ecluse
Safe HaskellNone
LanguageGHC2021

Ecluse.Composition.Credential

Description

Target-bound credential providers built at the composition root. CodeArtifact consumers with the same mint identity share one refresh provider and breaker.

Synopsis

Global credential providers

data CredentialProviders Source #

Providers keyed by the mount and the target that declared their authentication identity.

noCredentialProviders :: CredentialProviders Source #

No initialised providers: what a boot half that refused before it built any carries onward, so the halves after it still plan and still report what they refuse.

type BuildCredentials = (Ecosystem -> StoreTag -> CredentialReporters) -> [((Ecosystem, CredentialTarget), StoreBackend)] -> IO (Either [BootError] CredentialProviders) Source #

Build only credentials for the targets cleared by this boot role.

initCredentialProviders :: BuildCredentials -> (Ecosystem -> StoreTag -> CredentialReporters) -> [Mount] -> IO (Either [BootError] CredentialProviders) Source #

Build each mirroring mount's write-credential provider through the injected builder. The mint is eager, so a bad identity fails here as CodeArtifactMintFailed.

initTargetCredentialProviders :: (Ecosystem -> StoreTag -> CredentialReporters) -> [((Ecosystem, CredentialTarget), StoreBackend)] -> IO (Either [BootError] CredentialProviders) Source #

Build target-bound providers, sharing only matching CodeArtifact mint identities.

lookupTargetProvider :: CredentialTarget -> Ecosystem -> CredentialProviders -> Maybe CredentialProvider Source #

Look up only the declared target's credential.

initializedEcosystems :: CredentialProviders -> Set Ecosystem Source #

The set of ecosystems that resolved to an initialised provider: the pure surface the boot-time credential-reference check reasons over.

lookupProvider :: Ecosystem -> CredentialProviders -> Maybe CredentialProvider Source #

Look up the initialised provider for an ecosystem, Nothing when none is initialised (the unresolved-reference case the boot check rejects).

The telemetry label a store carries

providerLabel :: StoreTag -> Provider Source #

The provider metric label a store's credential signals record under. It reads as the configuration spells the tag, so a dashboard series and a mount's declaration are one word.

Internals exported for testing

mirrorBackends :: [Mount] -> [(Ecosystem, StoreBackend)] Source #

Each mirroring mount's ecosystem and the store its mirror write authenticates to. A mount declaring no mirror target contributes no mirror provider.

codeArtifactIdentityGroups :: [(key, StoreTag, CodeArtifactConfig)] -> [(CodeArtifactConfig, (StoreTag, NonEmpty key))] Source #

Group the mounts' resolved CodeArtifact identities by distinct CodeArtifactConfig. One domain shares a provider, its reporters, and its breaker, and a differing duration keeps its own.

codeArtifactMintFailure :: NonEmpty (Ecosystem, CredentialTarget) -> Text -> BootError Source #

Attribute a failed shared mint to every configured credential consumer.