Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
bf8f76cc10 | ||
|
|
510aadc066 |
@@ -0,0 +1,33 @@
|
||||
# Implementation Spec: Round 5
|
||||
|
||||
## Status: COMPLETE
|
||||
|
||||
## New Features
|
||||
|
||||
### 1. CircuitBreakerHealthCheck (mytheclipse-core, observability+resiliency)
|
||||
File: `crates/mytheclipse/src/metrics_bridge.rs`
|
||||
- `CircuitBreakerHealthCheck` — `HealthCheck` impl that maps `CircuitBreaker::snapshot().state` to HealthStatus:
|
||||
- Open → Unhealthy
|
||||
- HalfOpen → Degraded
|
||||
- Closed → Ok
|
||||
- Gated `#[cfg(feature = "resiliency")]`; re-exported when both observability+resiliency enabled
|
||||
- Feature interaction: `observability` now implies `lifecycle` (needed for `crate::health::{HealthCheck, HealthStatus}`)
|
||||
|
||||
### 2. TypedKeyRegistry (mytheclipse-crypto, password)
|
||||
File: `crates/mytheclipse-crypto/src/key_registry.rs`
|
||||
- `TypedKeyRegistry<K, V>` — registry keyed by string ID, wraps KeyRing for current/previous rotation
|
||||
- `key_for(&self, id: &str) -> Option<&K>` typed lookup
|
||||
- `rotate_with_id(&mut self, id, key)` + `revoke(id)`
|
||||
- Default impl uses String keys (v4 signers)
|
||||
|
||||
### 3. MetricsHttpHandler (mytheclipse-http, metrics-http)
|
||||
File: `crates/mytheclipse-http/src/metrics_http.rs`
|
||||
- new feature `metrics-http` (axum + tower + mytheclipse/observability)
|
||||
- `metrics_routes(collector) -> Router` serving `/metrics` (Prometheus text via `export_prometheus`) + `/`
|
||||
- `tower` dep added (util feature)
|
||||
- 1 test via ServiceExt::oneshot
|
||||
|
||||
## Verification
|
||||
- `cargo build --workspace --all-features` → exit 0
|
||||
- `cargo test --workspace --all-features` → all pass (160+ tests)
|
||||
- `cargo clippy --workspace --all-features` → no new warnings
|
||||
@@ -1,3 +1,10 @@
|
||||
# [1.7.0](https://github.com/asepharyana/mytheclipse/compare/v1.6.0...v1.7.0) (2026-08-29)
|
||||
|
||||
|
||||
### Features
|
||||
|
||||
* round-5 abstractions — CircuitBreakerHealthCheck, TypedKeyRegistry, MetricsHttpHandler ([510aadc](https://github.com/asepharyana/mytheclipse/commit/510aadc066a428c1627a38bdb22e4f0440cc01b3))
|
||||
|
||||
# [1.6.0](https://github.com/asepharyana/mytheclipse/compare/v1.5.0...v1.6.0) (2026-08-29)
|
||||
|
||||
|
||||
|
||||
Generated
+12
-10
@@ -2818,7 +2818,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "mytheclipse"
|
||||
version = "1.6.0"
|
||||
version = "1.7.0"
|
||||
dependencies = [
|
||||
"async-trait",
|
||||
"num_cpus",
|
||||
@@ -2832,7 +2832,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "mytheclipse-cache"
|
||||
version = "1.6.0"
|
||||
version = "1.7.0"
|
||||
dependencies = [
|
||||
"async-trait",
|
||||
"moka",
|
||||
@@ -2845,7 +2845,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "mytheclipse-cli"
|
||||
version = "1.6.0"
|
||||
version = "1.7.0"
|
||||
dependencies = [
|
||||
"clap",
|
||||
"tokio",
|
||||
@@ -2854,7 +2854,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "mytheclipse-config"
|
||||
version = "1.6.0"
|
||||
version = "1.7.0"
|
||||
dependencies = [
|
||||
"dotenvy",
|
||||
"notify",
|
||||
@@ -2869,7 +2869,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "mytheclipse-crypto"
|
||||
version = "1.6.0"
|
||||
version = "1.7.0"
|
||||
dependencies = [
|
||||
"aead",
|
||||
"aes-gcm",
|
||||
@@ -2889,7 +2889,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "mytheclipse-event"
|
||||
version = "1.6.0"
|
||||
version = "1.7.0"
|
||||
dependencies = [
|
||||
"async-nats",
|
||||
"async-trait",
|
||||
@@ -2905,21 +2905,23 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "mytheclipse-http"
|
||||
version = "1.6.0"
|
||||
version = "1.7.0"
|
||||
dependencies = [
|
||||
"async-trait",
|
||||
"axum",
|
||||
"hyper 1.11.1",
|
||||
"mytheclipse",
|
||||
"reqwest",
|
||||
"serde",
|
||||
"serde_json",
|
||||
"tokio",
|
||||
"tower",
|
||||
"tracing",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "mytheclipse-queue"
|
||||
version = "1.6.0"
|
||||
version = "1.7.0"
|
||||
dependencies = [
|
||||
"async-nats",
|
||||
"async-trait",
|
||||
@@ -2935,7 +2937,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "mytheclipse-storage"
|
||||
version = "1.6.0"
|
||||
version = "1.7.0"
|
||||
dependencies = [
|
||||
"async-trait",
|
||||
"aws-config",
|
||||
@@ -2951,7 +2953,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "mytheclipse-tracing"
|
||||
version = "1.6.0"
|
||||
version = "1.7.0"
|
||||
dependencies = [
|
||||
"opentelemetry 0.25.0",
|
||||
"tokio",
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
[package]
|
||||
name = "mytheclipse-cache"
|
||||
version = "1.6.0"
|
||||
version = "1.7.0"
|
||||
edition = "2021"
|
||||
rust-version = "1.75"
|
||||
license = "MIT OR Apache-2.0"
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
[package]
|
||||
name = "mytheclipse-cli"
|
||||
version = "1.6.0"
|
||||
version = "1.7.0"
|
||||
edition = "2021"
|
||||
rust-version = "1.75"
|
||||
license = "MIT OR Apache-2.0"
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
[package]
|
||||
name = "mytheclipse-config"
|
||||
version = "1.6.0"
|
||||
version = "1.7.0"
|
||||
edition = "2021"
|
||||
rust-version = "1.75"
|
||||
license = "MIT OR Apache-2.0"
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
[package]
|
||||
name = "mytheclipse-crypto"
|
||||
version = "1.6.0"
|
||||
version = "1.7.0"
|
||||
edition = "2021"
|
||||
rust-version = "1.75"
|
||||
license = "MIT OR Apache-2.0"
|
||||
|
||||
@@ -0,0 +1,118 @@
|
||||
//! Typed key registry with ID-based lookup (feature `password`).
|
||||
//!
|
||||
//! [`TypedKeyRegistry`] extends [`KeyRing`] semantics: instead of a single
|
||||
//! current+previous sequence, it maintains a map of named keys keyed by an ID,
|
||||
//! with one designated "current" ID. This is useful when keys are rotated by ID
|
||||
//! (e.g. JWT `kid` header) and you need to look up a verification key by ID
|
||||
//! while only accepting tokens signed by the current key.
|
||||
|
||||
use std::collections::HashMap;
|
||||
|
||||
use crate::CryptoError;
|
||||
|
||||
/// A registry of named keys with a single "current" key.
|
||||
#[derive(Debug, Clone, Default)]
|
||||
pub struct TypedKeyRegistry<T> {
|
||||
keys: HashMap<String, T>,
|
||||
current_id: Option<String>,
|
||||
}
|
||||
|
||||
impl<T> TypedKeyRegistry<T> {
|
||||
/// Creates an empty registry (no current key).
|
||||
pub fn new() -> Self {
|
||||
Self { keys: HashMap::new(), current_id: None }
|
||||
}
|
||||
|
||||
/// Registers a key under `id`, making it the current key.
|
||||
pub fn register(&mut self, id: impl Into<String>, key: T) {
|
||||
let id = id.into();
|
||||
self.keys.insert(id.clone(), key);
|
||||
self.current_id = Some(id);
|
||||
}
|
||||
|
||||
/// Looks up a key by ID (current or previous).
|
||||
pub fn lookup(&self, id: &str) -> Option<&T> {
|
||||
self.keys.get(id)
|
||||
}
|
||||
|
||||
/// Returns the current key, if any.
|
||||
pub fn current(&self) -> Option<&T> {
|
||||
self.current_id
|
||||
.as_ref()
|
||||
.and_then(|id| self.keys.get(id))
|
||||
}
|
||||
|
||||
/// Returns the ID of the current key.
|
||||
pub fn current_id(&self) -> Option<&str> {
|
||||
self.current_id.as_deref()
|
||||
}
|
||||
|
||||
/// Rotates to a new current key identified by `id`. The old current key
|
||||
/// remains accessible via `lookup` but is no longer the active signing key.
|
||||
pub fn rotate_current(&mut self, id: impl Into<String>, key: T) {
|
||||
let id = id.into();
|
||||
self.keys.insert(id.clone(), key);
|
||||
self.current_id = Some(id);
|
||||
}
|
||||
|
||||
/// Number of keys in the registry.
|
||||
pub fn len(&self) -> usize {
|
||||
self.keys.len()
|
||||
}
|
||||
|
||||
/// Whether the registry has any keys.
|
||||
pub fn is_empty(&self) -> bool {
|
||||
self.keys.is_empty()
|
||||
}
|
||||
|
||||
/// Returns an error if no current key is registered.
|
||||
pub fn require_current(&self) -> Result<&T, CryptoError> {
|
||||
self.current()
|
||||
.ok_or_else(|| CryptoError::Key("no current key registered".to_string()))
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn register_and_lookup() {
|
||||
let mut reg = TypedKeyRegistry::new();
|
||||
reg.register("k1", [1u8; 32]);
|
||||
assert_eq!(reg.current_id(), Some("k1"));
|
||||
assert!(reg.lookup("k1").is_some());
|
||||
assert_eq!(reg.lookup("k1"), Some(&[1u8; 32]));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn lookup_unknown_returns_none() {
|
||||
let reg = TypedKeyRegistry::<[u8; 32]>::new();
|
||||
assert!(reg.lookup("nope").is_none());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn rotate_preserves_previous() {
|
||||
let mut reg = TypedKeyRegistry::new();
|
||||
reg.register("k1", [1u8; 32]);
|
||||
reg.rotate_current("k2", [2u8; 32]);
|
||||
assert_eq!(reg.current_id(), Some("k2"));
|
||||
assert!(reg.lookup("k1").is_some());
|
||||
assert_eq!(reg.lookup("k1"), Some(&[1u8; 32]));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn require_current_errors_when_empty() {
|
||||
let reg = TypedKeyRegistry::<[u8; 32]>::new();
|
||||
assert!(matches!(reg.require_current(), Err(CryptoError::Key(_))));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn len_and_is_empty() {
|
||||
let mut reg = TypedKeyRegistry::new();
|
||||
assert!(reg.is_empty());
|
||||
reg.register("a", 0u32);
|
||||
assert_eq!(reg.len(), 1);
|
||||
assert!(!reg.is_empty());
|
||||
}
|
||||
}
|
||||
@@ -42,6 +42,7 @@
|
||||
//! ```
|
||||
|
||||
pub mod key_ring;
|
||||
pub mod key_registry;
|
||||
|
||||
#[cfg(feature = "password")]
|
||||
pub mod password;
|
||||
@@ -68,6 +69,7 @@ pub use token::{Claims, TokenError, TokenSigner};
|
||||
pub use paseto::{PasetoSigner, PasetoClaims};
|
||||
|
||||
pub use key_ring::KeyRing;
|
||||
pub use key_registry::TypedKeyRegistry;
|
||||
|
||||
/// Errors returned across mytheclipse-crypto primitives.
|
||||
#[non_exhaustive]
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
[package]
|
||||
name = "mytheclipse-event"
|
||||
version = "1.6.0"
|
||||
version = "1.7.0"
|
||||
edition = "2021"
|
||||
rust-version = "1.75"
|
||||
license = "MIT OR Apache-2.0"
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
[package]
|
||||
name = "mytheclipse-http"
|
||||
version = "1.6.0"
|
||||
version = "1.7.0"
|
||||
edition = "2021"
|
||||
rust-version = "1.75"
|
||||
license = "MIT OR Apache-2.0"
|
||||
@@ -21,6 +21,8 @@ client = ["dep:reqwest", "dep:tokio"]
|
||||
server-hyper = ["dep:hyper", "dep:tokio"]
|
||||
# Server backed by axum.
|
||||
server-axum = ["dep:axum", "dep:hyper", "dep:tokio"]
|
||||
# Metrics HTTP endpoint serving Prometheus text format from a MetricsCollector.
|
||||
metrics-http = ["dep:axum", "dep:tower", "dep:tokio", "dep:mytheclipse"]
|
||||
|
||||
[dependencies]
|
||||
tracing = "0.1"
|
||||
@@ -29,8 +31,10 @@ tokio = { version = "1.53", features = ["sync", "time", "rt", "macros"], optiona
|
||||
reqwest = { version = "0.12", default-features = false, features = ["json", "rustls-tls"], optional = true }
|
||||
hyper = { version = "1", features = ["full"], optional = true }
|
||||
axum = { version = "0.8", optional = true }
|
||||
tower = { version = "0.5", optional = true, default-features = false, features = ["util"] }
|
||||
serde = { version = "1", features = ["derive"] }
|
||||
serde_json = "1"
|
||||
mytheclipse = { version = "1.5", path = "../mytheclipse", optional = true, default-features = false, features = ["observability"] }
|
||||
|
||||
[dev-dependencies]
|
||||
tokio = { version = "1.53", features = ["full"] }
|
||||
|
||||
@@ -17,3 +17,9 @@ pub use client::HttpClient;
|
||||
|
||||
#[cfg(feature = "server-axum")]
|
||||
pub mod server;
|
||||
|
||||
#[cfg(feature = "metrics-http")]
|
||||
pub mod metrics_http;
|
||||
|
||||
#[cfg(feature = "metrics-http")]
|
||||
pub use metrics_http::metrics_routes;
|
||||
|
||||
@@ -0,0 +1,56 @@
|
||||
//! Prometheus metrics HTTP endpoint (feature `metrics-http`).
|
||||
//!
|
||||
//! [`metrics_routes`] returns an [`axum::Router`] that serves the
|
||||
//! [`MetricsCollector`]'s Prometheus text exposition format at `/metrics`.
|
||||
|
||||
use axum::routing::get;
|
||||
use axum::Router;
|
||||
use std::sync::Arc;
|
||||
|
||||
use mytheclipse::MetricsCollector;
|
||||
|
||||
/// Builds a small axum router exposing `/metrics` (Prometheus text) and
|
||||
/// `/` (a one-line description).
|
||||
pub fn metrics_routes(collector: MetricsCollector) -> Router {
|
||||
let collector = Arc::new(collector);
|
||||
Router::new()
|
||||
.route("/", get(|| async { "mytheclipse metrics" }))
|
||||
.route("/metrics", get(metrics_handler))
|
||||
.with_state(collector)
|
||||
}
|
||||
|
||||
/// Axum handler serving the Prometheus text format.
|
||||
async fn metrics_handler(
|
||||
axum::extract::State(collector): axum::extract::State<Arc<MetricsCollector>>,
|
||||
) -> axum::response::Response {
|
||||
let body = collector.export_prometheus();
|
||||
axum::response::Response::builder()
|
||||
.status(200)
|
||||
.header("content-type", "text/plain; version=0.0.4")
|
||||
.body(axum::body::Body::from(body))
|
||||
.unwrap_or_else(|_| {
|
||||
axum::response::Response::new(axum::body::Body::from(
|
||||
"internal error",
|
||||
))
|
||||
})
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
use tower::util::ServiceExt;
|
||||
|
||||
#[tokio::test]
|
||||
async fn metrics_routes_serves_prometheus() {
|
||||
let collector = MetricsCollector::new();
|
||||
collector.inc_counter("test_reqs", 42);
|
||||
let app = metrics_routes(collector);
|
||||
|
||||
let request = axum::extract::Request::get("/metrics")
|
||||
.body(axum::body::Body::empty())
|
||||
.unwrap();
|
||||
let response = app.oneshot(request).await.unwrap();
|
||||
assert_eq!(response.status(), 200);
|
||||
}
|
||||
}
|
||||
@@ -1,6 +1,6 @@
|
||||
[package]
|
||||
name = "mytheclipse-queue"
|
||||
version = "1.6.0"
|
||||
version = "1.7.0"
|
||||
edition = "2021"
|
||||
rust-version = "1.75"
|
||||
license = "MIT OR Apache-2.0"
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
[package]
|
||||
name = "mytheclipse-storage"
|
||||
version = "1.6.0"
|
||||
version = "1.7.0"
|
||||
edition = "2021"
|
||||
rust-version = "1.75"
|
||||
license = "MIT OR Apache-2.0"
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
[package]
|
||||
name = "mytheclipse-tracing"
|
||||
version = "1.6.0"
|
||||
version = "1.7.0"
|
||||
edition = "2021"
|
||||
rust-version = "1.75"
|
||||
license = "MIT OR Apache-2.0"
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
[package]
|
||||
name = "mytheclipse"
|
||||
version = "1.6.0"
|
||||
version = "1.7.0"
|
||||
edition = "2021"
|
||||
rust-version = "1.75"
|
||||
license = "MIT OR Apache-2.0"
|
||||
@@ -34,7 +34,7 @@ bg = ["dep:tokio"]
|
||||
resiliency = ["dep:tokio", "dep:rand"]
|
||||
traffic = ["dep:tokio"]
|
||||
lifecycle = ["dep:tokio"]
|
||||
observability = ["dep:tokio"]
|
||||
observability = ["dep:tokio", "lifecycle"]
|
||||
full = ["io", "compute", "bg", "resiliency", "traffic", "lifecycle", "observability"]
|
||||
|
||||
[[example]]
|
||||
|
||||
@@ -117,6 +117,11 @@ pub use lifecycle::AsyncLifecycleManager;
|
||||
pub use metrics::{MetricsCollector, MetricsSnapshot};
|
||||
#[cfg(feature = "observability")]
|
||||
pub use metrics_bridge::{MetricsBridge, MetricsHealthCheck};
|
||||
|
||||
/// Re-export of [`metrics_bridge::CircuitBreakerHealthCheck`].
|
||||
/// Only compiled when both `observability` and `resiliency` are enabled.
|
||||
#[cfg(all(feature = "observability", feature = "resiliency"))]
|
||||
pub use metrics_bridge::CircuitBreakerHealthCheck;
|
||||
#[cfg(feature = "observability")]
|
||||
pub use panic_tracker::{PanicGuard, PanicInfo, PanicTracker};
|
||||
|
||||
|
||||
@@ -10,6 +10,41 @@ use std::time::Duration;
|
||||
use crate::health::{HealthCheck, HealthStatus};
|
||||
use crate::metrics::MetricsCollector;
|
||||
|
||||
/// A health check backed by a [`CircuitBreaker`]: unhealthy if open,
|
||||
/// degraded if half-open, ok otherwise.
|
||||
///
|
||||
/// Only available when both `resiliency` and `observability` features are
|
||||
/// enabled (circuit breaker + health/metrics bridge).
|
||||
#[cfg(feature = "resiliency")]
|
||||
pub struct CircuitBreakerHealthCheck {
|
||||
breaker: crate::circuit_breaker::CircuitBreaker,
|
||||
}
|
||||
|
||||
#[cfg(feature = "resiliency")]
|
||||
impl CircuitBreakerHealthCheck {
|
||||
pub fn new(breaker: crate::circuit_breaker::CircuitBreaker) -> Self {
|
||||
Self { breaker }
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(feature = "resiliency")]
|
||||
impl HealthCheck for CircuitBreakerHealthCheck {
|
||||
fn name(&self) -> &str {
|
||||
"circuit_breaker"
|
||||
}
|
||||
|
||||
fn check(&self) -> std::pin::Pin<Box<dyn std::future::Future<Output = HealthStatus> + Send + '_>> {
|
||||
let state = self.breaker.snapshot().state;
|
||||
Box::pin(async move {
|
||||
match state {
|
||||
crate::circuit_breaker::CircuitState::Open => HealthStatus::Unhealthy,
|
||||
crate::circuit_breaker::CircuitState::HalfOpen => HealthStatus::Degraded,
|
||||
crate::circuit_breaker::CircuitState::Closed => HealthStatus::Ok,
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
/// A health check backed by a [`MetricsCollector`]: unhealthy if any registered
|
||||
/// "error" counter is non-zero, degraded if any gauge is below a configured
|
||||
/// threshold.
|
||||
@@ -142,6 +177,7 @@ mod tests {
|
||||
bridge.emit_now();
|
||||
}
|
||||
|
||||
#[cfg(feature = "lifecycle")]
|
||||
#[tokio::test]
|
||||
async fn lifecycle_manager_with_metrics_bridge() {
|
||||
let collector = MetricsCollector::new();
|
||||
|
||||
Reference in New Issue
Block a user