ecluse:ecluse-core
Safe HaskellNone
LanguageGHC2021

Ecluse.Core.Server.Upstream

Description

A mount's configured upstreams and the tarball-host gate derived from them, as one opaque cluster with a private constructor.

The TarballHostGate is built once per mount from the three upstream URLs, so the hot artifact path re-parses nothing. A gate that disagreed with those URLs would silently authorise the wrong authorities, so mountUpstreams is the only builder and neither the constructor nor the selectors are exported: an upstreams{...} update alone would break the pair.

Synopsis

Mirror serve plan

data MirrorServePlan Source #

Whether an admitted public artifact is enqueued for the demand-driven mirror, and where that write lands. A serve-only mount opens no producer span and emits no enqueue metric.

Constructors

MirrorOnAdmit RegistryUrl

Enqueue admitted public artifacts for publication to this mirror-target endpoint. The worker resolves its publish capability from the same configuration.

NoMirrorWrite

Serve-only: admitted public artifacts stream to the client and are mirrored nowhere.

The upstream cluster

data MountUpstreams Source #

A mount's three configured upstreams and the tarball-host gate they derive. Exported abstract, so the carried gate is always the gate of the carried URLs.

mountUpstreams :: [Text] -> Maybe RegistryUrl -> RegistryUrl -> MirrorServePlan -> MountUpstreams Source #

Bind a mount's upstreams. This is the only caller of tarballHostGate outside that gate's own specs, so the allowlist and the reference authorities have one derivation.

upstreamPrivateBaseUrl :: MountUpstreams -> Maybe RegistryUrl Source #

The private upstream base URL. Nothing when the mount has no private upstream, so the private leg is structurally absent rather than misconfigured.

upstreamPublicBaseUrl :: MountUpstreams -> RegistryUrl Source #

The public upstream base URL.

upstreamMirror :: MountUpstreams -> MirrorServePlan Source #

The mirror serve plan, carrying the mirror-target endpoint when there is one.

upstreamTarballHostGate :: MountUpstreams -> TarballHostGate Source #

The tarball-host gate of these upstreams: the canonicalised host:port allowlist and the private and public reference authorities the per-request SSRF check decides against.