Expand description
@yah:relay(R409, “Envoy — providers and internal verb catalog (W144)”) @yah:at(2026-06-02T20:58:35Z) @yah:status(open) @arch:see(.yah/docs/working/W144-envoy-providers-and-tiering.md)
Re-exports§
pub use cloudflare::CfAccountInfo;pub use cloudflare::CloudflareClient;pub use cloudflare::CreateR2BucketResult;pub use cloudflare::CreateTokenResult;pub use cloudflare::CreateTunnelResult;pub use cloudflare::DnsRecordDetail;pub use cloudflare::GrantScope;pub use cloudflare::R2BucketInfo;pub use cloudflare::R2CustomDomain;pub use cloudflare::TokenGrant;pub use cloudflare::TunnelConnState;pub use cloudflare::TunnelDnsRecord;pub use cloudflare::TunnelDriftRow;pub use cloudflare::TunnelDriftState;pub use cloudflare::WorkerDeployResult;pub use cloudflare::DOOR_DNS_GRANTS;pub use cloudflare::MESOFACT_STATIC_GRANTS;pub use cloudflare::TUNNEL_EDIT_GRANTS;pub use hetzner::HetznerDriver;pub use cloudflare_envoy::CloudflareEnvoy;pub use hetzner_envoy::HetznerEnvoy;pub use digitalocean::DigitalOceanClient;pub use digitalocean::DigitalOceanEnvoy;pub use digitalocean::DoCreateDropletSpec;pub use floating_ip::floating_ip_provider_for;pub use floating_ip_envoy::dispatch_floating_ip_verb;pub use floating_ip_envoy::FloatingIpEnvoy;
Modules§
- cloudflare
- Cloudflare management API client — accounts, tunnels, R2 buckets, DNS.
- cloudflare_
envoy CloudflareEnvoy— tier-S adapter for Cloudflare R2 (cloud.object.*) and Cloudflare DNS (dns.*) verbs (R409-T6).- digitalocean
DigitalOceanEnvoy— second nativecloud.vps.*adapter, spike scope (R409-T10). Together with [HetznerEnvoy] this is the catalog-shape validator R409-T11’s postmortem decides on.- floating_
ip - Cloud’s floating/reserved-IP surface: the vendor adapters, the credentialed constructor, and a re-export of the shared seam.
- floating_
ip_ envoy - The
floating_ip.*envoy layer overyah-floating-ip-adapters(R859-F3). - hetzner
- @yah:ticket(R040-F9, “Lift KeysStore into shared crate; cloud reads vault then env”)
@yah:at(2026-05-05T00:33:17Z)
@yah:status(review)
@yah:assignee(agent:claude)
@yah:parent(R040)
@yah:handoff(“DRY-up landed: app/yah/cli/src/keys.rs lifted to crates/yah/keys (own Cargo.toml, ProjectDirs::data_dir() unchanged so the existing on-disk vault keeps working). app/yah/cli now
keys = { path = ... }deps the new crate; aes-gcm and rand drops out of the CLI’s direct deps (transitive now). main.rs/agent.rs/agentd.rs swappedmod keys;/crate::keys::for the external crate path. cloud crate gainedkeysdep +HetznerDriver::from_default_sources()that tries KeysStore::open().get(slot) per-key then falls back to env: hetzner-api-token↔HETZNER_API_TOKEN, hetzner-s3-access-key↔HETZNER_S3_ACCESS_KEY, hetzner-s3-secret-key↔HETZNER_S3_SECRET_KEY. Vault open errors are swallowed (no vault → fall back to env). yah cloud callsites (app/yah/cli/src/cloud.rs:257 + :423) flipped to from_default_sources(). Tests: 6/6 green for keys (moved from CLI), 26/26 green for cloud (no test changes — all existing). cargo check -p keys + -p cloud + -p yah –bin yah-agentd clean.”) @yah:next(“Follow-up scoped as R043 (relay) with phases F1 bridge / F2 naming / F3 cleanup — unify desktop api_keys with this vault, KeysStore as canonical, drop keyring dep once soaked.”) @yah:next(“Optional: yah keys CLI could grow--from-keychain <provider>flag to one-shot import a desktop-vault token without typing it. Not urgent; the user can already pipe viasecurity find-generic-password ... | yah keys set --from-stdin <slot>.”) @yah:verify(“cargo test -p keys”) @yah:verify(“cargo test -p cloud”) @yah:verify(“cargo check -p yah –bin yah-agentd”) @yah:gotcha(“cargo check –workspace currently fails on app/yah/cli/src/cloud.rs:210 because handle_agent is referenced but not yet defined — that’s parallel R040-F7 WIP (yah cloud agent ping/services/logs against yah-yubaba), not this refactor. Thekeys = ...and HetznerDriver::from_default_sources additions compile clean on their own.”) - hetzner_
envoy HetznerEnvoy— adapter that exposes the existingHetznerDriverthrough the envoy framework’scloud.vps.*verbs (R409-T5).
Structs§
- Bucket
Ref - Reference to a created object-storage bucket.
- Floating
IpAssign Outcome - Outcome of
reconcile_assignment/on_ingress_owner_changed. - Floating
IpState - Current provider-side state of a floating/reserved IP.
- Floating
IpTarget - A resolved reassign target: provider-native attach id + the mobility zone it lives in.
- Hetzner
Floating Ip - Hetzner Cloud floating-IP client. Bearer-token auth, same as
cloud’sHetznerDriverCloud API calls. - OvhFloating
Ip - OVH Additional-IP client. See module docs re: the auth placeholder.
- Project
Id - Logical project scope. Hetzner Cloud tokens are already project-scoped, so this is a no-op placeholder there.
- Server
Id - Opaque server identifier returned by the provider.
- Server
Spec - Parameters for a new machine.
- Server
Summary - Snapshot of a live server returned by
MachineProvider::find_server_by_name. - Vultr
Floating Ip - Vultr reserved-IP client. Bearer-token auth (Vultr’s personal-access-token scheme).
Enums§
- Bucket
Acl - Canned S3 ACL policies for bucket-level access control.
- Ingress
Owner Effect - What should happen to public ingress, given an
ingress_ownerobservation. - Location
- Phase-1 cloud regions.
- Owner
Liveness - What a
TransitionTracker-style hysteresis says about one machine, crossed into this crate as plain data. - Quorum
Health - Live consensus health, crossed into this crate as plain data.
- Server
Status - Observed server lifecycle status (mirrors Hetzner Cloud’s status field).
Traits§
- Floating
IpProvider - One provider’s floating/reserved-IP transport + mobility policy.
- Machine
Provider - Abstracts over cloud providers for the machine + bucket lifecycle.
Functions§
- on_
ingress_ owner_ changed - Callable entry point: react to the raft
ingress_ownerseam namingmachineas the box that now owns public ingress, by commandingip_idto follow it. - plan_
ingress_ owner_ effect - Decide what public ingress should do about an
ingress_ownerobservation — pure, so the decision is testable as arithmetic and the I/O is somebody else’s problem. - provider_
has_ floating_ ip_ adapter - Does
providerhave a floating-IP adapter at all? - reconcile_
assignment - Idempotent, zone-checked core shared by every provider adapter and by
on_ingress_owner_changed. - resolve_
ingress_ owner - Resolve an
ingress_ownerstring to the machine it names.