ecluse
Safe HaskellNone
LanguageGHC2021

Ecluse.Config.Ambient

Description

The ambient cloud-SDK environment: the handful of AWS_* variables Écluse itself consults, read straight from the process environment at boot rather than from the config document.

Keeping them out of the document makes "secrets never live in the structured config" structural, because a key like awsSecretAccessKey is then an unknown key and a loud parse failure. Nothing here touches the AWS SDK's own credential discovery.

Synopsis

Documentation

data AmbientAws Source #

The AWS_* values Écluse consults directly: region scoping and endpoint overrides. A field is Nothing when its variable is unset, and each consumer handles a blank value itself.

Constructors

AmbientAws 

Fields

  • ambientAwsRegion :: Maybe Text

    AWS_REGION: read here only to scope SQS under an AWS_ENDPOINT_URL_SQS override, because a real SQS URL carries its own. The SDK reads it itself to region every other client.

  • ambientAwsEndpointUrlSqs :: Maybe Text

    AWS_ENDPOINT_URL_SQS: the SQS endpoint override (a local emulator or a VPC endpoint).

  • ambientAwsEndpointUrl :: Maybe Text

    AWS_ENDPOINT_URL: the generic endpoint override, consulted by the S3 advisory-database client (the proxy's sync and Pilot's export).

Instances

Instances details
Show AmbientAws Source # 
Instance details

Defined in Ecluse.Config.Ambient

Eq AmbientAws Source # 
Instance details

Defined in Ecluse.Config.Ambient

ambientAwsFromEnv :: [(String, String)] -> AmbientAws Source #

Read the ambient AWS values from the process environment, as getEnvironment returns it.

parseEndpointUrl :: Text -> Either Secret AwsEndpoint Source #

Parse an endpoint override, reading the authority the way the egress gate reads one. Userinfo, a query, a fragment, or a port outside its grammar refuses.

ambientS3Endpoint :: AmbientAws -> Either Secret (Maybe AwsEndpoint) Source #

The S3 advisory client's endpoint override, parsed once at boot. Nothing is an unset or blank AWS_ENDPOINT_URL, and a set-but-refused value is the Left, never a silent Nothing.