pub struct RenderInput<'a> {
pub machine: &'a MachineConfig,
pub yubaba_url: String,
pub yubaba_sha256: String,
pub yubaba_channel: String,
pub headscale_preauth_key: Option<String>,
pub mesh_url: Option<String>,
pub cloudflared_token: Option<String>,
pub yubaba_cosign_identity_regexp: Option<String>,
}Expand description
Inputs needed to render mirror.yml for a single machine.
Fields§
§machine: &'a MachineConfig§yubaba_url: StringHTTPS URL of the yah-yubaba release tar.gz (e.g. a GitHub release
asset published by .github/workflows/release.yml). Cloud-init’s
runcmd downloads it, verifies sha256 against Self::yubaba_sha256,
extracts, and installs /usr/local/bin/yubaba. Use
PLACEHOLDER_YUBABA_URL for dry-run previews.
yubaba_sha256: StringLowercase hex sha256 of the tar.gz at yubaba_url. Cloud-init verifies
this with sha256sum -c - against the downloaded archive and fails
the boot if it doesn’t match.
yubaba_channel: StringRelease channel passed to yah-yubaba serve --channel. One of
"stable" or "beta". Use DEFAULT_YUBABA_CHANNEL for Phase 1.
headscale_preauth_key: Option<String>Headscale pre-auth key. Some ⟺ this machine is joining an existing
mesh: the renderer emits the tailscaled install + tailscale up join
block (gated on this being Some, see render). None ⟺ standalone
/ coordinator-to-be — no mesh to join yet, so no join block is emitted
(the node becomes the coordinator later via yah mesh bootstrap).
mesh_url: Option<String>Stable URL of the Headscale coordinator (https://mesh.<domain>).
When set (R040-F18), the rendered cloud-init passes
--login-server <url> to tailscale up so the new machine joins
the camp’s Headscale instead of Tailscale SaaS. When None, the
{{MESH_LOGIN_SERVER_ARG}} placeholder is replaced with an empty
string, preserving the existing Tailscale SaaS behaviour.
cloudflared_token: Option<String>Cloudflare Tunnel token for cloudflared service install --token ....
None → no cloudflared install (mesh-only node). When Some, the
renderer emits the full cloudflared apt-repo install + service enable
block into runcmd in place of {{CLOUDFLARED_BLOCK}}.
yubaba_cosign_identity_regexp: Option<String>When Some, render the cosign install + cosign verify-blob runcmd
block into {{COSIGN_VERIFY_BLOCK}}, gating the yubaba tarball on a
keyless OIDC signature whose certificate identity matches this regexp
(e.g. ^https://github\.com/yah-ai/yah/). The sha256 check stays
in parallel as belt-and-suspenders (R330-F20, W203 §1.4). When None
the placeholder substitutes to an empty string and the bootstrap stays
on the sha256-only path.
Trait Implementations§
Auto Trait Implementations§
impl<'a> Freeze for RenderInput<'a>
impl<'a> RefUnwindSafe for RenderInput<'a>
impl<'a> Send for RenderInput<'a>
impl<'a> Sync for RenderInput<'a>
impl<'a> Unpin for RenderInput<'a>
impl<'a> UnsafeUnpin for RenderInput<'a>
impl<'a> UnwindSafe for RenderInput<'a>
Blanket Implementations§
impl<T> Allocation for T
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> Downcast for Twhere
T: Any,
impl<T> Downcast for Twhere
T: Any,
Source§fn into_any(self: Box<T>) -> Box<dyn Any>
fn into_any(self: Box<T>) -> Box<dyn Any>
Box<dyn Trait> (where Trait: Downcast) to Box<dyn Any>. Box<dyn Any> can
then be further downcast into Box<ConcreteType> where ConcreteType implements Trait.Source§fn into_any_rc(self: Rc<T>) -> Rc<dyn Any>
fn into_any_rc(self: Rc<T>) -> Rc<dyn Any>
Rc<Trait> (where Trait: Downcast) to Rc<Any>. Rc<Any> can then be
further downcast into Rc<ConcreteType> where ConcreteType implements Trait.Source§fn as_any(&self) -> &(dyn Any + 'static)
fn as_any(&self) -> &(dyn Any + 'static)
&Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot
generate &Any’s vtable from &Trait’s.Source§fn as_any_mut(&mut self) -> &mut (dyn Any + 'static)
fn as_any_mut(&mut self) -> &mut (dyn Any + 'static)
&mut Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot
generate &mut Any’s vtable from &mut Trait’s.Source§impl<T> Downcast for Twhere
T: Any,
impl<T> Downcast for Twhere
T: Any,
Source§fn into_any(self: Box<T>) -> Box<dyn Any>
fn into_any(self: Box<T>) -> Box<dyn Any>
Box<dyn Trait> (where Trait: Downcast) to Box<dyn Any>, which can then be
downcast into Box<dyn ConcreteType> where ConcreteType implements Trait.Source§fn into_any_rc(self: Rc<T>) -> Rc<dyn Any>
fn into_any_rc(self: Rc<T>) -> Rc<dyn Any>
Rc<Trait> (where Trait: Downcast) to Rc<Any>, which can then be further
downcast into Rc<ConcreteType> where ConcreteType implements Trait.Source§fn as_any(&self) -> &(dyn Any + 'static)
fn as_any(&self) -> &(dyn Any + 'static)
&Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot
generate &Any’s vtable from &Trait’s.Source§fn as_any_mut(&mut self) -> &mut (dyn Any + 'static)
fn as_any_mut(&mut self) -> &mut (dyn Any + 'static)
&mut Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot
generate &mut Any’s vtable from &mut Trait’s.Source§impl<T> DowncastSend for T
impl<T> DowncastSend for T
Source§impl<T> DowncastSync for T
impl<T> DowncastSync for T
Source§impl<T> DowncastSync for T
impl<T> DowncastSync for T
impl<T> ErasedDestructor for Twhere
T: 'static,
impl<T> Fruit for T
impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more