| Safe Haskell | None |
|---|---|
| Language | GHC2021 |
Ecluse.Core.Registry.Maintenance.Upstream
Description
Whether public content can reach clients through a private repository, and the bounded walk of its upstream chain a backend answers with. The answer is a value the boot reads, so the words an operator sees live in the boot renderers rather than here.
Synopsis
- data UpstreamSafety
- data UnsafeReason
- data UndecidabilityReason
- noUpstreamMechanism :: Applicative m => m UpstreamSafety
- newtype RepositoryName = RepositoryName {}
- newtype ExternalConnection = ExternalConnection {}
- newtype PermissionName = PermissionName {}
- data RepositoryLinks = RepositoryLinks {}
- walkUpstreamChain :: Monad m => (RepositoryName -> m (Either UpstreamSafety RepositoryLinks)) -> RepositoryName -> m UpstreamSafety
- upstreamHopCeiling :: Int
- upstreamCallCeiling :: Int
The answer
data UpstreamSafety Source #
Whether public content can reach a client through one repository.
Constructors
| Safe | Nothing public reaches a client through it. |
| Unsafe UnsafeReason | Public content reaches a client, or an identity that cannot ask assumed that it does. |
| Undecidable UndecidabilityReason | The question stayed open, so the threat stays the operator's. |
Instances
| Show UpstreamSafety Source # | |
Defined in Ecluse.Core.Registry.Maintenance.Upstream Methods showsPrec :: Int -> UpstreamSafety -> ShowS # show :: UpstreamSafety -> String # showList :: [UpstreamSafety] -> ShowS # | |
| Eq UpstreamSafety Source # | |
Defined in Ecluse.Core.Registry.Maintenance.Upstream Methods (==) :: UpstreamSafety -> UpstreamSafety -> Bool # (/=) :: UpstreamSafety -> UpstreamSafety -> Bool # | |
data UnsafeReason Source #
What made a repository unsafe to serve private content from.
Constructors
| ConfigurationEvidence RepositoryName ExternalConnection | This repository, or one in its chain, carries the named connection to a public registry. |
| InsufficientPermissions PermissionName | The role's identity may not read the configuration, which fails closed. |
Instances
| Show UnsafeReason Source # | |
Defined in Ecluse.Core.Registry.Maintenance.Upstream Methods showsPrec :: Int -> UnsafeReason -> ShowS # show :: UnsafeReason -> String # showList :: [UnsafeReason] -> ShowS # | |
| Eq UnsafeReason Source # | |
Defined in Ecluse.Core.Registry.Maintenance.Upstream | |
data UndecidabilityReason Source #
Why an answer stayed open.
Constructors
| NoMechanism | The backend reports no upstream configuration at all. |
| NetworkFailure | The backend did not answer, or faulted before it did. |
| ChainBoundExceeded | The walk met a ceiling with part of the chain still unread. |
Instances
| Show UndecidabilityReason Source # | |
Defined in Ecluse.Core.Registry.Maintenance.Upstream Methods showsPrec :: Int -> UndecidabilityReason -> ShowS # show :: UndecidabilityReason -> String # showList :: [UndecidabilityReason] -> ShowS # | |
| Eq UndecidabilityReason Source # | |
Defined in Ecluse.Core.Registry.Maintenance.Upstream Methods (==) :: UndecidabilityReason -> UndecidabilityReason -> Bool # (/=) :: UndecidabilityReason -> UndecidabilityReason -> Bool # | |
noUpstreamMechanism :: Applicative m => m UpstreamSafety Source #
The answer of a backend whose control plane reports no upstream configuration.
What an answer names
newtype RepositoryName Source #
A repository, as the backend that holds it names it.
Constructors
| RepositoryName | |
Fields | |
Instances
| Show RepositoryName Source # | |
Defined in Ecluse.Core.Registry.Maintenance.Upstream Methods showsPrec :: Int -> RepositoryName -> ShowS # show :: RepositoryName -> String # showList :: [RepositoryName] -> ShowS # | |
| Eq RepositoryName Source # | |
Defined in Ecluse.Core.Registry.Maintenance.Upstream Methods (==) :: RepositoryName -> RepositoryName -> Bool # (/=) :: RepositoryName -> RepositoryName -> Bool # | |
| Ord RepositoryName Source # | |
Defined in Ecluse.Core.Registry.Maintenance.Upstream Methods compare :: RepositoryName -> RepositoryName -> Ordering # (<) :: RepositoryName -> RepositoryName -> Bool # (<=) :: RepositoryName -> RepositoryName -> Bool # (>) :: RepositoryName -> RepositoryName -> Bool # (>=) :: RepositoryName -> RepositoryName -> Bool # max :: RepositoryName -> RepositoryName -> RepositoryName # min :: RepositoryName -> RepositoryName -> RepositoryName # | |
newtype ExternalConnection Source #
A backend's own name for a connection that admits content from a public registry.
Constructors
| ExternalConnection | |
Fields | |
Instances
| Show ExternalConnection Source # | |
Defined in Ecluse.Core.Registry.Maintenance.Upstream Methods showsPrec :: Int -> ExternalConnection -> ShowS # show :: ExternalConnection -> String # showList :: [ExternalConnection] -> ShowS # | |
| Eq ExternalConnection Source # | |
Defined in Ecluse.Core.Registry.Maintenance.Upstream Methods (==) :: ExternalConnection -> ExternalConnection -> Bool # (/=) :: ExternalConnection -> ExternalConnection -> Bool # | |
| Ord ExternalConnection Source # | |
Defined in Ecluse.Core.Registry.Maintenance.Upstream Methods compare :: ExternalConnection -> ExternalConnection -> Ordering # (<) :: ExternalConnection -> ExternalConnection -> Bool # (<=) :: ExternalConnection -> ExternalConnection -> Bool # (>) :: ExternalConnection -> ExternalConnection -> Bool # (>=) :: ExternalConnection -> ExternalConnection -> Bool # max :: ExternalConnection -> ExternalConnection -> ExternalConnection # min :: ExternalConnection -> ExternalConnection -> ExternalConnection # | |
newtype PermissionName Source #
The grant an identity needs to read a repository's configuration, as the backend spells it.
Constructors
| PermissionName | |
Fields | |
Instances
| Show PermissionName Source # | |
Defined in Ecluse.Core.Registry.Maintenance.Upstream Methods showsPrec :: Int -> PermissionName -> ShowS # show :: PermissionName -> String # showList :: [PermissionName] -> ShowS # | |
| Eq PermissionName Source # | |
Defined in Ecluse.Core.Registry.Maintenance.Upstream Methods (==) :: PermissionName -> PermissionName -> Bool # (/=) :: PermissionName -> PermissionName -> Bool # | |
The chain walk
data RepositoryLinks Source #
What one repository reported: what it admits from outside, and where it forwards a miss.
Constructors
| RepositoryLinks | |
Fields | |
Instances
| Show RepositoryLinks Source # | |
Defined in Ecluse.Core.Registry.Maintenance.Upstream Methods showsPrec :: Int -> RepositoryLinks -> ShowS # show :: RepositoryLinks -> String # showList :: [RepositoryLinks] -> ShowS # | |
| Eq RepositoryLinks Source # | |
Defined in Ecluse.Core.Registry.Maintenance.Upstream Methods (==) :: RepositoryLinks -> RepositoryLinks -> Bool # (/=) :: RepositoryLinks -> RepositoryLinks -> Bool # | |
walkUpstreamChain :: Monad m => (RepositoryName -> m (Either UpstreamSafety RepositoryLinks)) -> RepositoryName -> m UpstreamSafety Source #
Walk a repository's upstream chain breadth-first, stopping at the first external connection. A hop the reader could not read settles the answer, and a ceiling leaves it undecided, never safe.
upstreamHopCeiling :: Int Source #
How many repositories deep the walk follows a chain.
upstreamCallCeiling :: Int Source #
How many reads one whole walk makes.