ecluse
Safe HaskellNone
LanguageGHC2021

Ecluse.Config

Description

Configuration loading, mount resolution, and redacted operator diagnostics.

Synopsis

Documentation

data Config Source #

A completed load: the document's settings and the mounts resolved against them.

Constructors

Config 

Instances

Instances details
Show Config Source # 
Instance details

Defined in Ecluse.Config.Types

Eq Config Source # 
Instance details

Defined in Ecluse.Config.Types

Methods

(==) :: Config -> Config -> Bool #

(/=) :: Config -> Config -> Bool #

data AppConfig Source #

The resolved application configuration, one sub-record per document group. The document schema and this type mirror each other one to one.

Instances

Instances details
FromJSON AppConfig Source # 
Instance details

Defined in Ecluse.Config.Aeson

Show AppConfig Source # 
Instance details

Defined in Ecluse.Config.Types

Eq AppConfig Source # 
Instance details

Defined in Ecluse.Config.Types

data ServerSettings Source #

The server group: the inbound edge Écluse itself presents.

Constructors

ServerSettings 

Fields

Instances

Instances details
Show ServerSettings Source # 
Instance details

Defined in Ecluse.Config.Types

Eq ServerSettings Source # 
Instance details

Defined in Ecluse.Config.Types

data QueueSettings Source #

The queue group: the mirror queue's destination, depth cap, and redelivery budget. The URL's shape decides the backend, and the load derives it once (Ecluse.Config.QueueTarget).

Constructors

QueueSettings 

Fields

Instances

Instances details
Show QueueSettings Source # 
Instance details

Defined in Ecluse.Config.Types

Eq QueueSettings Source # 
Instance details

Defined in Ecluse.Config.Types

data LimitsSettings Source #

The limits group: the hostile-input bounds. The memory plan computes the tenant-sized caps when unset (Ecluse.Composition.MemoryPlan), a configured value winning, and the rest stay pinned.

Constructors

LimitsSettings 

Fields

Instances

Instances details
Show LimitsSettings Source # 
Instance details

Defined in Ecluse.Config.Types

Eq LimitsSettings Source # 
Instance details

Defined in Ecluse.Config.Types

data CacheSettings Source #

The cache group: the metadata cache's TTL and its computed-by-default bounds.

Constructors

CacheSettings 

Fields

Instances

Instances details
Show CacheSettings Source # 
Instance details

Defined in Ecluse.Config.Types

Eq CacheSettings Source # 
Instance details

Defined in Ecluse.Config.Types

data IntegritySettings Source #

Global integrity floors. A mount can refine the trusted floor through MountIntegrity.

Constructors

IntegritySettings 

Fields

newtype EgressSettings Source #

The egress group: the operator's additions to the blocked target ranges.

Instances

Instances details
Show EgressSettings Source # 
Instance details

Defined in Ecluse.Config.Types

Eq EgressSettings Source # 
Instance details

Defined in Ecluse.Config.Types

data AdvisoriesSettings Source #

The advisories group: the OSV/CVE pipeline's store, cadences, and upstream feeds.

Constructors

AdvisoriesSettings 

Fields

data RuntimeSettings Source #

The runtime group: the process-sizing overrides. Unset, each is computed from the runtime posture (cgroups, RTS, file-descriptor limit), with its provenance boot-logged.

data ObservabilitySettings Source #

The observability group: log shape, log level, and telemetry switch.

Constructors

ObservabilitySettings 

Fields

data DredgerSettings Source #

The dredger group: how the mirror sweep paces itself, how much one cycle may delete, and which names it carries. Only ecluse dredger reads it, and every other role carries it unread.

Constructors

DredgerSettings 

Fields

  • drgChunkSize :: Int

    Candidate packages one chunk examines before the sweep pauses.

  • drgChunkPause :: NominalDiffTime

    Seconds between chunks, which is also the wait a fault advising no delay of its own takes.

  • drgCyclePause :: NominalDiffTime

    Seconds between the end of one cycle and the start of the next.

  • drgTargetCycleWindow :: Maybe NominalDiffTime

    Seconds within which an advisory is paced to reach every affected mirrored version. Computed from the cycle pause when unset.

  • drgRequestBudgetFraction :: Maybe Rational

    The share of a store's request capacity one sweep may take. Computed per capacity pool when unset, so a sweep cannot starve the proxy's own calls.

  • drgQuotaOverrides :: Map Text QuotaOverride

    Declared request capacity, keyed by the store URL it describes.

  • drgDeletionCap :: Maybe Int

    Versions one cycle may hand over for deletion, computed per sweepable store when unset. Reaching it halts the sweep for the life of the process, so a poisoned generation stops there.

  • drgFullWalk :: Bool

    Walk every package each cycle rather than the advisory and identity-deny candidates. It covers a rule-configuration change, and it writes one resumption marker to the store.

data QuotaOverride Source #

One store's declared request capacity. It supplies the capacity a backend publishes none of, and a shared scope joins two endpoints of one pool so the sweep paces them together.

Constructors

QuotaOverride 

Fields

  • qoScope :: Maybe Text

    The capacity pool this store shares, which defaults to the store's own authority.

  • qoQuotas :: Map QuotaDimension Rational

    Requests per second the pool admits, replacing the backend's own number per dimension.

  • qoWeights :: Map RequestKind Rational

    What one request of a kind costs relative to the backend's own cost for it.

Instances

Instances details
Show QuotaOverride Source # 
Instance details

Defined in Ecluse.Config.Types

Eq QuotaOverride Source # 
Instance details

Defined in Ecluse.Config.Types

type MountMap = Map Ecosystem Mount Source #

The mounts a load resolved, keyed by the ecosystem each was declared under.

data Mount Source #

One resolved mount: its ecosystem, its endpoints, and the rules in precedence order.

Constructors

Mount 

Fields

Instances

Instances details
Show Mount Source # 
Instance details

Defined in Ecluse.Config.Types

Methods

showsPrec :: Int -> Mount -> ShowS #

show :: Mount -> String #

showList :: [Mount] -> ShowS #

Eq Mount Source # 
Instance details

Defined in Ecluse.Config.Types

Methods

(==) :: Mount -> Mount -> Bool #

(/=) :: Mount -> Mount -> Bool #

data MountRegistries Source #

A resolved mount's endpoints: the public upstream it gates, and what it does with the rest.

Constructors

MountRegistries 

Fields

data MountMode Source #

Whether a mount mirrors, derived from its declared endpoints. A declared mirrorTarget makes it Mirrored, which carries the private upstream the mirror is read back through, never without.

Constructors

Mirrored MirroredLegs

The mount mirrors admitted public artifacts, and it needs both legs.

ServeOnly (Maybe RegistryUrl)

The mount never writes. It still merges the optional private upstream when present.

Instances

Instances details
Show MountMode Source # 
Instance details

Defined in Ecluse.Config.Types

Eq MountMode Source # 
Instance details

Defined in Ecluse.Config.Types

data MirroredLegs Source #

A mirrored mount's two required halves: the readable private upstream and the mirror target married to its derived write credential.

Constructors

MirroredLegs 

Fields

Instances

Instances details
Show MirroredLegs Source # 
Instance details

Defined in Ecluse.Config.Types

Eq MirroredLegs Source # 
Instance details

Defined in Ecluse.Config.Types

regPrivateUpstream :: MountRegistries -> Maybe RegistryUrl Source #

The mount's private upstream, when it has one. It is total over both mount modes.

regMirrorTarget :: MountRegistries -> Maybe MirrorTarget Source #

The mount's mirror target (with its derived credential), when it mirrors.

data MirrorTarget Source #

A mirror target married to the backend resolved from the tag it was declared under.

Constructors

MirrorTarget 

Fields

Instances

Instances details
Show MirrorTarget Source # 
Instance details

Defined in Ecluse.Config.Types

Eq MirrorTarget Source # 
Instance details

Defined in Ecluse.Config.Types

data StoreTag Source #

Which store backend an endpoint names. The operator declares it as the one key under the endpoint, and the load validates the URL against it rather than guessing it from a host shape.

Constructors

TagRegistry

Any host that speaks the ecosystem's protocol, authenticated by a static token.

TagCodeArtifact

A CodeArtifact repository endpoint, which mints its own write token.

TagVerdaccio

A Verdaccio development store, authenticated by a static token.

Instances

Instances details
Show StoreTag Source # 
Instance details

Defined in Ecluse.Config.Types

Eq StoreTag Source # 
Instance details

Defined in Ecluse.Config.Types

storeTagName :: StoreTag -> Text Source #

The tag as an operator writes it, and as a refusal names it.

data Target Source #

An endpoint as a mount declares it: the tag naming its store, and the URL under that tag.

Constructors

Target 

Fields

Instances

Instances details
Show Target Source # 
Instance details

Defined in Ecluse.Config.Types

Eq Target Source # 
Instance details

Defined in Ecluse.Config.Types

Methods

(==) :: Target -> Target -> Bool #

(/=) :: Target -> Target -> Bool #

data PrivateEndpoint Source #

A private read endpoint with maintenance authority used only by Dredger.

data DeletionConsent Source #

Whether the operator consented to ecluse dredger deleting from a Verdaccio store. It is a declaration about that one store, so it exists under no other tag.

data MirrorWrite Source #

How a mount's mirror write authenticates, one arm per tag. The mirror write is Écluse's one standing credential, so a minting tag carries no static token and a non-minting tag requires one.

Constructors

WriteRegistry Secret

Any protocol-speaking host: the operator's static write token.

WriteCodeArtifact (Maybe Natural)

A CodeArtifact repository: the requested lifetime of the token it mints.

WriteVerdaccio Secret DeletionConsent

A Verdaccio store: its static write token, and the operator's deletion consent.

Instances

Instances details
Show MirrorWrite Source # 
Instance details

Defined in Ecluse.Config.Types

Eq MirrorWrite Source # 
Instance details

Defined in Ecluse.Config.Types

data MirrorEndpoint Source #

A declared mirrorTarget: where the mirror writes, and how that write authenticates.

Constructors

MirrorEndpoint 

Fields

Instances

Instances details
Show MirrorEndpoint Source # 
Instance details

Defined in Ecluse.Config.Types

Eq MirrorEndpoint Source # 
Instance details

Defined in Ecluse.Config.Types

meTarget :: MirrorEndpoint -> Target Source #

The mirror endpoint as the collision rules read it. The tag comes from meWrite.

data PublicationEndpoint Source #

A declared publicationTarget: where a client publish is relayed, and the static credential forwarded only when the publishing client sends none.

Constructors

PublicationEndpoint 

Fields

data MintPlan Source #

How a mount's mirror write authenticates, projected from its resolved StoreBackend.

Constructors

MintCodeArtifact CodeArtifactConfig

A CodeArtifact mirror target: the mint identity parsed from its host.

MintStatic Secret

Any other mirror target: an operator-supplied static write token.

Instances

Instances details
Show MintPlan Source # 
Instance details

Defined in Ecluse.Config.Types

Eq MintPlan Source # 
Instance details

Defined in Ecluse.Config.Types

data ControlPlane Source #

The control plane a mount's store offers, the face ecluse dredger deletes through.

Constructors

ControlCodeArtifact CodeArtifactStore

The CodeArtifact repository the target addresses, which the load has vetted.

ControlProtocol Secret DeletionConsent

A store with no vendor control plane, swept through the ecosystem protocol's own verbs: its write token, and the operator's consent to delete from it.

ControlNone

The tag names no control plane this build implements.

Instances

Instances details
Show ControlPlane Source # 
Instance details

Defined in Ecluse.Config.Types

Eq ControlPlane Source # 
Instance details

Defined in Ecluse.Config.Types

data StoreBackend Source #

A mount's store backend, resolved once at load (Ecluse.Config.Target), so no two roles infer a different one. The tag discriminates, so no arm pairs one store's mint with another's plane.

Constructors

BackendRegistry Secret

A protocol-speaking host: its static write token, and no control plane.

BackendCodeArtifact CodeArtifactConfig CodeArtifactStore

A CodeArtifact repository: the identity it mints from, and the store a sweep deletes in.

BackendVerdaccio Secret DeletionConsent

A Verdaccio store: its static write token, and the operator's deletion consent.

Instances

Instances details
Show StoreBackend Source # 
Instance details

Defined in Ecluse.Config.Types

Eq StoreBackend Source # 
Instance details

Defined in Ecluse.Config.Types

sbTag :: StoreBackend -> StoreTag Source #

The tag a backend was declared under.

sbMint :: StoreBackend -> MintPlan Source #

How the mirror write to this backend authenticates.

sbControl :: StoreBackend -> ControlPlane Source #

The control plane this build reaches for a backend.

data FirstParty Source #

The namespaces a mount's deployment owns, one arm per ecosystem, read only in that registry's own naming shape. Every consumer of the privilege derives its predicate from this one value.

Constructors

FirstPartyNpmScopes (NonEmpty Scope)

The npm scopes the deployment owns, at least one.

FirstPartyPyPI (NonEmpty PyPIFirstParty)

The PyPI distributions and name prefixes the deployment owns, at least one.

Instances

Instances details
Show FirstParty Source # 
Instance details

Defined in Ecluse.Config.Types

Eq FirstParty Source # 
Instance details

Defined in Ecluse.Config.Types

newtype MountIntegrity Source #

A mount's refinements of the global integrity group, under its own integrity key so the mount groups them exactly as the top level does. Each is Nothing at the global setting.

Constructors

MountIntegrity 

Fields

  • miMinTrusted :: Maybe MinTrustedIntegrity

    A per-mount refinement of the global trusted-integrity floor, for the one legacy private registry whose loosening must not leak onto other mounts.

Instances

Instances details
Show MountIntegrity Source # 
Instance details

Defined in Ecluse.Config.Types

Eq MountIntegrity Source # 
Instance details

Defined in Ecluse.Config.Types

data MountConfig Source #

One mount as the document declares it, before Ecluse.Config resolves it into a Mount.

Constructors

MountConfig 

Fields

Instances

Instances details
Show MountConfig Source # 
Instance details

Defined in Ecluse.Config.Types

Eq MountConfig Source # 
Instance details

Defined in Ecluse.Config.Types

data Url Source #

An operator-configured http(s) URL, whitespace-trimmed. mkUrl is the only builder, so no value exists carrying credential material, another scheme, or an authority the egress gate misses.

Instances

Instances details
Show Url Source # 
Instance details

Defined in Ecluse.Config.Types

Methods

showsPrec :: Int -> Url -> ShowS #

show :: Url -> String #

showList :: [Url] -> ShowS #

Eq Url Source # 
Instance details

Defined in Ecluse.Config.Types

Methods

(==) :: Url -> Url -> Bool #

(/=) :: Url -> Url -> Bool #

Ord Url Source # 
Instance details

Defined in Ecluse.Config.Types

Methods

compare :: Url -> Url -> Ordering #

(<) :: Url -> Url -> Bool #

(<=) :: Url -> Url -> Bool #

(>) :: Url -> Url -> Bool #

(>=) :: Url -> Url -> Bool #

max :: Url -> Url -> Url #

min :: Url -> Url -> Url #

unUrl :: Url -> Text Source #

The stored URL text.

data QueueTarget Source #

A recognised mirror-queue destination, parsed from the queue URL's shape.

Constructors

SqsTarget Text

An SQS queue URL, carrying the region parsed from its host.

PubSubTarget Text Text

A Pub/Sub topic resource, carrying its project and topic.

Instances

Instances details
Show QueueTarget Source # 
Instance details

Defined in Ecluse.Config.Queue.Internal

Eq QueueTarget Source # 
Instance details

Defined in Ecluse.Config.Queue.Internal

data QueueUrl Source #

queue.url as parsed at load (mkQueueUrl): the value as written, with the backend its shape names, or no backend when only the SQS endpoint override can dial it.

Instances

Instances details
Show QueueUrl Source # 
Instance details

Defined in Ecluse.Config.Queue.Internal

Eq QueueUrl Source # 
Instance details

Defined in Ecluse.Config.Queue.Internal

queueUrlText :: QueueUrl -> Text Source #

The value as written, trimmed.

queueUrlTarget :: QueueUrl -> Maybe QueueTarget Source #

The backend the value's shape names, Nothing when it names none.

data AdvisoryStoreTarget Source #

A recognised advisory-database store, parsed from the URL's scheme. It carries the bucket and the optional key prefix under which the compiled artifacts live.

Constructors

S3Store Text (Maybe Text)

An s3://bucket[/prefix] store.

data AdvisoryStoreUrl Source #

advisories.url as parsed at load (mkAdvisoryStoreUrl): the value as written, with the store its scheme names.

advisoryStoreUrlText :: AdvisoryStoreUrl -> Text Source #

The value as written, trimmed.

advisoryStoreTarget :: AdvisoryStoreUrl -> AdvisoryStoreTarget Source #

The store the value's scheme names.

advisoryStoreBucket :: AdvisoryStoreUrl -> Text Source #

The bucket the store names.

advisoryObjectKey :: AdvisoryStoreUrl -> FilePath -> Text Source #

The object key one compiled artifact takes in the store: the configured prefix ahead of the artifact's own file name.

newtype RulePatch Source #

A declared rules object: one RuleEntry per rule name it names.

Constructors

RulePatch (Map Text RuleEntry) 

Instances

Instances details
FromJSON RulePatch Source # 
Instance details

Defined in Ecluse.Config.Aeson

Show RulePatch Source # 
Instance details

Defined in Ecluse.Config.Rule

Eq RulePatch Source # 
Instance details

Defined in Ecluse.Config.Rule

data RuleEntry Source #

One rule's declared keys, every one optional. Which of them the entry may set depends on the rule type, and refuseStrayParameters refuses the rest.

Instances

Instances details
FromJSON RuleEntry Source # 
Instance details

Defined in Ecluse.Config.Aeson

Show RuleEntry Source # 
Instance details

Defined in Ecluse.Config.Rule

Eq RuleEntry Source # 
Instance details

Defined in Ecluse.Config.Rule

newtype RulePolicy Source #

A resolved rule set, keyed by the rule name an operator patches it under.

Constructors

RulePolicy 

Fields

Instances

Instances details
Show RulePolicy Source # 
Instance details

Defined in Ecluse.Config.Rule

Eq RulePolicy Source # 
Instance details

Defined in Ecluse.Config.Rule

data PolicyError Source #

Why one declared rule was refused. A load reports every one it accumulated.

Instances

Instances details
Show PolicyError Source # 
Instance details

Defined in Ecluse.Config.Rule

Eq PolicyError Source # 
Instance details

Defined in Ecluse.Config.Rule

renderPolicyError :: PolicyError -> Text Source #

One refusal as the boot reports it, naming the rule it was declared under.

emptyPolicy :: RulePolicy Source #

The policy a load starts from before the shipped defaults are applied.

defaultPolicy :: RulePolicy Source #

The rule policy embedded in the shipped configuration.

data ConfigError Source #

Why a load was refused. renderConfigError writes each one as the boot reports it.

Constructors

ParseError Text 
PolicyErrors [PolicyError] 
PublicUrlRequired

A mount is active but server.publicUrl is unset. It is not derived from the Host header: a spoofed header poisons shared-cache entries with an attacker-chosen artifact URL.

MountMissingPrivateUpstream Ecosystem

A mount declares a mirrorTarget but no private upstream, through which the mirror write must be readable back. A serve-only mount never raises this.

CodeArtifactHostMismatch Ecosystem Text

An endpoint declared under the codeArtifact tag whose URL is not a CodeArtifact endpoint. The tag names the store, so a URL contradicting it is a misdirected write or read.

CodeArtifactFormatUnsupported Ecosystem Text

A codeArtifact endpoint on a mount whose ecosystem CodeArtifact carries no package format for, so no repository under it could serve the mount. Carries the key it was written at.

CodeArtifactRepositoryMissing Ecosystem Text Text

A codeArtifact endpoint whose path addresses no repository under the mount's own format, whose per-format endpoints are separate stores. Carries its key, then the format token.

Instances

Instances details
Show ConfigError Source # 
Instance details

Defined in Ecluse.Config.Types

Eq ConfigError Source # 
Instance details

Defined in Ecluse.Config.Types

loadConfig :: [(String, String)] -> Maybe ByteString -> Either [ConfigError] Config Source #

Load the merged configuration: the defaults, the operator document, then the environment overlay, strongest-last. A mount is active only where that overlay declares a key under it.

sameRegistry :: RegistryUrl -> RegistryUrl -> Bool Source #

Whether two configured endpoints name the same registry. The authority folds to lower case with its default port applied, and the path is compared exactly past a trailing slash.

mountPostureLines :: Config -> [Text] Source #

Mount modes followed by the live-environment limits of check-config, shared with boot.

mountAdvisoryAge :: AdvisoriesSettings -> Mount -> MaxAdvisoryAge Source #

One mount's effective maximum advisory push age, derived from that mount's own rules. An explicit advisories.maxAgeSeconds overrides the derivation on every mount.

mountEpssRequirement :: Mount -> EpssRequirement Source #

Require enrichment when this mount's resolved policy contains an EPSS rule.

mountAdvisoryDenials :: Mount -> [Text] Source #

The names of this mount's rules that deny on the advisory database, in policy order. A non-empty list is what makes an advisory store mandatory and the mount's readiness wait for one.

mountDatabaseRequirement :: Mount -> DatabaseRequirement Source #

Whether this mount must hold an advisory database before it can serve anything.

advisoryAgeLines :: Config -> [Text] Source #

The effective maximum push age of every mount whose rules read the advisory database, with the basis that produced it. With no store configured nothing syncs, so nothing has an age.

advisoryEpssLines :: Config -> [Text] Source #

Each mount's EPSS requirement, which Pilot and that mount's advisory consumers apply alike. It is reported with no store too, because pilot compile runs under it without uploading.

resolvedKeyProvenance :: [(String, String)] -> Maybe ByteString -> [Text] Source #

One line per resolved leaf of the merged configuration: the dotted path, the redacted value, and its layer. Empty when a layer fails to parse, and a boot-computed key has no leaf to report.