ecluse:ecluse-core
Safe HaskellNone
LanguageGHC2021

Ecluse.Core.Registry.Maintenance.Upstream

Description

Whether public content can reach clients through a private repository, and the bounded walk of its upstream chain a backend answers with. The answer is a value the boot reads, so the words an operator sees live in the boot renderers rather than here.

Synopsis

The answer

data UpstreamSafety Source #

Whether public content can reach a client through one repository.

Constructors

Safe

Nothing public reaches a client through it.

Unsafe UnsafeReason

Public content reaches a client, or an identity that cannot ask assumed that it does.

Undecidable UndecidabilityReason

The question stayed open, so the threat stays the operator's.

data UnsafeReason Source #

What made a repository unsafe to serve private content from.

Constructors

ConfigurationEvidence RepositoryName ExternalConnection

This repository, or one in its chain, carries the named connection to a public registry.

InsufficientPermissions PermissionName

The role's identity may not read the configuration, which fails closed.

data UndecidabilityReason Source #

Why an answer stayed open.

Constructors

NoMechanism

The backend reports no upstream configuration at all.

NetworkFailure

The backend did not answer, or faulted before it did.

ChainBoundExceeded

The walk met a ceiling with part of the chain still unread.

noUpstreamMechanism :: Applicative m => m UpstreamSafety Source #

The answer of a backend whose control plane reports no upstream configuration.

What an answer names

newtype PermissionName Source #

The grant an identity needs to read a repository's configuration, as the backend spells it.

Constructors

PermissionName 

The chain walk

data RepositoryLinks Source #

What one repository reported: what it admits from outside, and where it forwards a miss.

walkUpstreamChain :: Monad m => (RepositoryName -> m (Either UpstreamSafety RepositoryLinks)) -> RepositoryName -> m UpstreamSafety Source #

Walk a repository's upstream chain breadth-first, stopping at the first external connection. A hop the reader could not read settles the answer, and a ceiling leaves it undecided, never safe.

upstreamHopCeiling :: Int Source #

How many repositories deep the walk follows a chain.

upstreamCallCeiling :: Int Source #

How many reads one whole walk makes.