivalent<Q> for K
impl<K, Q> Equivalent<Q> for K
Source§fn equivalent(&self, key: &Q) -> bool
fn equivalent(&self, key: &Q) -> bool
key and return true if they are equal.impl<T> ErasedDestructor for Twhere
T: 'static,
impl<T> Fruit for T
impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more