config

package
v1.68.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 7, 2026 License: MIT Imports: 18 Imported by: 0

Documentation

Index

Constants

View Source
const (
	DirEnvVar  = "CONFIG_DIR"
	PathEnvVar = "CONFIG_PATH"

	ConfigFileName = "config.yaml"
)
View Source
const (
	ServiceAuth       = "auth"
	ServiceDataAccess = "data-access"
)

Variables

This section is empty.

Functions

func LoadDBMigrationConfig added in v1.35.0

func LoadDBMigrationConfig() (platformConfig.DatabaseConfig, error)

LoadDBMigrationConfig loads the platform database config for migrations (driver + a DataSource resolved from the migration credentials), independent of any service. It is used by cmd/migrate, which connects as the migration role; running services load their DB config via Load[T] instead.

func SecretsPath added in v1.59.0

func SecretsPath(configPath, ref string) string

func SetIfAbsent added in v1.64.0

func SetIfAbsent[T any](field **T, value T)

SetIfAbsent fills an optional field the file left out.

func UsesYAMLConfig added in v1.59.0

func UsesYAMLConfig() bool

Types

type AuthSecrets added in v1.61.0

type AuthSecrets struct {
	SharedSecrets

	OAuthHMACSecret secret.Secret
	OAuthSigningKey secret.Secret
	OAuthProviders  map[string]OAuthClientCredentials
}

type BootConfig added in v1.66.0

type BootConfig interface {
	ServiceConfig
	MetricsService
}

BootConfig is the constraint pkg/boot.Boot places on a service's config.

type CORSConfig

type CORSConfig struct {
	AllowedOrigins []string `mapstructure:"allowed_origins"`

	AllowedMethods []string `mapstructure:"allowed_methods"`

	AllowedHeaders []string `mapstructure:"allowed_headers"`

	MaxAge int `mapstructure:"max_age" default:"300"`

	AllowCredentials bool `mapstructure:"allow_credentials" default:"false"`
}

func (*CORSConfig) Validate

func (c *CORSConfig) Validate() error

type DataAccessSecrets added in v1.61.0

type DataAccessSecrets struct {
	SharedSecrets
}

type DatabaseSecrets added in v1.61.0

type DatabaseSecrets struct {
	Username          string
	Password          secret.Secret
	MigrationUsername string
	MigrationPassword secret.Secret
}

type GRPCConfig added in v1.10.0

type GRPCConfig struct {
	// EnableReflection registers the gRPC server reflection service, which lets
	// clients (grpcurl, grpcui) enumerate services, methods, and message
	// schemas at runtime. Reflection is exposed as a stream RPC and is NOT
	// covered by the unary service-token interceptors, so it is unauthenticated
	// wherever it is on. Keep it off in production (the zero value): it leaks the
	// full API surface of the auth services to anyone who can reach the port.
	// Enabled in development/CI/staging config for debugging.
	EnableReflection bool `mapstructure:"enable_reflection" default:"false"`
}

GRPCConfig holds platform-wide gRPC server settings shared by all services.

type GRPCService

type GRPCService interface {
	GRPCAddr() string
}

type HTTPDefaults

type HTTPDefaults struct {
	ReadTimeout  time.Duration `mapstructure:"read_timeout" default:"30s"`
	WriteTimeout time.Duration `mapstructure:"write_timeout" default:"30s"`
	IdleTimeout  time.Duration `mapstructure:"idle_timeout" default:"60s"`
}

type HTTPService

type HTTPService interface {
	HTTPAddr() string
}

type ListenConfig added in v1.66.0

type ListenConfig struct {
	// GRPCAddress serves every gRPC service, grpc.health.v1 and reflection.
	GRPCAddress string `mapstructure:"grpc_address"`
	// HTTPAddress serves every HTTP route.
	HTTPAddress string `mapstructure:"http_address"`
	// MetricsAddress serves labkit's /-/metrics, /-/liveness and /-/readiness.
	MetricsAddress string `mapstructure:"metrics_address"`
}

ListenConfig is the set of addresses one process listens on: at most one gRPC, one HTTP and one metrics listener, whatever it hosts. It is the value `[services.iam]` unmarshals into (see cmd/iam) and the shape every standalone service's own `*_address` keys reduce to.

func (ListenConfig) GRPCAddr added in v1.66.0

func (l ListenConfig) GRPCAddr() string

GRPCAddr, HTTPAddr and MetricsAddr make ListenConfig a GRPCService, HTTPService and MetricsService, so a config that embeds it is addressed the same way pkg/boot addresses every other service config.

func (ListenConfig) HTTPAddr added in v1.66.0

func (l ListenConfig) HTTPAddr() string

func (ListenConfig) MetricsAddr added in v1.66.0

func (l ListenConfig) MetricsAddr() string

func (ListenConfig) ValidateComplete added in v1.66.0

func (l ListenConfig) ValidateComplete() error

ValidateComplete checks a process that serves every transport: each of the three addresses must be set and well-formed.

type Loaded added in v1.61.0

type Loaded[T ServiceRoot, S ServiceSecrets] struct {
	Config  T
	Secrets S
}

Loaded is a service's config file and its secrets file, parsed and validated, with the platform defaults applied. Each service package applies its own defaults when it maps the file.

func LoadAuth added in v1.61.0

func LoadAuth() (*Loaded[*configpb.AuthConfig, *AuthSecrets], error)

func LoadAuthFile added in v1.61.0

func LoadAuthFile(path string) (*Loaded[*configpb.AuthConfig, *AuthSecrets], error)

func LoadDataAccess added in v1.61.0

func LoadDataAccess() (*Loaded[*configpb.DataAccessConfig, *DataAccessSecrets], error)

func LoadDataAccessFile added in v1.61.0

func LoadDataAccessFile(path string) (*Loaded[*configpb.DataAccessConfig, *DataAccessSecrets], error)

type MetricsService added in v1.54.0

type MetricsService interface {
	MetricsAddr() string
}

MetricsService is required of every service pkg/boot.Boot runs: Boot attaches the metrics HTTP server. An empty address skips it.

type OAuthClientCredentials added in v1.61.0

type OAuthClientCredentials struct {
	ClientID     string
	ClientSecret secret.Secret
}

type PlatformConfig added in v1.66.0

type PlatformConfig struct {
	Database platformConfig.DatabaseConfig `mapstructure:"database"`
	CORS     CORSConfig                    `mapstructure:"cors"`
	HTTP     HTTPDefaults                  `mapstructure:"http"`
	GRPC     GRPCConfig                    `mapstructure:"grpc"`
}

PlatformConfig is the `[platform]` table: settings every service in a process shares, as opposed to the per-service `[services.<name>]` tables.

type RuntimeConfig

type RuntimeConfig[T ServiceConfig] struct {
	Platform PlatformConfig
	Service  T
}

func Load

func Load[T ServiceConfig](serviceName string) (*RuntimeConfig[T], error)

func (*RuntimeConfig[T]) GRPCReflectionEnabled added in v1.10.0

func (r *RuntimeConfig[T]) GRPCReflectionEnabled() bool

GRPCReflectionEnabled reports whether gRPC server reflection should be registered. It defaults to false (production-safe) and is opted into by the development/CI/staging environment config. See GRPCConfig.EnableReflection.

func (*RuntimeConfig[T]) GetDatabaseConfig

func (r *RuntimeConfig[T]) GetDatabaseConfig() platformConfig.DatabaseConfig

func (*RuntimeConfig[T]) Validate

func (r *RuntimeConfig[T]) Validate() error

type ServiceConfig

type ServiceConfig interface {
	Validate() error
}

ServiceConfig interface all service configs must implement

type ServiceRoot added in v1.61.0

type ServiceRoot interface {
	proto.Message
	GetPlatform() *configpb.Platform
	GetSecretsFile() string
}

ServiceRoot is a service's config root message: AuthConfig or DataAccessConfig.

type ServiceSecrets added in v1.61.0

type ServiceSecrets interface {
	*AuthSecrets | *DataAccessSecrets
	Shared() *SharedSecrets
}

ServiceSecrets is a service's secrets file, AuthSecrets or DataAccessSecrets, held as secret.Secret values, which print and marshal as [REDACTED]. The generated message prints every field, so it never leaves this package.

type SharedSecrets added in v1.61.0

type SharedSecrets struct {
	Database         DatabaseSecrets
	ServiceToken     secret.Secret
	NextServiceToken secret.Secret
}

func (*SharedSecrets) Shared added in v1.68.0

func (s *SharedSecrets) Shared() *SharedSecrets

Shared lets code that serves both services, such as pkg/config/bind, read these without knowing which service's secrets it holds.

type Source added in v1.59.0

type Source int
const (
	SourceNone Source = iota
	SourceDir
	SourcePath
	SourceLocal
)

func ResolveConfigPath added in v1.59.0

func ResolveConfigPath(service string) (string, Source, error)

Only the committed profile is checked for existence, so a wrong CONFIG_DIR or CONFIG_PATH fails at load time naming that path.

Directories

Path Synopsis
Package bind maps a config loaded from YAML onto RuntimeConfig.
Package bind maps a config loaded from YAML onto RuntimeConfig.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL