mirror of
https://github.com/rustfs/rustfs.git
synced 2026-08-05 21:07:43 +00:00
d74e6eb042
* refactor(targets): move notify net helpers from utils * refactor(tls): centralize runtime foundation * refactor(targets): move notify net helpers from utils * refactor(tls): centralize runtime foundation * feat(tls-runtime): add TLS debug state and admin handler * refactor(tls-runtime): unify TLS debug consumer status view * fix(tls): address PR3065 review feedback * refactor(tls): align debug status payload types * refactor(targets): harden TLS hot reload paths * fix(targets): resolve review-4348251652 findings * fix(targets): finalize tls runtime review follow-ups * fix(targets): harden tls reload and review follow-ups * fix(targets): align tls reload handling across targets * fix(targets): finalize tls reload state and metrics updates * chore(deps): trim unused TLS deps * style(targets): normalize TLS reload formatting * refactor(targets): introduce tls runtime adapter path * chore: update workspace manifests for tls refactor * fix(tls): stabilize material reload and audit workflow * fix(targets): refresh tls fingerprint flow across sinks * fix(tls): align runtime coordinator and http reader updates * fix(sftp): simplify protocol error mapping * fix(tls): harmonize material loading behavior * fix(server): finalize tls material wiring in startup flow * fix(protos): tighten tls generation cache and deps
68 lines
2.6 KiB
Rust
68 lines
2.6 KiB
Rust
// Copyright 2024 RustFS Team
|
|
//
|
|
// Licensed under the Apache License, Version 2.0 (the "License");
|
|
// you may not use this file except in compliance with the License.
|
|
// You may obtain a copy of the License at
|
|
//
|
|
// http://www.apache.org/licenses/LICENSE-2.0
|
|
//
|
|
// Unless required by applicable law or agreed to in writing, software
|
|
// distributed under the License is distributed on an "AS IS" BASIS,
|
|
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
// See the License for the specific language governing permissions and
|
|
// limitations under the License.
|
|
|
|
use crate::material::OutboundTlsMaterial;
|
|
use crate::metrics::record_outbound_tls_publication;
|
|
use crate::state::TlsGeneration;
|
|
use rustfs_common::{
|
|
GLOBAL_MTLS_IDENTITY, GLOBAL_ROOT_CERT, MtlsIdentityPem, get_global_outbound_tls_generation, set_global_mtls_identity,
|
|
set_global_outbound_tls_generation, set_global_root_cert,
|
|
};
|
|
|
|
#[derive(Debug, Clone)]
|
|
pub struct GlobalPublishedOutboundTlsState {
|
|
pub generation: TlsGeneration,
|
|
pub root_ca_pem: Option<Vec<u8>>,
|
|
pub mtls_identity: Option<MtlsIdentityPem>,
|
|
}
|
|
|
|
#[derive(Debug, Clone, Copy, PartialEq, Eq)]
|
|
pub struct GlobalOutboundTlsStateSummary {
|
|
pub generation: TlsGeneration,
|
|
pub has_root_ca: bool,
|
|
pub has_mtls_identity: bool,
|
|
}
|
|
|
|
pub async fn publish_global_outbound_tls_state(generation: TlsGeneration, material: &OutboundTlsMaterial) {
|
|
if !material.root_ca_pem.is_empty() {
|
|
set_global_root_cert(material.root_ca_pem.clone()).await;
|
|
} else {
|
|
*GLOBAL_ROOT_CERT.write().await = None;
|
|
}
|
|
set_global_mtls_identity(material.mtls_identity.clone()).await;
|
|
set_global_outbound_tls_generation(generation.0);
|
|
record_outbound_tls_publication(generation.0, !material.root_ca_pem.is_empty(), material.mtls_identity.is_some());
|
|
}
|
|
|
|
pub async fn load_global_outbound_tls_state() -> GlobalPublishedOutboundTlsState {
|
|
GlobalPublishedOutboundTlsState {
|
|
generation: TlsGeneration(get_global_outbound_tls_generation()),
|
|
root_ca_pem: GLOBAL_ROOT_CERT.read().await.clone(),
|
|
mtls_identity: GLOBAL_MTLS_IDENTITY.read().await.clone(),
|
|
}
|
|
}
|
|
|
|
pub fn load_global_outbound_tls_generation() -> TlsGeneration {
|
|
TlsGeneration(get_global_outbound_tls_generation())
|
|
}
|
|
|
|
pub async fn summarize_global_outbound_tls_state() -> GlobalOutboundTlsStateSummary {
|
|
let state = load_global_outbound_tls_state().await;
|
|
GlobalOutboundTlsStateSummary {
|
|
generation: state.generation,
|
|
has_root_ca: state.root_ca_pem.as_ref().is_some_and(|pem| !pem.is_empty()),
|
|
has_mtls_identity: state.mtls_identity.is_some(),
|
|
}
|
|
}
|