Public release release-98d969b26488
Source commit: 98d969b26488b4cda8b2381fa870276a00ca98ea Public tree identity: sha256:d02dd1e8d3547a489bb300741bed544bdc60bb8fe0bd541fd43ce9bfa7129a3e
This commit is contained in:
commit
8ded2b6a42
210 changed files with 76954 additions and 0 deletions
139
crates/clusterflux-coordinator/src/service/authenticated.rs
Normal file
139
crates/clusterflux-coordinator/src/service/authenticated.rs
Normal file
|
|
@ -0,0 +1,139 @@
|
|||
use clusterflux_core::{AuthContext, UserId};
|
||||
|
||||
use super::{
|
||||
AuthenticatedCoordinatorRequest, CoordinatorRequest, CoordinatorResponse, CoordinatorService,
|
||||
CoordinatorServiceError,
|
||||
};
|
||||
|
||||
impl CoordinatorService {
|
||||
pub(super) fn handle_authenticated_agent_key_request(
|
||||
&mut self,
|
||||
context: &AuthContext,
|
||||
actor: &UserId,
|
||||
request: AuthenticatedCoordinatorRequest,
|
||||
) -> Result<CoordinatorResponse, CoordinatorServiceError> {
|
||||
let request = match request {
|
||||
AuthenticatedCoordinatorRequest::RegisterAgentPublicKey { agent, public_key } => {
|
||||
CoordinatorRequest::RegisterAgentPublicKey {
|
||||
tenant: context.tenant.as_str().to_owned(),
|
||||
project: context.project.as_str().to_owned(),
|
||||
user: actor.as_str().to_owned(),
|
||||
agent,
|
||||
public_key,
|
||||
}
|
||||
}
|
||||
AuthenticatedCoordinatorRequest::ListAgentPublicKeys => {
|
||||
CoordinatorRequest::ListAgentPublicKeys {
|
||||
tenant: context.tenant.as_str().to_owned(),
|
||||
project: context.project.as_str().to_owned(),
|
||||
user: actor.as_str().to_owned(),
|
||||
}
|
||||
}
|
||||
AuthenticatedCoordinatorRequest::RotateAgentPublicKey { agent, public_key } => {
|
||||
CoordinatorRequest::RotateAgentPublicKey {
|
||||
tenant: context.tenant.as_str().to_owned(),
|
||||
project: context.project.as_str().to_owned(),
|
||||
user: actor.as_str().to_owned(),
|
||||
agent,
|
||||
public_key,
|
||||
}
|
||||
}
|
||||
AuthenticatedCoordinatorRequest::RevokeAgentPublicKey { agent } => {
|
||||
CoordinatorRequest::RevokeAgentPublicKey {
|
||||
tenant: context.tenant.as_str().to_owned(),
|
||||
project: context.project.as_str().to_owned(),
|
||||
user: actor.as_str().to_owned(),
|
||||
agent,
|
||||
}
|
||||
}
|
||||
_ => unreachable!("caller filters authenticated agent key operations"),
|
||||
};
|
||||
self.handle_request(request)
|
||||
}
|
||||
|
||||
pub(super) fn handle_authenticated_launch_task(
|
||||
&mut self,
|
||||
context: &AuthContext,
|
||||
actor: &UserId,
|
||||
request: AuthenticatedCoordinatorRequest,
|
||||
) -> Result<CoordinatorResponse, CoordinatorServiceError> {
|
||||
let AuthenticatedCoordinatorRequest::LaunchTask {
|
||||
task_spec,
|
||||
wait_for_node,
|
||||
artifact_path,
|
||||
wasm_module_base64,
|
||||
} = request
|
||||
else {
|
||||
unreachable!("caller filters authenticated task launches");
|
||||
};
|
||||
self.handle_launch_task(
|
||||
context.tenant.as_str().to_owned(),
|
||||
context.project.as_str().to_owned(),
|
||||
Some(actor.as_str().to_owned()),
|
||||
None,
|
||||
None,
|
||||
None,
|
||||
None,
|
||||
*task_spec,
|
||||
wait_for_node,
|
||||
artifact_path,
|
||||
wasm_module_base64,
|
||||
)
|
||||
}
|
||||
|
||||
pub(super) fn handle_authenticated_schedule_task(
|
||||
&mut self,
|
||||
context: &AuthContext,
|
||||
request: AuthenticatedCoordinatorRequest,
|
||||
) -> Result<CoordinatorResponse, CoordinatorServiceError> {
|
||||
let AuthenticatedCoordinatorRequest::ScheduleTask {
|
||||
environment,
|
||||
environment_digest,
|
||||
required_capabilities,
|
||||
dependency_cache,
|
||||
source_snapshot,
|
||||
required_artifacts,
|
||||
prefer_node,
|
||||
} = request
|
||||
else {
|
||||
unreachable!("caller filters authenticated task scheduling");
|
||||
};
|
||||
self.handle_schedule_task(
|
||||
context.tenant.as_str().to_owned(),
|
||||
context.project.as_str().to_owned(),
|
||||
environment,
|
||||
environment_digest,
|
||||
required_capabilities,
|
||||
dependency_cache,
|
||||
source_snapshot,
|
||||
required_artifacts,
|
||||
prefer_node,
|
||||
)
|
||||
}
|
||||
|
||||
pub(super) fn handle_authenticated_artifact_export(
|
||||
&mut self,
|
||||
context: &AuthContext,
|
||||
actor: &UserId,
|
||||
request: AuthenticatedCoordinatorRequest,
|
||||
) -> Result<CoordinatorResponse, CoordinatorServiceError> {
|
||||
let AuthenticatedCoordinatorRequest::ExportArtifactToNode {
|
||||
artifact,
|
||||
receiver_node,
|
||||
direct_connectivity,
|
||||
failure_reason,
|
||||
} = request
|
||||
else {
|
||||
unreachable!("caller filters authenticated artifact exports");
|
||||
};
|
||||
self.handle_export_artifact_to_node(
|
||||
context.tenant.as_str().to_owned(),
|
||||
context.project.as_str().to_owned(),
|
||||
actor.as_str().to_owned(),
|
||||
artifact,
|
||||
receiver_node,
|
||||
direct_connectivity,
|
||||
failure_reason,
|
||||
)
|
||||
}
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue