| Safe Haskell | None |
|---|---|
| Language | GHC2021 |
Ecluse.Runtime.Credential.CodeArtifact
Contents
Description
The AWS CodeArtifact leaf of the outbound-credential handle: mint a short-lived registry
bearer token through GetAuthorizationToken, carrying its real expiry so the refresh policy
schedules off the token's own lifetime. Caching, proactive refresh, single-flight, and the
breaker are the cloud-agnostic policy of Ecluse.Core.Credential.Refresh, which this leaf
wires its mint into. This is control plane only: the data plane that uses the token stays
on http-client. The amazonka Env is built once at provider creation and captured in the
mint closure, so the backend's state never reaches the proxy's Env.
Synopsis
- data CodeArtifactConfig = CodeArtifactConfig {}
- newCodeArtifactProvider :: CredentialReporters -> CodeArtifactConfig -> IO CredentialProvider
Configuration
data CodeArtifactConfig Source #
What the CodeArtifact leaf needs to mint a token. The AWS credentials are not here:
discover finds them in the ambient environment, so the proxy never holds long-lived AWS keys.
Constructors
| CodeArtifactConfig | |
Fields
| |
Instances
| Show CodeArtifactConfig Source # | |
Defined in Ecluse.Runtime.Credential.CodeArtifact.Internal Methods showsPrec :: Int -> CodeArtifactConfig -> ShowS # show :: CodeArtifactConfig -> String # showList :: [CodeArtifactConfig] -> ShowS # | |
| Eq CodeArtifactConfig Source # | |
Defined in Ecluse.Runtime.Credential.CodeArtifact.Internal Methods (==) :: CodeArtifactConfig -> CodeArtifactConfig -> Bool # (/=) :: CodeArtifactConfig -> CodeArtifactConfig -> Bool # | |
| Ord CodeArtifactConfig Source # | |
Defined in Ecluse.Runtime.Credential.CodeArtifact.Internal Methods compare :: CodeArtifactConfig -> CodeArtifactConfig -> Ordering # (<) :: CodeArtifactConfig -> CodeArtifactConfig -> Bool # (<=) :: CodeArtifactConfig -> CodeArtifactConfig -> Bool # (>) :: CodeArtifactConfig -> CodeArtifactConfig -> Bool # (>=) :: CodeArtifactConfig -> CodeArtifactConfig -> Bool # max :: CodeArtifactConfig -> CodeArtifactConfig -> CodeArtifactConfig # min :: CodeArtifactConfig -> CodeArtifactConfig -> CodeArtifactConfig # | |
The provider
newCodeArtifactProvider :: CredentialReporters -> CodeArtifactConfig -> IO CredentialProvider Source #
Build a refreshing CredentialProvider backed by CodeArtifact GetAuthorizationToken. It
mints once eagerly, so a misconfiguration fails at construction, not on the first mirror write.