Skip to main content

EgressPolicy

Struct EgressPolicy 

pub struct EgressPolicy { /* private fields */ }
Expand description

One materialized view of canonical operator egress policy.

Construct this inside an EgressPolicyResolver call. Long-lived stores retain the resolver, not this view, so an operator’s edit applies to the next dial rather than to the next restart.

The two host lists are exactly the operator’s plugins.entries[].egress_hosts and egress_allow_private. There is no second config surface: a destination is reachable because the operator granted it, and no manifest, permission, or default adds to that.

Implementations§

Source§

impl EgressPolicy

Source

pub fn new( hosts: &[String], allow_private: &[String], nat64_prefixes: &[String], max_connections_per_instance: usize, ) -> Result<Self, EgressError>

Build and validate one resolved policy view.

hosts and allow_private use the strict egress grammar (zeroclaw_infra::net_guard::normalize_egress_pattern): exact hosts or *.suffix patterns, with no allow-all form. An empty hosts list is the default and means no reach at all.

nat64_prefixes is the deployment’s security.nat64_prefixes, parsed here so a malformed list fails the policy closed rather than silently disabling network-specific classification. This mirrors how the built-in tools parse the same list at construction.

§Errors

Returns EgressError for an invalid host pattern, a private carveout that is broader than every host grant, an invalid NAT64 prefix, or a zero connection ceiling.

Source

pub fn deny_all( max_connections_per_instance: usize, ) -> Result<Self, EgressError>

A policy that grants nothing. The state an unconfigured instance is in.

§Errors

Returns EgressError::InvalidConnectionLimit for a zero ceiling.

Trait Implementations§

Source§

impl Clone for EgressPolicy

Source§

fn clone(&self) -> EgressPolicy

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · §

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for EgressPolicy

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

§

impl<T> Instrument for T

§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided [Span], returning an Instrumented wrapper. Read more
§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
§

impl<T> WithSubscriber for T

§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a [WithDispatch] wrapper. Read more