config

package
v1.64.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 6, 2026 License: MIT Imports: 16 Imported by: 0

Documentation

Index

Constants

View Source
const (
	DirEnvVar  = "CONFIG_DIR"
	PathEnvVar = "CONFIG_PATH"

	ConfigFileName = "config.yaml"
)
View Source
const (
	ServiceAuth       = "auth"
	ServiceDataAccess = "data-access"
)

Variables

This section is empty.

Functions

func LoadDBMigrationConfig added in v1.35.0

func LoadDBMigrationConfig() (platformConfig.DatabaseConfig, error)

LoadDBMigrationConfig loads the platform database config for migrations (driver + a DataSource resolved from the migration credentials), independent of any service. It is used by cmd/migrate, which connects as the migration role; running services load their DB config via Load[T] instead.

func SecretsPath added in v1.59.0

func SecretsPath(configPath, ref string) string

func SetIfAbsent added in v1.64.0

func SetIfAbsent[T any](field **T, value T)

SetIfAbsent fills an optional field the file left out.

func UsesYAMLConfig added in v1.59.0

func UsesYAMLConfig() bool

Types

type AuthSecrets added in v1.61.0

type AuthSecrets struct {
	SharedSecrets

	OAuthHMACSecret secret.Secret
	OAuthSigningKey secret.Secret
	OAuthProviders  map[string]OAuthClientCredentials
}

type CORSConfig

type CORSConfig struct {
	AllowedOrigins []string `mapstructure:"allowed_origins"`

	AllowedMethods []string `mapstructure:"allowed_methods"`

	AllowedHeaders []string `mapstructure:"allowed_headers"`

	MaxAge int `mapstructure:"max_age" default:"300"`

	AllowCredentials bool `mapstructure:"allow_credentials" default:"false"`
}

func (*CORSConfig) Validate

func (c *CORSConfig) Validate() error

type DataAccessSecrets added in v1.61.0

type DataAccessSecrets struct {
	SharedSecrets
}

type DatabaseSecrets added in v1.61.0

type DatabaseSecrets struct {
	Username          string
	Password          secret.Secret
	MigrationUsername string
	MigrationPassword secret.Secret
}

type GRPCConfig added in v1.10.0

type GRPCConfig struct {
	// EnableReflection registers the gRPC server reflection service, which lets
	// clients (grpcurl, grpcui) enumerate services, methods, and message
	// schemas at runtime. Reflection is exposed as a stream RPC and is NOT
	// covered by the unary service-token interceptors, so it is unauthenticated
	// wherever it is on. Keep it off in production (the zero value): it leaks the
	// full API surface of the auth services to anyone who can reach the port.
	// Enabled in development/CI/staging config for debugging.
	EnableReflection bool `mapstructure:"enable_reflection" default:"false"`
}

GRPCConfig holds platform-wide gRPC server settings shared by all services.

type GRPCService

type GRPCService interface {
	GRPCAddr() string
}

type HTTPDefaults

type HTTPDefaults struct {
	ReadTimeout  time.Duration `mapstructure:"read_timeout" default:"30s"`
	WriteTimeout time.Duration `mapstructure:"write_timeout" default:"30s"`
	IdleTimeout  time.Duration `mapstructure:"idle_timeout" default:"60s"`
}

type HTTPService

type HTTPService interface {
	HTTPAddr() string
}

type Loaded added in v1.61.0

type Loaded[T ServiceRoot, S ServiceSecrets] struct {
	Config  T
	Secrets S
}

Loaded is a service's config file and its secrets file, parsed and validated, with the platform defaults applied. Each service package applies its own defaults when it maps the file.

func LoadAuth added in v1.61.0

func LoadAuth() (*Loaded[*configpb.AuthConfig, *AuthSecrets], error)

func LoadAuthFile added in v1.61.0

func LoadAuthFile(path string) (*Loaded[*configpb.AuthConfig, *AuthSecrets], error)

func LoadDataAccess added in v1.61.0

func LoadDataAccess() (*Loaded[*configpb.DataAccessConfig, *DataAccessSecrets], error)

func LoadDataAccessFile added in v1.61.0

func LoadDataAccessFile(path string) (*Loaded[*configpb.DataAccessConfig, *DataAccessSecrets], error)

type MetricsService added in v1.54.0

type MetricsService interface {
	MetricsAddr() string
}

MetricsService is optional, unlike GRPCService/HTTPService: a service that implements it gets a metrics/probe HTTP server attached automatically by pkg/boot.Boot, with no per-service decision to make.

type OAuthClientCredentials added in v1.61.0

type OAuthClientCredentials struct {
	ClientID     string
	ClientSecret secret.Secret
}

type RuntimeConfig

type RuntimeConfig[T ServiceConfig] struct {
	Platform config
	Service  T
}

func Load

func Load[T ServiceConfig](serviceName string) (*RuntimeConfig[T], error)

func (*RuntimeConfig[T]) GRPCReflectionEnabled added in v1.10.0

func (r *RuntimeConfig[T]) GRPCReflectionEnabled() bool

GRPCReflectionEnabled reports whether gRPC server reflection should be registered. It defaults to false (production-safe) and is opted into by the development/CI/staging environment config. See GRPCConfig.EnableReflection.

func (*RuntimeConfig[T]) GetDatabaseConfig

func (r *RuntimeConfig[T]) GetDatabaseConfig() platformConfig.DatabaseConfig

func (*RuntimeConfig[T]) Validate

func (r *RuntimeConfig[T]) Validate() error

type ServiceConfig

type ServiceConfig interface {
	Validate() error
}

ServiceConfig interface all service configs must implement

type ServiceRoot added in v1.61.0

type ServiceRoot interface {
	proto.Message
	GetPlatform() *configpb.Platform
	GetSecretsFile() string
}

ServiceRoot is a service's config root message: AuthConfig or DataAccessConfig.

type ServiceSecrets added in v1.61.0

type ServiceSecrets interface {
	*AuthSecrets | *DataAccessSecrets
}

ServiceSecrets is a service's secrets file, AuthSecrets or DataAccessSecrets, held as secret.Secret values, which print and marshal as [REDACTED]. The generated message prints every field, so it never leaves this package.

type SharedSecrets added in v1.61.0

type SharedSecrets struct {
	Database         DatabaseSecrets
	ServiceToken     secret.Secret
	NextServiceToken secret.Secret
}

type Source added in v1.59.0

type Source int
const (
	SourceNone Source = iota
	SourceDir
	SourcePath
	SourceLocal
)

func ResolveConfigPath added in v1.59.0

func ResolveConfigPath(service string) (string, Source, error)

Only the committed profile is checked for existence, so a wrong CONFIG_DIR or CONFIG_PATH fails at load time naming that path.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL