ecluse:ecluse-runtime
Safe HaskellNone
LanguageGHC2021

Ecluse.Runtime.Credential.CodeArtifact

Description

The AWS CodeArtifact leaf of the outbound-credential handle: mint a short-lived registry bearer token through GetAuthorizationToken, carrying its real expiry so the refresh policy schedules off the token's own lifetime. Caching, proactive refresh, single-flight, and the breaker are the cloud-agnostic policy of Ecluse.Core.Credential.Refresh, which this leaf wires its mint into. This is control plane only: the data plane that uses the token stays on http-client. The amazonka Env is built once at provider creation and captured in the mint closure, so the backend's state never reaches the proxy's Env.

Synopsis

Configuration

data CodeArtifactConfig Source #

What the CodeArtifact leaf needs to mint a token. The AWS credentials are not here: discover finds them in the ambient environment, so the proxy never holds long-lived AWS keys.

Constructors

CodeArtifactConfig 

Fields

  • caRegion :: Text

    The AWS region the CodeArtifact domain lives in (e.g. "us-east-1").

  • caDomain :: Text

    The CodeArtifact domain that scopes the token.

  • caDomainOwner :: Maybe Text

    The 12-digit account number that owns the domain, when it differs from the calling account (Nothing to default to the caller's account).

  • caDurationSeconds :: Maybe Natural

    Requested token lifetime in seconds (900-43200). Nothing defaults it to the caller's role-credential expiry, and the refresh policy adapts to the minted expiry anyway.

The provider

newCodeArtifactProvider :: CredentialReporters -> CodeArtifactConfig -> IO CredentialProvider Source #

Build a refreshing CredentialProvider backed by CodeArtifact GetAuthorizationToken. It mints once eagerly, so a misconfiguration fails at construction, not on the first mirror write.