| Safe Haskell | None |
|---|---|
| Language | GHC2021 |
Ecluse.Config
Description
Configuration loading, mount resolution, and redacted operator diagnostics.
Synopsis
- data Config = Config {}
- data AppConfig = AppConfig {
- cfgServer :: ServerSettings
- cfgQueue :: QueueSettings
- cfgLimits :: LimitsSettings
- cfgCache :: CacheSettings
- cfgIntegrity :: IntegritySettings
- cfgEgress :: EgressSettings
- cfgAdvisories :: AdvisoriesSettings
- cfgRuntime :: RuntimeSettings
- cfgObservability :: ObservabilitySettings
- cfgDredger :: DredgerSettings
- cfgMounts :: Map Ecosystem MountConfig
- data ServerSettings = ServerSettings {
- srvPort :: Int
- srvPublicUrl :: Maybe Url
- srvAuthToken :: Maybe Secret
- srvHelpMessage :: Maybe Text
- srvShutdownDrainTimeout :: Int
- data QueueSettings = QueueSettings {}
- data LimitsSettings = LimitsSettings {}
- data CacheSettings = CacheSettings {}
- data IntegritySettings = IntegritySettings {
- intMinPublic :: MinIntegrity
- intMinTrusted :: MinTrustedIntegrity
- newtype EgressSettings = EgressSettings {}
- data AdvisoriesSettings = AdvisoriesSettings {}
- data RuntimeSettings = RuntimeSettings {}
- data ObservabilitySettings = ObservabilitySettings {
- obsLogFormat :: LogFormat
- obsLogLevel :: LogLevel
- obsTelemetry :: TelemetrySwitch
- data DredgerSettings = DredgerSettings {}
- data QuotaOverride = QuotaOverride {}
- type MountMap = Map Ecosystem Mount
- data Mount = Mount {
- mountEcosystem :: Ecosystem
- mountRegistries :: MountRegistries
- mountPolicy :: [PrecededRule]
- data MountRegistries = MountRegistries {
- regPublicUpstream :: RegistryUrl
- regMode :: MountMode
- data MountMode
- = Mirrored MirroredLegs
- | ServeOnly (Maybe RegistryUrl)
- data MirroredLegs = MirroredLegs {
- mlPrivateUpstream :: RegistryUrl
- mlMirrorTarget :: MirrorTarget
- regPrivateUpstream :: MountRegistries -> Maybe RegistryUrl
- regMirrorTarget :: MountRegistries -> Maybe MirrorTarget
- data MirrorTarget = MirrorTarget {
- mtUrl :: RegistryUrl
- mtBackend :: StoreBackend
- data StoreTag
- storeTagName :: StoreTag -> Text
- data Target = Target {}
- data PrivateEndpoint = PrivateEndpoint {
- preTarget :: Target
- preToken :: Maybe Secret
- preConsent :: DeletionConsent
- data DeletionConsent
- data MirrorWrite
- = WriteRegistry Secret
- | WriteCodeArtifact (Maybe Natural)
- | WriteVerdaccio Secret DeletionConsent
- data MirrorEndpoint = MirrorEndpoint {
- meUrl :: RegistryUrl
- meWrite :: MirrorWrite
- meTarget :: MirrorEndpoint -> Target
- data PublicationEndpoint = PublicationEndpoint {}
- data MintPlan
- = MintCodeArtifact CodeArtifactConfig
- | MintStatic Secret
- data ControlPlane
- = ControlCodeArtifact CodeArtifactStore
- | ControlProtocol Secret DeletionConsent
- | ControlNone
- data StoreBackend
- = BackendRegistry Secret
- | BackendCodeArtifact CodeArtifactConfig CodeArtifactStore
- | BackendVerdaccio Secret DeletionConsent
- sbTag :: StoreBackend -> StoreTag
- sbMint :: StoreBackend -> MintPlan
- sbControl :: StoreBackend -> ControlPlane
- data FirstParty
- = FirstPartyNpmScopes (NonEmpty Scope)
- | FirstPartyPyPI (NonEmpty PyPIFirstParty)
- newtype MountIntegrity = MountIntegrity {
- miMinTrusted :: Maybe MinTrustedIntegrity
- data MountConfig = MountConfig {}
- data Url
- unUrl :: Url -> Text
- data QueueTarget
- data QueueUrl
- queueUrlText :: QueueUrl -> Text
- queueUrlTarget :: QueueUrl -> Maybe QueueTarget
- data AdvisoryStoreTarget = S3Store Text (Maybe Text)
- data AdvisoryStoreUrl
- advisoryStoreUrlText :: AdvisoryStoreUrl -> Text
- advisoryStoreTarget :: AdvisoryStoreUrl -> AdvisoryStoreTarget
- advisoryStoreBucket :: AdvisoryStoreUrl -> Text
- advisoryObjectKey :: AdvisoryStoreUrl -> FilePath -> Text
- newtype RulePatch = RulePatch (Map Text RuleEntry)
- data RuleEntry = RuleEntry {}
- newtype RulePolicy = RulePolicy {
- policyRules :: Map Text PrecededRule
- data PolicyError
- renderPolicyError :: PolicyError -> Text
- emptyPolicy :: RulePolicy
- defaultPolicy :: RulePolicy
- data ConfigError
- = ParseError Text
- | PolicyErrors [PolicyError]
- | PublicUrlRequired
- | MountMissingPrivateUpstream Ecosystem
- | CodeArtifactHostMismatch Ecosystem Text
- | CodeArtifactFormatUnsupported Ecosystem Text
- | CodeArtifactRepositoryMissing Ecosystem Text Text
- renderConfigError :: ConfigError -> Text
- loadConfig :: [(String, String)] -> Maybe ByteString -> Either [ConfigError] Config
- sameRegistry :: RegistryUrl -> RegistryUrl -> Bool
- mountPostureLines :: Config -> [Text]
- mountAdvisoryAge :: AdvisoriesSettings -> Mount -> MaxAdvisoryAge
- mountEpssRequirement :: Mount -> EpssRequirement
- mountAdvisoryDenials :: Mount -> [Text]
- mountDatabaseRequirement :: Mount -> DatabaseRequirement
- advisoryAgeLines :: Config -> [Text]
- advisoryEpssLines :: Config -> [Text]
- resolvedKeyProvenance :: [(String, String)] -> Maybe ByteString -> [Text]
Documentation
A completed load: the document's settings and the mounts resolved against them.
Constructors
| Config | |
Fields | |
The resolved application configuration, one sub-record per document group. The document schema and this type mirror each other one to one.
Constructors
data ServerSettings Source #
The server group: the inbound edge Écluse itself presents.
Constructors
| ServerSettings | |
Fields
| |
Instances
| Show ServerSettings Source # | |
Defined in Ecluse.Config.Types Methods showsPrec :: Int -> ServerSettings -> ShowS # show :: ServerSettings -> String # showList :: [ServerSettings] -> ShowS # | |
| Eq ServerSettings Source # | |
Defined in Ecluse.Config.Types Methods (==) :: ServerSettings -> ServerSettings -> Bool # (/=) :: ServerSettings -> ServerSettings -> Bool # | |
data QueueSettings Source #
The queue group: the mirror queue's destination, depth cap, and redelivery budget. The
URL's shape decides the backend, and the load derives it once (Ecluse.Config.QueueTarget).
Constructors
| QueueSettings | |
Fields
| |
Instances
| Show QueueSettings Source # | |
Defined in Ecluse.Config.Types Methods showsPrec :: Int -> QueueSettings -> ShowS # show :: QueueSettings -> String # showList :: [QueueSettings] -> ShowS # | |
| Eq QueueSettings Source # | |
Defined in Ecluse.Config.Types Methods (==) :: QueueSettings -> QueueSettings -> Bool # (/=) :: QueueSettings -> QueueSettings -> Bool # | |
data LimitsSettings Source #
The limits group: the hostile-input bounds. The memory plan computes the tenant-sized caps
when unset (Ecluse.Composition.MemoryPlan), a configured value winning, and the rest stay pinned.
Constructors
| LimitsSettings | |
Fields
| |
Instances
| Show LimitsSettings Source # | |
Defined in Ecluse.Config.Types Methods showsPrec :: Int -> LimitsSettings -> ShowS # show :: LimitsSettings -> String # showList :: [LimitsSettings] -> ShowS # | |
| Eq LimitsSettings Source # | |
Defined in Ecluse.Config.Types Methods (==) :: LimitsSettings -> LimitsSettings -> Bool # (/=) :: LimitsSettings -> LimitsSettings -> Bool # | |
data CacheSettings Source #
The cache group: the metadata cache's TTL and its computed-by-default bounds.
Constructors
| CacheSettings | |
Fields
| |
Instances
| Show CacheSettings Source # | |
Defined in Ecluse.Config.Types Methods showsPrec :: Int -> CacheSettings -> ShowS # show :: CacheSettings -> String # showList :: [CacheSettings] -> ShowS # | |
| Eq CacheSettings Source # | |
Defined in Ecluse.Config.Types Methods (==) :: CacheSettings -> CacheSettings -> Bool # (/=) :: CacheSettings -> CacheSettings -> Bool # | |
data IntegritySettings Source #
Global integrity floors. A mount can refine the trusted floor through MountIntegrity.
Constructors
| IntegritySettings | |
Fields
| |
Instances
| Show IntegritySettings Source # | |
Defined in Ecluse.Config.Types Methods showsPrec :: Int -> IntegritySettings -> ShowS # show :: IntegritySettings -> String # showList :: [IntegritySettings] -> ShowS # | |
| Eq IntegritySettings Source # | |
Defined in Ecluse.Config.Types Methods (==) :: IntegritySettings -> IntegritySettings -> Bool # (/=) :: IntegritySettings -> IntegritySettings -> Bool # | |
newtype EgressSettings Source #
The egress group: the operator's additions to the blocked target ranges.
Constructors
| EgressSettings | |
Fields | |
Instances
| Show EgressSettings Source # | |
Defined in Ecluse.Config.Types Methods showsPrec :: Int -> EgressSettings -> ShowS # show :: EgressSettings -> String # showList :: [EgressSettings] -> ShowS # | |
| Eq EgressSettings Source # | |
Defined in Ecluse.Config.Types Methods (==) :: EgressSettings -> EgressSettings -> Bool # (/=) :: EgressSettings -> EgressSettings -> Bool # | |
data AdvisoriesSettings Source #
The advisories group: the OSV/CVE pipeline's store, cadences, and upstream feeds.
Constructors
| AdvisoriesSettings | |
Fields
| |
Instances
| Show AdvisoriesSettings Source # | |
Defined in Ecluse.Config.Types Methods showsPrec :: Int -> AdvisoriesSettings -> ShowS # show :: AdvisoriesSettings -> String # showList :: [AdvisoriesSettings] -> ShowS # | |
| Eq AdvisoriesSettings Source # | |
Defined in Ecluse.Config.Types Methods (==) :: AdvisoriesSettings -> AdvisoriesSettings -> Bool # (/=) :: AdvisoriesSettings -> AdvisoriesSettings -> Bool # | |
data RuntimeSettings Source #
The runtime group: the process-sizing overrides. Unset, each is computed from the runtime
posture (cgroups, RTS, file-descriptor limit), with its provenance boot-logged.
Constructors
| RuntimeSettings | |
Fields | |
Instances
| Show RuntimeSettings Source # | |
Defined in Ecluse.Config.Types Methods showsPrec :: Int -> RuntimeSettings -> ShowS # show :: RuntimeSettings -> String # showList :: [RuntimeSettings] -> ShowS # | |
| Eq RuntimeSettings Source # | |
Defined in Ecluse.Config.Types Methods (==) :: RuntimeSettings -> RuntimeSettings -> Bool # (/=) :: RuntimeSettings -> RuntimeSettings -> Bool # | |
data ObservabilitySettings Source #
The observability group: log shape, log level, and telemetry switch.
Constructors
| ObservabilitySettings | |
Fields
| |
Instances
| Show ObservabilitySettings Source # | |
Defined in Ecluse.Config.Types Methods showsPrec :: Int -> ObservabilitySettings -> ShowS # show :: ObservabilitySettings -> String # showList :: [ObservabilitySettings] -> ShowS # | |
| Eq ObservabilitySettings Source # | |
Defined in Ecluse.Config.Types Methods (==) :: ObservabilitySettings -> ObservabilitySettings -> Bool # (/=) :: ObservabilitySettings -> ObservabilitySettings -> Bool # | |
data DredgerSettings Source #
The dredger group: how the mirror sweep paces itself, how much one cycle may delete, and
which names it carries. Only ecluse dredger reads it, and every other role carries it unread.
Constructors
| DredgerSettings | |
Fields
| |
Instances
| Show DredgerSettings Source # | |
Defined in Ecluse.Config.Types Methods showsPrec :: Int -> DredgerSettings -> ShowS # show :: DredgerSettings -> String # showList :: [DredgerSettings] -> ShowS # | |
| Eq DredgerSettings Source # | |
Defined in Ecluse.Config.Types Methods (==) :: DredgerSettings -> DredgerSettings -> Bool # (/=) :: DredgerSettings -> DredgerSettings -> Bool # | |
data QuotaOverride Source #
One store's declared request capacity. It supplies the capacity a backend publishes none of, and a shared scope joins two endpoints of one pool so the sweep paces them together.
Constructors
| QuotaOverride | |
Fields
| |
Instances
| Show QuotaOverride Source # | |
Defined in Ecluse.Config.Types Methods showsPrec :: Int -> QuotaOverride -> ShowS # show :: QuotaOverride -> String # showList :: [QuotaOverride] -> ShowS # | |
| Eq QuotaOverride Source # | |
Defined in Ecluse.Config.Types Methods (==) :: QuotaOverride -> QuotaOverride -> Bool # (/=) :: QuotaOverride -> QuotaOverride -> Bool # | |
type MountMap = Map Ecosystem Mount Source #
The mounts a load resolved, keyed by the ecosystem each was declared under.
One resolved mount: its ecosystem, its endpoints, and the rules in precedence order.
Constructors
| Mount | |
Fields
| |
data MountRegistries Source #
A resolved mount's endpoints: the public upstream it gates, and what it does with the rest.
Constructors
| MountRegistries | |
Fields
| |
Instances
| Show MountRegistries Source # | |
Defined in Ecluse.Config.Types Methods showsPrec :: Int -> MountRegistries -> ShowS # show :: MountRegistries -> String # showList :: [MountRegistries] -> ShowS # | |
| Eq MountRegistries Source # | |
Defined in Ecluse.Config.Types Methods (==) :: MountRegistries -> MountRegistries -> Bool # (/=) :: MountRegistries -> MountRegistries -> Bool # | |
Whether a mount mirrors, derived from its declared endpoints. A declared mirrorTarget makes
it Mirrored, which carries the private upstream the mirror is read back through, never without.
Constructors
| Mirrored MirroredLegs | The mount mirrors admitted public artifacts, and it needs both legs. |
| ServeOnly (Maybe RegistryUrl) | The mount never writes. It still merges the optional private upstream when present. |
data MirroredLegs Source #
A mirrored mount's two required halves: the readable private upstream and the mirror target married to its derived write credential.
Constructors
| MirroredLegs | |
Fields
| |
Instances
| Show MirroredLegs Source # | |
Defined in Ecluse.Config.Types Methods showsPrec :: Int -> MirroredLegs -> ShowS # show :: MirroredLegs -> String # showList :: [MirroredLegs] -> ShowS # | |
| Eq MirroredLegs Source # | |
Defined in Ecluse.Config.Types | |
regPrivateUpstream :: MountRegistries -> Maybe RegistryUrl Source #
The mount's private upstream, when it has one. It is total over both mount modes.
regMirrorTarget :: MountRegistries -> Maybe MirrorTarget Source #
The mount's mirror target (with its derived credential), when it mirrors.
data MirrorTarget Source #
A mirror target married to the backend resolved from the tag it was declared under.
Constructors
| MirrorTarget | |
Fields
| |
Instances
| Show MirrorTarget Source # | |
Defined in Ecluse.Config.Types Methods showsPrec :: Int -> MirrorTarget -> ShowS # show :: MirrorTarget -> String # showList :: [MirrorTarget] -> ShowS # | |
| Eq MirrorTarget Source # | |
Defined in Ecluse.Config.Types | |
Which store backend an endpoint names. The operator declares it as the one key under the endpoint, and the load validates the URL against it rather than guessing it from a host shape.
Constructors
| TagRegistry | Any host that speaks the ecosystem's protocol, authenticated by a static token. |
| TagCodeArtifact | A CodeArtifact repository endpoint, which mints its own write token. |
| TagVerdaccio | A Verdaccio development store, authenticated by a static token. |
Instances
storeTagName :: StoreTag -> Text Source #
The tag as an operator writes it, and as a refusal names it.
An endpoint as a mount declares it: the tag naming its store, and the URL under that tag.
data PrivateEndpoint Source #
A private read endpoint with maintenance authority used only by Dredger.
Constructors
| PrivateEndpoint | |
Fields
| |
Instances
| Show PrivateEndpoint Source # | |
Defined in Ecluse.Config.Types Methods showsPrec :: Int -> PrivateEndpoint -> ShowS # show :: PrivateEndpoint -> String # showList :: [PrivateEndpoint] -> ShowS # | |
| Eq PrivateEndpoint Source # | |
Defined in Ecluse.Config.Types Methods (==) :: PrivateEndpoint -> PrivateEndpoint -> Bool # (/=) :: PrivateEndpoint -> PrivateEndpoint -> Bool # | |
data DeletionConsent Source #
Whether the operator consented to ecluse dredger deleting from a Verdaccio store. It is a
declaration about that one store, so it exists under no other tag.
Constructors
| DeletionPermitted | |
| DeletionWithheld |
Instances
| Show DeletionConsent Source # | |
Defined in Ecluse.Config.Types Methods showsPrec :: Int -> DeletionConsent -> ShowS # show :: DeletionConsent -> String # showList :: [DeletionConsent] -> ShowS # | |
| Eq DeletionConsent Source # | |
Defined in Ecluse.Config.Types Methods (==) :: DeletionConsent -> DeletionConsent -> Bool # (/=) :: DeletionConsent -> DeletionConsent -> Bool # | |
data MirrorWrite Source #
How a mount's mirror write authenticates, one arm per tag. The mirror write is Écluse's one standing credential, so a minting tag carries no static token and a non-minting tag requires one.
Constructors
| WriteRegistry Secret | Any protocol-speaking host: the operator's static write token. |
| WriteCodeArtifact (Maybe Natural) | A CodeArtifact repository: the requested lifetime of the token it mints. |
| WriteVerdaccio Secret DeletionConsent | A Verdaccio store: its static write token, and the operator's deletion consent. |
Instances
| Show MirrorWrite Source # | |
Defined in Ecluse.Config.Types Methods showsPrec :: Int -> MirrorWrite -> ShowS # show :: MirrorWrite -> String # showList :: [MirrorWrite] -> ShowS # | |
| Eq MirrorWrite Source # | |
Defined in Ecluse.Config.Types | |
data MirrorEndpoint Source #
A declared mirrorTarget: where the mirror writes, and how that write authenticates.
Constructors
| MirrorEndpoint | |
Fields
| |
Instances
| Show MirrorEndpoint Source # | |
Defined in Ecluse.Config.Types Methods showsPrec :: Int -> MirrorEndpoint -> ShowS # show :: MirrorEndpoint -> String # showList :: [MirrorEndpoint] -> ShowS # | |
| Eq MirrorEndpoint Source # | |
Defined in Ecluse.Config.Types Methods (==) :: MirrorEndpoint -> MirrorEndpoint -> Bool # (/=) :: MirrorEndpoint -> MirrorEndpoint -> Bool # | |
meTarget :: MirrorEndpoint -> Target Source #
The mirror endpoint as the collision rules read it. The tag comes from meWrite.
data PublicationEndpoint Source #
A declared publicationTarget: where a client publish is relayed, and the static credential
forwarded only when the publishing client sends none.
Constructors
| PublicationEndpoint | |
Instances
| Show PublicationEndpoint Source # | |
Defined in Ecluse.Config.Types Methods showsPrec :: Int -> PublicationEndpoint -> ShowS # show :: PublicationEndpoint -> String # showList :: [PublicationEndpoint] -> ShowS # | |
| Eq PublicationEndpoint Source # | |
Defined in Ecluse.Config.Types Methods (==) :: PublicationEndpoint -> PublicationEndpoint -> Bool # (/=) :: PublicationEndpoint -> PublicationEndpoint -> Bool # | |
How a mount's mirror write authenticates, projected from its resolved StoreBackend.
Constructors
| MintCodeArtifact CodeArtifactConfig | A CodeArtifact mirror target: the mint identity parsed from its host. |
| MintStatic Secret | Any other mirror target: an operator-supplied static write token. |
Instances
data ControlPlane Source #
The control plane a mount's store offers, the face ecluse dredger deletes through.
Constructors
| ControlCodeArtifact CodeArtifactStore | The CodeArtifact repository the target addresses, which the load has vetted. |
| ControlProtocol Secret DeletionConsent | A store with no vendor control plane, swept through the ecosystem protocol's own verbs: its write token, and the operator's consent to delete from it. |
| ControlNone | The tag names no control plane this build implements. |
Instances
| Show ControlPlane Source # | |
Defined in Ecluse.Config.Types Methods showsPrec :: Int -> ControlPlane -> ShowS # show :: ControlPlane -> String # showList :: [ControlPlane] -> ShowS # | |
| Eq ControlPlane Source # | |
Defined in Ecluse.Config.Types | |
data StoreBackend Source #
A mount's store backend, resolved once at load (Ecluse.Config.Target), so no two roles infer a different one. The tag discriminates, so no arm pairs one store's mint with another's plane.
Constructors
| BackendRegistry Secret | A protocol-speaking host: its static write token, and no control plane. |
| BackendCodeArtifact CodeArtifactConfig CodeArtifactStore | A CodeArtifact repository: the identity it mints from, and the store a sweep deletes in. |
| BackendVerdaccio Secret DeletionConsent | A Verdaccio store: its static write token, and the operator's deletion consent. |
Instances
| Show StoreBackend Source # | |
Defined in Ecluse.Config.Types Methods showsPrec :: Int -> StoreBackend -> ShowS # show :: StoreBackend -> String # showList :: [StoreBackend] -> ShowS # | |
| Eq StoreBackend Source # | |
Defined in Ecluse.Config.Types | |
sbTag :: StoreBackend -> StoreTag Source #
The tag a backend was declared under.
sbMint :: StoreBackend -> MintPlan Source #
How the mirror write to this backend authenticates.
sbControl :: StoreBackend -> ControlPlane Source #
The control plane this build reaches for a backend.
data FirstParty Source #
The namespaces a mount's deployment owns, one arm per ecosystem, read only in that registry's own naming shape. Every consumer of the privilege derives its predicate from this one value.
Constructors
| FirstPartyNpmScopes (NonEmpty Scope) | The npm scopes the deployment owns, at least one. |
| FirstPartyPyPI (NonEmpty PyPIFirstParty) | The PyPI distributions and name prefixes the deployment owns, at least one. |
Instances
| Show FirstParty Source # | |
Defined in Ecluse.Config.Types Methods showsPrec :: Int -> FirstParty -> ShowS # show :: FirstParty -> String # showList :: [FirstParty] -> ShowS # | |
| Eq FirstParty Source # | |
Defined in Ecluse.Config.Types | |
newtype MountIntegrity Source #
A mount's refinements of the global integrity group, under its own integrity key so the
mount groups them exactly as the top level does. Each is Nothing at the global setting.
Constructors
| MountIntegrity | |
Fields
| |
Instances
| Show MountIntegrity Source # | |
Defined in Ecluse.Config.Types Methods showsPrec :: Int -> MountIntegrity -> ShowS # show :: MountIntegrity -> String # showList :: [MountIntegrity] -> ShowS # | |
| Eq MountIntegrity Source # | |
Defined in Ecluse.Config.Types Methods (==) :: MountIntegrity -> MountIntegrity -> Bool # (/=) :: MountIntegrity -> MountIntegrity -> Bool # | |
data MountConfig Source #
One mount as the document declares it, before Ecluse.Config resolves it into a Mount.
Constructors
| MountConfig | |
Fields
| |
Instances
| Show MountConfig Source # | |
Defined in Ecluse.Config.Types Methods showsPrec :: Int -> MountConfig -> ShowS # show :: MountConfig -> String # showList :: [MountConfig] -> ShowS # | |
| Eq MountConfig Source # | |
Defined in Ecluse.Config.Types | |
An operator-configured http(s) URL, whitespace-trimmed. mkUrl is the only builder, so no
value exists carrying credential material, another scheme, or an authority the egress gate misses.
data QueueTarget Source #
A recognised mirror-queue destination, parsed from the queue URL's shape.
Constructors
| SqsTarget Text | An SQS queue URL, carrying the region parsed from its host. |
| PubSubTarget Text Text | A Pub/Sub topic resource, carrying its project and topic. |
Instances
| Show QueueTarget Source # | |
Defined in Ecluse.Config.Queue.Internal Methods showsPrec :: Int -> QueueTarget -> ShowS # show :: QueueTarget -> String # showList :: [QueueTarget] -> ShowS # | |
| Eq QueueTarget Source # | |
Defined in Ecluse.Config.Queue.Internal | |
queue.url as parsed at load (mkQueueUrl): the value as written,
with the backend its shape names, or no backend when only the SQS endpoint override can dial it.
queueUrlText :: QueueUrl -> Text Source #
The value as written, trimmed.
queueUrlTarget :: QueueUrl -> Maybe QueueTarget Source #
The backend the value's shape names, Nothing when it names none.
data AdvisoryStoreTarget Source #
A recognised advisory-database store, parsed from the URL's scheme. It carries the bucket and the optional key prefix under which the compiled artifacts live.
Instances
| Show AdvisoryStoreTarget Source # | |
Defined in Ecluse.Config.Advisory.Internal Methods showsPrec :: Int -> AdvisoryStoreTarget -> ShowS # show :: AdvisoryStoreTarget -> String # showList :: [AdvisoryStoreTarget] -> ShowS # | |
| Eq AdvisoryStoreTarget Source # | |
Defined in Ecluse.Config.Advisory.Internal Methods (==) :: AdvisoryStoreTarget -> AdvisoryStoreTarget -> Bool # (/=) :: AdvisoryStoreTarget -> AdvisoryStoreTarget -> Bool # | |
data AdvisoryStoreUrl Source #
advisories.url as parsed at load (mkAdvisoryStoreUrl): the
value as written, with the store its scheme names.
Instances
| Show AdvisoryStoreUrl Source # | |
Defined in Ecluse.Config.Advisory.Internal Methods showsPrec :: Int -> AdvisoryStoreUrl -> ShowS # show :: AdvisoryStoreUrl -> String # showList :: [AdvisoryStoreUrl] -> ShowS # | |
| Eq AdvisoryStoreUrl Source # | |
Defined in Ecluse.Config.Advisory.Internal Methods (==) :: AdvisoryStoreUrl -> AdvisoryStoreUrl -> Bool # (/=) :: AdvisoryStoreUrl -> AdvisoryStoreUrl -> Bool # | |
advisoryStoreUrlText :: AdvisoryStoreUrl -> Text Source #
The value as written, trimmed.
advisoryStoreTarget :: AdvisoryStoreUrl -> AdvisoryStoreTarget Source #
The store the value's scheme names.
advisoryStoreBucket :: AdvisoryStoreUrl -> Text Source #
The bucket the store names.
advisoryObjectKey :: AdvisoryStoreUrl -> FilePath -> Text Source #
The object key one compiled artifact takes in the store: the configured prefix ahead of the artifact's own file name.
A declared rules object: one RuleEntry per rule name it names.
One rule's declared keys, every one optional. Which of them the entry may set depends on the
rule type, and refuseStrayParameters refuses the rest.
Constructors
| RuleEntry | |
Fields
| |
newtype RulePolicy Source #
A resolved rule set, keyed by the rule name an operator patches it under.
Constructors
| RulePolicy | |
Fields
| |
Instances
| Show RulePolicy Source # | |
Defined in Ecluse.Config.Rule Methods showsPrec :: Int -> RulePolicy -> ShowS # show :: RulePolicy -> String # showList :: [RulePolicy] -> ShowS # | |
| Eq RulePolicy Source # | |
Defined in Ecluse.Config.Rule | |
data PolicyError Source #
Why one declared rule was refused. A load reports every one it accumulated.
Constructors
| MissingRuleType Text | |
| UnknownRuleType Text Text | |
| MalformedRule Text Text | |
| SuppressUnknownRule Text |
Instances
| Show PolicyError Source # | |
Defined in Ecluse.Config.Rule Methods showsPrec :: Int -> PolicyError -> ShowS # show :: PolicyError -> String # showList :: [PolicyError] -> ShowS # | |
| Eq PolicyError Source # | |
Defined in Ecluse.Config.Rule | |
renderPolicyError :: PolicyError -> Text Source #
One refusal as the boot reports it, naming the rule it was declared under.
emptyPolicy :: RulePolicy Source #
The policy a load starts from before the shipped defaults are applied.
defaultPolicy :: RulePolicy Source #
The rule policy embedded in the shipped configuration.
data ConfigError Source #
Why a load was refused. renderConfigError writes each one as the boot reports it.
Constructors
| ParseError Text | |
| PolicyErrors [PolicyError] | |
| PublicUrlRequired | A mount is active but |
| MountMissingPrivateUpstream Ecosystem | A mount declares a |
| CodeArtifactHostMismatch Ecosystem Text | An endpoint declared under the |
| CodeArtifactFormatUnsupported Ecosystem Text | A |
| CodeArtifactRepositoryMissing Ecosystem Text Text | A |
Instances
| Show ConfigError Source # | |
Defined in Ecluse.Config.Types Methods showsPrec :: Int -> ConfigError -> ShowS # show :: ConfigError -> String # showList :: [ConfigError] -> ShowS # | |
| Eq ConfigError Source # | |
Defined in Ecluse.Config.Types | |
renderConfigError :: ConfigError -> Text Source #
loadConfig :: [(String, String)] -> Maybe ByteString -> Either [ConfigError] Config Source #
Load the merged configuration: the defaults, the operator document, then the environment overlay, strongest-last. A mount is active only where that overlay declares a key under it.
sameRegistry :: RegistryUrl -> RegistryUrl -> Bool Source #
Whether two configured endpoints name the same registry. The authority folds to lower case with its default port applied, and the path is compared exactly past a trailing slash.
mountPostureLines :: Config -> [Text] Source #
Mount modes followed by the live-environment limits of check-config, shared with boot.
mountAdvisoryAge :: AdvisoriesSettings -> Mount -> MaxAdvisoryAge Source #
One mount's effective maximum advisory push age, derived from that mount's own rules. An
explicit advisories.maxAgeSeconds overrides the derivation on every mount.
mountEpssRequirement :: Mount -> EpssRequirement Source #
Require enrichment when this mount's resolved policy contains an EPSS rule.
mountAdvisoryDenials :: Mount -> [Text] Source #
The names of this mount's rules that deny on the advisory database, in policy order. A non-empty list is what makes an advisory store mandatory and the mount's readiness wait for one.
mountDatabaseRequirement :: Mount -> DatabaseRequirement Source #
Whether this mount must hold an advisory database before it can serve anything.
advisoryAgeLines :: Config -> [Text] Source #
The effective maximum push age of every mount whose rules read the advisory database, with the basis that produced it. With no store configured nothing syncs, so nothing has an age.
advisoryEpssLines :: Config -> [Text] Source #
Each mount's EPSS requirement, which Pilot and that mount's advisory consumers apply alike.
It is reported with no store too, because pilot compile runs under it without uploading.
resolvedKeyProvenance :: [(String, String)] -> Maybe ByteString -> [Text] Source #
One line per resolved leaf of the merged configuration: the dotted path, the redacted value, and its layer. Empty when a layer fails to parse, and a boot-computed key has no leaf to report.