ecluse:ecluse-runtime
Safe HaskellNone
LanguageGHC2021

Ecluse.Runtime.Credential.CodeArtifact.Internal

Description

The mint closure and its amazonka environment behind Ecluse.Runtime.Credential.CodeArtifact, which documents the leaf and re-exports the curated surface. Importing this module opts out of that stability promise, the convention text and bytestring use, so production code imports the public one.

Synopsis

Configuration

data CodeArtifactConfig Source #

What the CodeArtifact leaf needs to mint a token. The AWS credentials are not here: discover finds them in the ambient environment, so the proxy never holds long-lived AWS keys.

Constructors

CodeArtifactConfig 

Fields

  • caRegion :: Text

    The AWS region the CodeArtifact domain lives in (e.g. "us-east-1").

  • caDomain :: Text

    The CodeArtifact domain that scopes the token.

  • caDomainOwner :: Maybe Text

    The 12-digit account number that owns the domain, when it differs from the calling account (Nothing to default to the caller's account).

  • caDurationSeconds :: Maybe Natural

    Requested token lifetime in seconds (900-43200). Nothing defaults it to the caller's role-credential expiry, and the refresh policy adapts to the minted expiry anyway.

The provider

newCodeArtifactProvider :: CredentialReporters -> CodeArtifactConfig -> IO CredentialProvider Source #

Build a refreshing CredentialProvider backed by CodeArtifact GetAuthorizationToken. It mints once eagerly, so a misconfiguration fails at construction, not on the first mirror write.

providerForEnv :: CredentialReporters -> Env -> CodeArtifactConfig -> IO CredentialProvider Source #

Build the provider over a caller-supplied amazonka Env, minting through the policy of Ecluse.Core.Credential.Refresh. Exposed so a test can drive the mint against a stub endpoint.