Skip to main content

Manager

Struct Manager 

Source
pub struct Manager {
    cfg: ManagerConfig,
    factory: Arc<dyn AcmeClientFactory>,
    client: Mutex<Option<Arc<dyn AcmeClient>>>,
    storage: Arc<dyn CertStorage>,
    solver: Arc<TlsAlpnSolver>,
    certs: Arc<ArcSwap<HashMap<String, ManagedCert>>>,
    slots: Vec<ManagedSlot>,
    controls: HashMap<String, SlotControl>,
    metrics: Option<Arc<AcmeMetrics>>,
    owner: String,
}

Fields§

§cfg: ManagerConfig§factory: Arc<dyn AcmeClientFactory>§client: Mutex<Option<Arc<dyn AcmeClient>>>§storage: Arc<dyn CertStorage>§solver: Arc<TlsAlpnSolver>§certs: Arc<ArcSwap<HashMap<String, ManagedCert>>>§slots: Vec<ManagedSlot>§controls: HashMap<String, SlotControl>§metrics: Option<Arc<AcmeMetrics>>§owner: String

Implementations§

Source§

impl Manager

Source

pub fn new( cfg: ManagerConfig, factory: Arc<dyn AcmeClientFactory>, storage: Arc<dyn CertStorage>, solver: Arc<TlsAlpnSolver>, certs: Arc<ArcSwap<HashMap<String, ManagedCert>>>, slots: Vec<ManagedSlot>, metrics: Option<Arc<AcmeMetrics>>, ) -> Arc<Self>

Source

pub fn slots(&self) -> &[ManagedSlot]

Source

pub fn in_flight(&self, id: &str) -> bool

Source

pub fn renew_now(&self, id: &str, force: bool) -> RenewOutcome

Wakes the slot’s task. Without force, a valid certificate outside its renewal window is left alone (NotDue) — Let’s Encrypt’s duplicate-cert limits are the classic footgun.

Source

pub async fn run(self: Arc<Self>)

Spawns the per-slot loops and returns.

Source

async fn client(&self) -> Result<Arc<dyn AcmeClient>, AcmeError>

Source

fn snapshot(&self, id: &CertId) -> Option<ManagedCert>

Source

fn observe(&self, id: &CertId)

Source

fn remint_placeholder_if_stale( &self, slot: &ManagedSlot, current: ManagedCert, ) -> ManagedCert

Mints a fresh self-signed placeholder when the current one is about to lapse. Placeholders are deliberately short-lived (one hour) so they are never mistaken for a real certificate; a slot whose issuance keeps failing would otherwise end up serving an expired self-signed cert, which fails the TLS handshake outright instead of merely failing verification. The state stays Placeholder – that is what /readyz keys on – and the recorded attempt/error history is carried over.

Source

async fn run_slot(self: Arc<Self>, slot: ManagedSlot)

Source

async fn attempt(&self, slot: &ManagedSlot) -> Result<bool, AcmeError>

One issuance under the lease. Ok(false) = a peer holds the lease.

Source

async fn follow_peer(&self, slot: &ManagedSlot, ctl: &SlotControl) -> bool

Non-leaseholder path: refresh challenge certs from storage every challenge_refresh and look for the peer’s certificate every peer_poll, for at most one lease TTL (then the outer loop re-evaluates). Returns whether a peer’s certificate was adopted, so the caller can reset any failure/backoff state that no longer applies to it.

Source

async fn adopt_from_storage( &self, slot: &ManagedSlot, ) -> Result<bool, AcmeError>

Publishes the stored certificate when it is newer than what we serve.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
§

impl<'a, T, E> AsTaggedExplicit<'a, E> for T
where T: 'a,

§

fn explicit(self, class: Class, tag: u32) -> TaggedParser<'a, Explicit, Self, E>

§

impl<'a, T, E> AsTaggedImplicit<'a, E> for T
where T: 'a,

§

fn implicit( self, class: Class, constructed: bool, tag: u32, ) -> TaggedParser<'a, Implicit, Self, E>

Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

§

impl<T> Instrument for T

§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided [Span], returning an Instrumented wrapper. Read more
§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
§

impl<T> MaybeSend for T

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

§

fn vzip(self) -> V

§

impl<T> WithSubscriber for T

§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a [WithDispatch] wrapper. Read more