ecluse
Safe HaskellNone
LanguageGHC2021

Ecluse.Config.Target

Contents

Description

Resolve a mount's declared endpoints against the store tag each one names.

The tag is the declaration, and the URL is checked against it. A codeArtifact endpoint must carry the CodeArtifact host shape and, as mirror target or private upstream, address a repository under the mount's own package format, because a repository's per-format endpoints are separate stores. Every other tag admits any https registry the egress boundary cleared. Each refusal names the key, so a store this build cannot address is refused at load rather than at the first write.

Synopsis

Resolution

resolveStoreBackend :: Ecosystem -> MirrorEndpoint -> Either ConfigError StoreBackend Source #

Resolve a mirror target's store backend from the tag it declares. Only the CodeArtifact arm reads the URL, and it refuses one that addresses no repository this mount could mirror into.

resolvePrivateBackend :: Ecosystem -> Target -> Either ConfigError (StoreBackend, CodeArtifactStore) Source #

Resolve a private target already classified as CodeArtifact, using the default token lifetime. The repository is returned beside the backend, so a caller needs no second read of the control plane.

vetTargetTag :: Ecosystem -> Text -> Target -> Either ConfigError () Source #

Vet a read or publish endpoint's URL against its declared tag. Only codeArtifact constrains the host, and only a mirror target constrains the path, so this is total over the other tags.

vetPrivateRepository :: Ecosystem -> Target -> Either ConfigError () Source #

Vet a declared private upstream past its tag. A codeArtifact one must address a repository under the mount's own format, because the boot asks that repository what content it aggregates.

parseCodeArtifactHost :: Text -> Maybe (Text, Text, Text) Source #

Parse {domain}-{owner}.d.codeartifact.{region}.amazonaws.com into (domain, owner, region). The owner is the 12-digit account id after the last hyphen, so a domain may carry them.

isAccountId :: Text -> Bool Source #

Whether a value is a 12-digit AWS account id (shared with the SQS queue-URL shape validation in Ecluse.Config.QueueTarget).