pub struct UpstreamPlugin {
balancer: Balancer,
client: Arc<OutboundClient>,
timeout: Duration,
tls: bool,
ssl_verify: bool,
tls_identity: Option<Arc<UpstreamTls>>,
}Expand description
Proxies the request to one of the configured backend targets and populates
Context.response with the upstream’s status, headers, and body.
Connection failures, request-build failures, and body-read failures are
returned as PluginExecutionErrors so the graph engine can route them
through this node’s error port.
Fields§
§balancer: BalancerBackend pool + load-balancing strategy (shared with the L4 stream proxy).
client: Arc<OutboundClient>Shared pooled HTTP client (from PluginResources).
timeout: DurationWhole-call deadline per proxied request.
tls: boolConnect to the upstream over TLS (https/wss); default false.
ssl_verify: boolVerify the upstream’s TLS certificate; default true. Only meaningful
when tls is set.
tls_identity: Option<Arc<UpstreamTls>>Per-upstream TLS identity (client cert / private CA); None = shared clients, exactly the pre-mTLS behavior.
Implementations§
Source§impl UpstreamPlugin
impl UpstreamPlugin
Sourcepub fn from_config(
config: &HashMap<String, Value>,
resources: &Arc<PluginResources>,
) -> Result<Self, String>
pub fn from_config( config: &HashMap<String, Value>, resources: &Arc<PluginResources>, ) -> Result<Self, String>
Builds the plugin from node config.
Accepted keys:
-
targets(array of{host: string, port: integer}, required): the backend pool. Entries missinghostorportare skipped; an empty resulting pool is a config error. -
load_balancing(string, defaultround_robin): one ofround_robin,least_connections, orip_hash. Hyphenated and short spellings (round-robin,least-conn) are accepted, as is the legacy key nameload_balancer(seeStrategy::parse). -
timeout_ms(integer, default60000): whole-call deadline (connect + request + response body) per proxied request; exceeding it fails the node withUPSTREAM_TIMEOUTthrough the error port. -
tls(bool, defaultfalse): connect to the upstream over TLS (httpsfor the buffered path,wssfor WebSocket). -
ssl_verify(bool, defaulttrue): verify the upstream’s TLS certificate. Only meaningful whentlsis set. -
client_cert_path/client_key_path(string, optional): PEM client certificate and private key presented to the upstream for mutual TLS. Must be set together, and only withtls: true. -
ca_cert_path(string, optional): PEM CA bundle used to verify the upstream’s certificate, replacing the native root store for this upstream. Requirestls: true; rejected together withssl_verify: false(a CA bundle to verify with is contradictory when verification is off).
Errors if no valid target is configured, if the load-balancing value
is not a string, if it names an unknown strategy, if any mTLS key is
set without tls: true, if client_cert_path/client_key_path are
not both set, if ca_cert_path is set with ssl_verify: false, or if
the configured cert/key/CA files can’t be read or parsed.
type: upstream
config:
targets:
- host: backend-1
port: 3000
- host: backend-2
port: 3000
load_balancing: least_connections
timeout_ms: 60000
tls: true
client_cert_path: /etc/gateway/client.crt
client_key_path: /etc/gateway/client.key
ca_cert_path: /etc/gateway/ca.crtTrait Implementations§
Source§impl Debug for UpstreamPlugin
impl Debug for UpstreamPlugin
Source§impl Plugin for UpstreamPlugin
impl Plugin for UpstreamPlugin
Source§fn plugin_type(&self) -> &str
fn plugin_type(&self) -> &str
Source§fn execute<'life0, 'life1, 'async_trait>(
&'life0 self,
ctx: Context,
_named_inputs: &'life1 HashMap<String, Value>,
) -> Pin<Box<dyn Future<Output = Result<PluginOutput, PluginExecutionError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
fn execute<'life0, 'life1, 'async_trait>(
&'life0 self,
ctx: Context,
_named_inputs: &'life1 HashMap<String, Value>,
) -> Pin<Box<dyn Future<Output = Result<PluginOutput, PluginExecutionError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
Auto Trait Implementations§
impl !Freeze for UpstreamPlugin
impl !RefUnwindSafe for UpstreamPlugin
impl Send for UpstreamPlugin
impl Sync for UpstreamPlugin
impl Unpin for UpstreamPlugin
impl UnsafeUnpin for UpstreamPlugin
impl !UnwindSafe for UpstreamPlugin
Blanket Implementations§
§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more