| Safe Haskell | None |
|---|---|
| Language | GHC2021 |
Ecluse.Config.Ambient
Description
The ambient cloud-SDK environment: the handful of AWS_* variables Écluse itself consults,
read straight from the process environment at boot rather than from the config document.
Keeping them out of the document makes "secrets never live in the structured config" structural,
because a key like awsSecretAccessKey is then an unknown key and a loud parse failure. Nothing
here touches the AWS SDK's own credential discovery.
Synopsis
- data AmbientAws = AmbientAws {}
- ambientAwsFromEnv :: [(String, String)] -> AmbientAws
- parseEndpointUrl :: Text -> Either Secret AwsEndpoint
- ambientS3Endpoint :: AmbientAws -> Either Secret (Maybe AwsEndpoint)
Documentation
data AmbientAws Source #
The AWS_* values Écluse consults directly: region scoping and endpoint overrides. A
field is Nothing when its variable is unset, and each consumer handles a blank value itself.
Constructors
| AmbientAws | |
Fields
| |
Instances
| Show AmbientAws Source # | |
Defined in Ecluse.Config.Ambient Methods showsPrec :: Int -> AmbientAws -> ShowS # show :: AmbientAws -> String # showList :: [AmbientAws] -> ShowS # | |
| Eq AmbientAws Source # | |
Defined in Ecluse.Config.Ambient | |
ambientAwsFromEnv :: [(String, String)] -> AmbientAws Source #
Read the ambient AWS values from the process environment, as getEnvironment returns it.
parseEndpointUrl :: Text -> Either Secret AwsEndpoint Source #
Parse an endpoint override, reading the authority the way the egress gate reads one. Userinfo, a query, a fragment, or a port outside its grammar refuses.
ambientS3Endpoint :: AmbientAws -> Either Secret (Maybe AwsEndpoint) Source #