Documentation
¶
Overview ¶
Package policystore publishes immutable filesystem-owned policy generations. Its APIs are for trusted owner administration; they are not HTTP permissions.
Index ¶
- Variables
- type Controller
- func (c *Controller) AcquirePolicyLease(ctx context.Context) (access.PolicyLease, error)
- func (c *Controller) Activate(ctx context.Context, expected string, documents []access.DTQLDocument) (Snapshot, error)
- func (c *Controller) Policies(ctx context.Context) ([]access.Policy, error)
- func (c *Controller) Reload(ctx context.Context) (Snapshot, error)
- func (c *Controller) Snapshot() (Snapshot, error)
- type Document
- type Owner
- type Snapshot
- type Store
Constants ¶
This section is empty.
Variables ¶
var ErrConflict = errors.New("policy generation revision conflict")
Functions ¶
This section is empty.
Types ¶
type Controller ¶
type Controller struct {
// contains filtered or unexported fields
}
Controller owns one admitted, immutable in-process policy snapshot. Publish and reload are trusted owner operations, not data-policy administration grants.
func NewController ¶
func NewController(ctx context.Context, store *Store) (*Controller, error)
func (*Controller) AcquirePolicyLease ¶
func (c *Controller) AcquirePolicyLease(ctx context.Context) (access.PolicyLease, error)
AcquirePolicyLease is called only after the adapter storage admission lock. Publication waits for this lease through the actual commit/abort boundary.
func (*Controller) Activate ¶
func (c *Controller) Activate(ctx context.Context, expected string, documents []access.DTQLDocument) (Snapshot, error)
func (*Controller) Snapshot ¶
func (c *Controller) Snapshot() (Snapshot, error)
type Snapshot ¶
type Store ¶
type Store struct {
// contains filtered or unexported fields
}
func Open ¶
Open opens an owner store without activating a generation. The caller must Load before serving an enabled owner. An absent pointer is never disabled ACL.
func (*Store) Activate ¶
func (s *Store) Activate(ctx context.Context, expected string, documents []access.DTQLDocument) (Snapshot, error)
Activate publishes one complete set using whole-owner CAS. expected is empty only for first activation. Per-document administration can merge under this same owner lock in a future management API; public ETags are document hashes.