Skip to main content

Module provider

Module provider 

Source
Expand description

@yah:relay(R409, “Envoy — providers and internal verb catalog (W144)”) @yah:at(2026-06-02T20:58:35Z) @yah:status(open) @arch:see(.yah/docs/working/W144-envoy-providers-and-tiering.md)

Re-exports§

pub use cloudflare::CfAccountInfo;
pub use cloudflare::CloudflareClient;
pub use cloudflare::CreateR2BucketResult;
pub use cloudflare::CreateTokenResult;
pub use cloudflare::CreateTunnelResult;
pub use cloudflare::GrantScope;
pub use cloudflare::R2BucketInfo;
pub use cloudflare::R2CustomDomain;
pub use cloudflare::TokenGrant;
pub use cloudflare::TunnelConnState;
pub use cloudflare::TunnelDnsRecord;
pub use cloudflare::TunnelDriftRow;
pub use cloudflare::TunnelDriftState;
pub use cloudflare::WorkerDeployResult;
pub use cloudflare::MESOFACT_STATIC_GRANTS;
pub use hetzner::HetznerDriver;
pub use cloudflare_envoy::CloudflareEnvoy;
pub use hetzner_envoy::HetznerEnvoy;
pub use digitalocean::DigitalOceanClient;
pub use digitalocean::DigitalOceanEnvoy;
pub use digitalocean::DoCreateDropletSpec;
pub use floating_ip::floating_ip_provider_for;
pub use floating_ip_envoy::dispatch_floating_ip_verb;
pub use floating_ip_envoy::FloatingIpEnvoy;

Modules§

cloudflare
Cloudflare management API client — accounts, tunnels, R2 buckets, DNS.
cloudflare_envoy
CloudflareEnvoy — tier-S adapter for Cloudflare R2 (cloud.object.*) and Cloudflare DNS (dns.*) verbs (R409-T6).
digitalocean
DigitalOceanEnvoy — second native cloud.vps.* adapter, spike scope (R409-T10). Together with [HetznerEnvoy] this is the catalog-shape validator R409-T11’s postmortem decides on.
floating_ip
Cloud’s floating/reserved-IP surface: the vendor adapters, the credentialed constructor, and a re-export of the shared seam.
floating_ip_envoy
The floating_ip.* envoy layer over yah-floating-ip-adapters (R859-F3).
hetzner
@yah:ticket(R040-F9, “Lift KeysStore into shared crate; cloud reads vault then env”) @yah:at(2026-05-05T00:33:17Z) @yah:status(review) @yah:assignee(agent:claude) @yah:parent(R040) @yah:handoff(“DRY-up landed: app/yah/cli/src/keys.rs lifted to crates/yah/keys (own Cargo.toml, ProjectDirs::data_dir() unchanged so the existing on-disk vault keeps working). app/yah/cli now keys = { path = ... } deps the new crate; aes-gcm and rand drops out of the CLI’s direct deps (transitive now). main.rs/agent.rs/agentd.rs swapped mod keys;/crate::keys:: for the external crate path. cloud crate gained keys dep + HetznerDriver::from_default_sources() that tries KeysStore::open().get(slot) per-key then falls back to env: hetzner-api-token↔HETZNER_API_TOKEN, hetzner-s3-access-key↔HETZNER_S3_ACCESS_KEY, hetzner-s3-secret-key↔HETZNER_S3_SECRET_KEY. Vault open errors are swallowed (no vault → fall back to env). yah cloud callsites (app/yah/cli/src/cloud.rs:257 + :423) flipped to from_default_sources(). Tests: 6/6 green for keys (moved from CLI), 26/26 green for cloud (no test changes — all existing). cargo check -p keys + -p cloud + -p yah –bin yah-agentd clean.”) @yah:next(“Follow-up scoped as R043 (relay) with phases F1 bridge / F2 naming / F3 cleanup — unify desktop api_keys with this vault, KeysStore as canonical, drop keyring dep once soaked.”) @yah:next(“Optional: yah keys CLI could grow --from-keychain <provider> flag to one-shot import a desktop-vault token without typing it. Not urgent; the user can already pipe via security find-generic-password ... | yah keys set --from-stdin <slot>.”) @yah:verify(“cargo test -p keys”) @yah:verify(“cargo test -p cloud”) @yah:verify(“cargo check -p yah –bin yah-agentd”) @yah:gotcha(“cargo check –workspace currently fails on app/yah/cli/src/cloud.rs:210 because handle_agent is referenced but not yet defined — that’s parallel R040-F7 WIP (yah cloud agent ping/services/logs against yah-yubaba), not this refactor. The keys = ... and HetznerDriver::from_default_sources additions compile clean on their own.”)
hetzner_envoy
HetznerEnvoy — adapter that exposes the existing HetznerDriver through the envoy framework’s cloud.vps.* verbs (R409-T5).

Structs§

BucketRef
Reference to a created object-storage bucket.
FloatingIpAssignOutcome
Outcome of reconcile_assignment / on_ingress_owner_changed.
FloatingIpState
Current provider-side state of a floating/reserved IP.
FloatingIpTarget
A resolved reassign target: provider-native attach id + the mobility zone it lives in.
HetznerFloatingIp
Hetzner Cloud floating-IP client. Bearer-token auth, same as cloud’s HetznerDriver Cloud API calls.
OvhFloatingIp
OVH Additional-IP client. See module docs re: the auth placeholder.
ProjectId
Logical project scope. Hetzner Cloud tokens are already project-scoped, so this is a no-op placeholder there.
ServerId
Opaque server identifier returned by the provider.
ServerSpec
Parameters for a new machine.
ServerSummary
Snapshot of a live server returned by MachineProvider::find_server_by_name.
VultrFloatingIp
Vultr reserved-IP client. Bearer-token auth (Vultr’s personal-access-token scheme).

Enums§

BucketAcl
Canned S3 ACL policies for bucket-level access control.
IngressOwnerEffect
What should happen to public ingress, given an ingress_owner observation.
Location
Phase-1 cloud regions.
OwnerLiveness
What a TransitionTracker-style hysteresis says about one machine, crossed into this crate as plain data.
QuorumHealth
Live consensus health, crossed into this crate as plain data.
ServerStatus
Observed server lifecycle status (mirrors Hetzner Cloud’s status field).

Traits§

FloatingIpProvider
One provider’s floating/reserved-IP transport + mobility policy.
MachineProvider
Abstracts over cloud providers for the machine + bucket lifecycle.

Functions§

on_ingress_owner_changed
Callable entry point: react to the raft ingress_owner seam naming machine as the box that now owns public ingress, by commanding ip_id to follow it.
plan_ingress_owner_effect
Decide what public ingress should do about an ingress_owner observation — pure, so the decision is testable as arithmetic and the I/O is somebody else’s problem.
provider_has_floating_ip_adapter
Does provider have a floating-IP adapter at all?
reconcile_assignment
Idempotent, zone-checked core shared by every provider adapter and by on_ingress_owner_changed.
resolve_ingress_owner
Resolve an ingress_owner string to the machine it names.