Expand description
@yah:relay(R409, “Envoy — providers and internal verb catalog (W144)”) @yah:at(2026-06-02T20:58:35Z) @yah:status(open) @arch:see(.yah/docs/working/W144-envoy-providers-and-tiering.md)
Re-exports§
pub use cloudflare::CfAccountInfo;pub use cloudflare::CloudflareClient;pub use cloudflare::CreateR2BucketResult;pub use cloudflare::CreateTokenResult;pub use cloudflare::CreateTunnelResult;pub use cloudflare::GrantScope;pub use cloudflare::R2BucketInfo;pub use cloudflare::R2CustomDomain;pub use cloudflare::TokenGrant;pub use cloudflare::TunnelConnState;pub use cloudflare::TunnelDnsRecord;pub use cloudflare::TunnelDriftRow;pub use cloudflare::TunnelDriftState;pub use cloudflare::WorkerDeployResult;pub use cloudflare::MESOFACT_STATIC_GRANTS;pub use hetzner::HetznerDriver;pub use cloudflare_envoy::CloudflareEnvoy;pub use hetzner_envoy::HetznerEnvoy;pub use digitalocean::DigitalOceanClient;pub use digitalocean::DigitalOceanEnvoy;pub use digitalocean::DoCreateDropletSpec;pub use floating_ip::on_ingress_owner_changed;pub use floating_ip::reconcile_assignment;pub use floating_ip::FloatingIpAssignOutcome;pub use floating_ip::FloatingIpProvider;pub use floating_ip::FloatingIpState;pub use floating_ip::FloatingIpTarget;pub use floating_ip::floating_ip_provider_for;pub use floating_ip::plan_ingress_owner_effect;pub use floating_ip::provider_has_floating_ip_adapter;pub use floating_ip::resolve_ingress_owner;pub use floating_ip::IngressOwnerEffect;pub use floating_ip::OwnerLiveness;pub use floating_ip::QuorumHealth;pub use hetzner_floating_ip::HetznerFloatingIp;pub use ovh_floating_ip::OvhFloatingIp;pub use vultr_floating_ip::VultrFloatingIp;
Modules§
- cloudflare
- Cloudflare management API client — accounts, tunnels, R2 buckets, DNS.
- cloudflare_
envoy CloudflareEnvoy— tier-S adapter for Cloudflare R2 (cloud.object.*) and Cloudflare DNS (dns.*) verbs (R409-T6).- digitalocean
DigitalOceanEnvoy— second nativecloud.vps.*adapter, spike scope (R409-T10). Together with [HetznerEnvoy] this is the catalog-shape validator R409-T11’s postmortem decides on.- floating_
ip - Provider-abstracted floating/reserved-IP mobility (R594-F5).
- hetzner
- @yah:ticket(R040-F9, “Lift KeysStore into shared crate; cloud reads vault then env”)
@yah:at(2026-05-05T00:33:17Z)
@yah:status(review)
@yah:assignee(agent:claude)
@yah:parent(R040)
@yah:handoff(“DRY-up landed: app/yah/cli/src/keys.rs lifted to crates/yah/keys (own Cargo.toml, ProjectDirs::data_dir() unchanged so the existing on-disk vault keeps working). app/yah/cli now
keys = { path = ... }deps the new crate; aes-gcm and rand drops out of the CLI’s direct deps (transitive now). main.rs/agent.rs/agentd.rs swappedmod keys;/crate::keys::for the external crate path. cloud crate gainedkeysdep +HetznerDriver::from_default_sources()that tries KeysStore::open().get(slot) per-key then falls back to env: hetzner-api-token↔HETZNER_API_TOKEN, hetzner-s3-access-key↔HETZNER_S3_ACCESS_KEY, hetzner-s3-secret-key↔HETZNER_S3_SECRET_KEY. Vault open errors are swallowed (no vault → fall back to env). yah cloud callsites (app/yah/cli/src/cloud.rs:257 + :423) flipped to from_default_sources(). Tests: 6/6 green for keys (moved from CLI), 26/26 green for cloud (no test changes — all existing). cargo check -p keys + -p cloud + -p yah –bin yah-agentd clean.”) @yah:next(“Follow-up scoped as R043 (relay) with phases F1 bridge / F2 naming / F3 cleanup — unify desktop api_keys with this vault, KeysStore as canonical, drop keyring dep once soaked.”) @yah:next(“Optional: yah keys CLI could grow--from-keychain <provider>flag to one-shot import a desktop-vault token without typing it. Not urgent; the user can already pipe viasecurity find-generic-password ... | yah keys set --from-stdin <slot>.”) @yah:verify(“cargo test -p keys”) @yah:verify(“cargo test -p cloud”) @yah:verify(“cargo check -p yah –bin yah-agentd”) @yah:gotcha(“cargo check –workspace currently fails on app/yah/cli/src/cloud.rs:210 because handle_agent is referenced but not yet defined — that’s parallel R040-F7 WIP (yah cloud agent ping/services/logs against yah-yubaba), not this refactor. Thekeys = ...and HetznerDriver::from_default_sources additions compile clean on their own.”) - hetzner_
envoy HetznerEnvoy— adapter that exposes the existingHetznerDriverthrough the envoy framework’scloud.vps.*verbs (R409-T5).- hetzner_
floating_ ip HetznerFloatingIp—floating_ip.*adapter for Hetzner Cloud floating IPs (R594-F5).- ovh_
floating_ ip OvhFloatingIp—floating_ip.*adapter for OVH Additional IPs (R594-F5).- vultr_
floating_ ip VultrFloatingIp—floating_ip.*adapter for Vultr reserved IPs (R594-F5).
Structs§
- Bucket
Ref - Reference to a created object-storage bucket.
- Project
Id - Logical project scope. Hetzner Cloud tokens are already project-scoped, so this is a no-op placeholder there.
- Server
Id - Opaque server identifier returned by the provider.
- Server
Spec - Parameters for a new machine.
- Server
Summary - Snapshot of a live server returned by
MachineProvider::find_server_by_name.
Enums§
- Bucket
Acl - Canned S3 ACL policies for bucket-level access control.
- Location
- Phase-1 cloud regions.
- Server
Status - Observed server lifecycle status (mirrors Hetzner Cloud’s status field).
Traits§
- Machine
Provider - Abstracts over cloud providers for the machine + bucket lifecycle.