Documentation
¶
Overview ¶
Package ldappool provides a concurrency-safe pool of reusable, authenticated LDAP connections.
A Pool has exactly one endpoint, transport-security policy, and authentication identity. Connections are exposed only through callback-scoped leases, so a caller cannot rebind, start TLS, close, or retain the underlying LDAP client. The package never retries LDAP operations automatically. In particular, a write that may have reached the server is reported with ErrOutcomeUnknown.
Index ¶
- Variables
- type AcquireError
- type AuthConfig
- type AuthMode
- type BackoffConfig
- type CloseError
- type Config
- type ConfigError
- type Connection
- func (c *Connection) Add(ctx context.Context, request *ldap.AddRequest) error
- func (c *Connection) Compare(ctx context.Context, dn, attribute, value string) (bool, error)
- func (c *Connection) Del(ctx context.Context, request *ldap.DelRequest) error
- func (c *Connection) DirSync(ctx context.Context, request *ldap.SearchRequest, flags, maxAttrCount int64, ...) (*ldap.SearchResult, error)
- func (Connection) GoString() string
- func (c *Connection) Modify(ctx context.Context, request *ldap.ModifyRequest) error
- func (c *Connection) ModifyDN(ctx context.Context, request *ldap.ModifyDNRequest) error
- func (c *Connection) PasswordModify(ctx context.Context, request *ldap.PasswordModifyRequest) (*ldap.PasswordModifyResult, error)
- func (c *Connection) Search(ctx context.Context, request *ldap.SearchRequest) (*ldap.SearchResult, error)
- func (c *Connection) SearchWithPaging(ctx context.Context, request *ldap.SearchRequest, pagingSize uint32) (*ldap.SearchResult, error)
- func (Connection) String() string
- type Counts
- type CredentialAction
- type CredentialDecision
- type CredentialError
- type CredentialFailure
- type CredentialFailureClassifier
- type CredentialFailureClassifierFunc
- type CredentialReason
- type CredentialState
- type DeliveryState
- type Dialer
- type Event
- type EventType
- type FailureReason
- type FailureStage
- type Observer
- type ObserverFunc
- type Operation
- type OperationError
- type PanicError
- type Pool
- func (p *Pool) Close(ctx context.Context) error
- func (p *Pool) ForceClose(ctx context.Context) error
- func (Pool) GoString() string
- func (p *Pool) ResetCredentialGuard() error
- func (p *Pool) RotateCredentials(secret Secret) error
- func (p *Pool) Snapshot() Snapshot
- func (Pool) String() string
- func (p *Pool) Warmup(ctx context.Context, target int) (returnErr error)
- func (p *Pool) WithConnection(ctx context.Context, callback func(*Connection) error) (returnErr error)
- type PoolState
- type Secret
- type Snapshot
- type TLSConfig
- type TLSMode
Examples ¶
Constants ¶
This section is empty.
Variables ¶
var ( // ErrPoolClosed indicates that the Pool is closing or closed. ErrPoolClosed = errors.New("ldappool: pool closed") // ErrWaitQueueFull indicates that MaxWaiters has been reached. ErrWaitQueueFull = errors.New("ldappool: wait queue full") // ErrCredentialDelayed indicates that new authentication attempts are delayed. ErrCredentialDelayed = errors.New("ldappool: credential attempt delayed") // ErrCredentialBlocked indicates that new authentication attempts are blocked. ErrCredentialBlocked = errors.New("ldappool: credential attempt blocked") // ErrNotSent indicates that no byte of the LDAP request was written. ErrNotSent = errors.New("ldappool: request was not sent") // ErrOutcomeUnknown indicates that a write may have taken effect but was not confirmed. ErrOutcomeUnknown = errors.New("ldappool: write outcome unknown") // ErrLeaseInvalid indicates use outside the callback-scoped lease. ErrLeaseInvalid = errors.New("ldappool: connection lease invalid") // ErrConcurrentUse indicates overlapping operations on one lease. ErrConcurrentUse = errors.New("ldappool: concurrent lease use") // ErrDependencyPanic indicates a recovered panic in a dependency boundary. ErrDependencyPanic = errors.New("ldappool: dependency panic") // ErrTransport indicates a transport failure. ErrTransport = errors.New("ldappool: transport failure") // ErrProtocol indicates a malformed, mismatched, or unexpected response. ErrProtocol = errors.New("ldappool: protocol failure") // ErrCloseFailed indicates that resource cleanup failed or exceeded its budget. ErrCloseFailed = errors.New("ldappool: close failed") )
Functions ¶
This section is empty.
Types ¶
type AcquireError ¶
type AcquireError struct {
// Stage identifies where acquisition failed.
Stage FailureStage
// RetryAt is the earliest effective retry time when known.
RetryAt time.Time
// Cause retains a programmatically inspectable error chain.
Cause error
// contains filtered or unexported fields
}
AcquireError reports why a connection could not be acquired.
func (*AcquireError) Error ¶
func (e *AcquireError) Error() string
func (*AcquireError) Unwrap ¶
func (e *AcquireError) Unwrap() []error
type AuthConfig ¶
type AuthConfig struct {
// Mode must explicitly select simple or anonymous authentication.
Mode AuthMode
// BindPrincipal is the fixed simple-Bind identity.
BindPrincipal string
// Password is the fixed simple-Bind secret.
Password Secret
}
AuthConfig configures the Pool's fixed LDAP authentication identity.
func (AuthConfig) GoString ¶
func (AuthConfig) GoString() string
GoString returns a constant redacted representation.
func (AuthConfig) String ¶
func (AuthConfig) String() string
String returns a constant redacted representation.
type BackoffConfig ¶
type BackoffConfig struct {
// Initial is the first failure delay.
Initial time.Duration
// Multiplier controls exponential growth and must be at least one.
Multiplier float64
// Max caps the jittered delay.
Max time.Duration
// Jitter is a multiplicative fraction in [0, 1).
Jitter float64
}
BackoffConfig configures capped exponential backoff with multiplicative jitter. Jitter is a fraction in [0, 1).
type CloseError ¶
type CloseError struct {
// Remaining is the number of open physical connections at timeout.
Remaining int
// TimedOut reports whether the shutdown wait budget expired.
TimedOut bool
// Cause retains timeout or physical-close errors.
Cause error
}
CloseError reports incomplete or failed physical cleanup.
func (*CloseError) Error ¶
func (e *CloseError) Error() string
func (*CloseError) Unwrap ¶
func (e *CloseError) Unwrap() []error
type Config ¶
type Config struct {
// Endpoint is a required ldap:// or ldaps:// URL containing only host and port.
Endpoint string
// TLS configures transport encryption and peer verification.
TLS TLSConfig
// Auth configures the fixed LDAP identity.
Auth AuthConfig
// AllowInsecurePlaintextCredentials is a development-only second gate for a
// plaintext simple Bind.
AllowInsecurePlaintextCredentials bool
// MaxOpen includes connecting, idle, borrowed, and physically closing
// connections. Zero defaults to 8.
MaxOpen int
// MaxIdle bounds retained idle connections. Zero defaults to min(2, MaxOpen).
MaxIdle int
// MaxWaiters bounds externally queued acquisitions. Zero defaults to 1024.
MaxWaiters int
// MaxIdleTime retires a connection after this idle duration. Zero defaults
// to 5 minutes.
MaxIdleTime time.Duration
// MaxLifetime retires a connection after this total lifetime. Zero defaults
// to 30 minutes; it is independent of MaxIdleTime.
MaxLifetime time.Duration
// ConnectTimeout bounds Dial, TLS, and Bind together. Zero defaults to 10 seconds.
ConnectTimeout time.Duration
// RequestTimeout bounds one public synchronous operation. Zero defaults to 30 seconds.
RequestTimeout time.Duration
// CloseTimeout bounds shutdown, callback cleanup, and Warmup cleanup waits.
// Zero defaults to 10 seconds.
CloseTimeout time.Duration
// ConnectBackoff limits new connection attempts after ordinary failures.
// Zero fields default to 100ms initial, 2x, 30s maximum, and 20% jitter.
ConnectBackoff BackoffConfig
// CredentialBackoff controls delayed credential probes. Zero fields default
// to 5s initial, 2x, 5m maximum, and 30% jitter.
CredentialBackoff BackoffConfig
// Dialer optionally supplies a context-aware transport. Nil uses net.Dialer.
Dialer Dialer
// CredentialFailureClassifier optionally applies deployment credential
// policy. Nil uses the conservative built-in classifier.
CredentialFailureClassifier CredentialFailureClassifier
// Observer optionally receives redacted asynchronous events. Nil disables events.
Observer Observer
// ObserverBuffer bounds the observer event queue. Zero defaults to 256 when
// Observer is non-nil and is invalid otherwise when nonzero.
ObserverBuffer int
}
Config configures a Pool. New applies documented defaults, validates all fields, and copies copyable security material. Trusted interface values and arbitrary private-key signers are retained by reference and must be immutable after New. Changing ordinary Config fields after New has no effect.
type ConfigError ¶
type ConfigError struct {
// Field identifies the invalid field without including its value.
Field string
// Reason is a static, non-sensitive validation reason.
Reason string
}
ConfigError reports invalid static configuration without echoing field values.
func (*ConfigError) Error ¶
func (e *ConfigError) Error() string
type Connection ¶
type Connection struct {
// contains filtered or unexported fields
}
Connection is a callback-scoped, single-operation-at-a-time LDAP lease. Its zero value and every value retained after WithConnection returns are invalid. Copying a Connection does not create a new lease; copies share the same invalidation and busy state. Connection intentionally exposes no raw client or session-changing methods.
func (*Connection) Add ¶
func (c *Connection) Add(ctx context.Context, request *ldap.AddRequest) error
Add performs an LDAP Add operation. It is never retried automatically.
func (*Connection) Del ¶
func (c *Connection) Del(ctx context.Context, request *ldap.DelRequest) error
Del performs an LDAP Delete operation. It is never retried automatically.
func (*Connection) DirSync ¶
func (c *Connection) DirSync(ctx context.Context, request *ldap.SearchRequest, flags, maxAttrCount int64, cookie []byte) (*ldap.SearchResult, error)
DirSync performs one bounded synchronous search using the Microsoft DirSync control. It does not expose the asynchronous response API.
func (Connection) GoString ¶
func (Connection) GoString() string
GoString returns a constant redacted representation.
func (*Connection) Modify ¶
func (c *Connection) Modify(ctx context.Context, request *ldap.ModifyRequest) error
Modify performs an LDAP Modify operation. It is never retried automatically.
func (*Connection) ModifyDN ¶
func (c *Connection) ModifyDN(ctx context.Context, request *ldap.ModifyDNRequest) error
ModifyDN performs an LDAP Modify DN operation. It is never retried automatically.
func (*Connection) PasswordModify ¶
func (c *Connection) PasswordModify(ctx context.Context, request *ldap.PasswordModifyRequest) (*ldap.PasswordModifyResult, error)
PasswordModify performs RFC 3062 Password Modify. It is a write and is never retried automatically.
func (*Connection) Search ¶
func (c *Connection) Search(ctx context.Context, request *ldap.SearchRequest) (*ldap.SearchResult, error)
Search performs one complete synchronous LDAP search.
func (*Connection) SearchWithPaging ¶
func (c *Connection) SearchWithPaging(ctx context.Context, request *ldap.SearchRequest, pagingSize uint32) (*ldap.SearchResult, error)
SearchWithPaging performs all pages synchronously within this lease. It copies the paging control and outer request slices before go-ldap mutates them.
func (Connection) String ¶
func (Connection) String() string
String returns a constant redacted representation.
type Counts ¶
type Counts struct {
// Open is connecting plus idle plus borrowed plus closing.
Open int
// Idle is the number available for immediate acquisition.
Idle int
// Borrowed is the number owned by callback leases.
Borrowed int
// Connecting is zero or one.
Connecting int
// Closing remains part of Open until physical close terminates.
Closing int
// Waiters includes queued external and internal acquisitions.
Waiters int
}
Counts is a consistent snapshot of Pool counters taken under the Pool lock.
type CredentialAction ¶
type CredentialAction uint8
CredentialAction controls only future connection authentication attempts. It never determines whether an existing connection is healthy.
const ( // CredentialNotCredential treats a Bind result as an ordinary connection failure. CredentialNotCredential CredentialAction = iota // CredentialDelay delays a future authentication probe using credential backoff. CredentialDelay // CredentialBlock blocks authentication probes until reset or rotation. CredentialBlock )
type CredentialDecision ¶
type CredentialDecision struct {
// Action controls future connection authentication attempts.
Action CredentialAction
// Reason must be a safe, low-cardinality reason value.
Reason CredentialReason
}
CredentialDecision is returned by CredentialFailureClassifier.
type CredentialError ¶
type CredentialError struct {
// State is the credential guard state that denied creation.
State CredentialState
// Reason is a sanitized, low-cardinality classification.
Reason CredentialReason
// RetryAt is the credential probe time when delayed.
RetryAt time.Time
// Cause retains sanitized LDAP result and dependency causes.
Cause error
}
CredentialError reports a delayed or blocked connection-creation decision.
func (*CredentialError) Error ¶
func (e *CredentialError) Error() string
func (*CredentialError) Unwrap ¶
func (e *CredentialError) Unwrap() []error
type CredentialFailure ¶
type CredentialFailure struct {
// ResultCode is the standard LDAP result code.
ResultCode uint16
// Diagnostic is sensitive vendor text available only at the classifier boundary.
Diagnostic string
}
CredentialFailure contains the server result presented to a custom classifier. Diagnostic may contain vendor-specific text and must not be logged or retained. The core package never publishes it in errors or events.
func (CredentialFailure) GoString ¶
func (CredentialFailure) GoString() string
GoString returns a constant redacted representation because Diagnostic is sensitive.
func (CredentialFailure) String ¶
func (CredentialFailure) String() string
String returns a constant redacted representation because Diagnostic is sensitive.
type CredentialFailureClassifier ¶
type CredentialFailureClassifier interface {
Classify(CredentialFailure) CredentialDecision
}
CredentialFailureClassifier optionally classifies a complete Bind result. Implementations must return promptly and must not retain or log CredentialFailure.Diagnostic. They must not wait on the Pool whose connection attempt is being classified.
type CredentialFailureClassifierFunc ¶
type CredentialFailureClassifierFunc func(CredentialFailure) CredentialDecision
CredentialFailureClassifierFunc adapts a function to a classifier.
func (CredentialFailureClassifierFunc) Classify ¶
func (f CredentialFailureClassifierFunc) Classify(failure CredentialFailure) CredentialDecision
Classify calls f(failure).
type CredentialReason ¶
type CredentialReason string
CredentialReason is a sanitized, low-cardinality classification.
const ( CredentialReasonNone CredentialReason = "none" CredentialReasonInvalid CredentialReason = "invalid" CredentialReasonPolicy CredentialReason = "policy" CredentialReasonUnsupported CredentialReason = "unsupported" CredentialReasonUnknown CredentialReason = "unknown" CredentialReasonClassifierPanic CredentialReason = "classifier_panic" CredentialReasonManualReset CredentialReason = "manual_reset" CredentialReasonCredentialRotated CredentialReason = "credential_rotated" )
type CredentialState ¶
type CredentialState string
CredentialState is the process-local credential guard state.
const ( CredentialClear CredentialState = "clear" CredentialDelayed CredentialState = "delayed" CredentialHalfOpen CredentialState = "half_open" CredentialBlocked CredentialState = "blocked" )
type DeliveryState ¶
type DeliveryState uint8
DeliveryState describes whether a request could have reached the server.
const ( // DeliveryNotSent means no request byte was written. DeliveryNotSent DeliveryState = iota // DeliveryDispatched means the request may have reached the server. DeliveryDispatched // DeliveryConfirmed means a complete expected LDAP result was received. DeliveryConfirmed )
func (DeliveryState) String ¶
func (d DeliveryState) String() string
String returns the stable delivery-state name.
type Dialer ¶
type Dialer interface {
DialContext(ctx context.Context, network, address string) (net.Conn, error)
}
Dialer creates a fresh transport for every call.
Implementations must honor ctx and must never return the same live net.Conn instance from more than one call. A proxying implementation must still route the supplied address to one stable logical LDAP endpoint for the Pool's lifetime.
type Event ¶
type Event struct {
// Sequence is monotonically delivered within one Pool observer.
Sequence uint64
// Type identifies the event.
Type EventType
// At is the event time.
At time.Time
// Duration is populated for timed events.
Duration time.Duration
// Operation is populated for LDAP operation events.
Operation Operation
// Stage identifies a lifecycle failure stage or StageNone.
Stage FailureStage
// Reason is a sanitized event or eviction reason.
Reason FailureReason
// CredentialState is populated for credential events.
CredentialState CredentialState
// CredentialReason is a sanitized credential classification.
CredentialReason CredentialReason
// RetryAt is populated for delayed creation events.
RetryAt time.Time
// Counts is a mutually consistent pool-counter sample.
Counts Counts
}
Event is a redacted observation record.
type EventType ¶
type EventType string
EventType identifies an observation event. Values are stable and contain no request or identity data.
const ( EventDialStart EventType = "dial_start" EventDialSuccess EventType = "dial_success" EventDialFailure EventType = "dial_failure" EventTLSFailure EventType = "tls_failure" EventBindSuccess EventType = "bind_success" EventBindFailure EventType = "bind_failure" EventAcquireQueued EventType = "acquire_queued" EventAcquireSuccess EventType = "acquire_success" EventAcquireCanceled EventType = "acquire_canceled" EventBackoffArmed EventType = "backoff_armed" EventCredentialState EventType = "credential_state" EventEviction EventType = "eviction" EventOperationCanceled EventType = "operation_canceled" EventWriteOutcomeUnknown EventType = "write_outcome_unknown" EventCloseTimeout EventType = "close_timeout" EventForceClose EventType = "force_close" EventPoolRecovered EventType = "pool_recovered" EventDependencyPanic EventType = "dependency_panic" )
type FailureReason ¶
type FailureReason string
FailureReason is a sanitized event or eviction reason.
const ( ReasonNone FailureReason = "none" ReasonDial FailureReason = "dial_failure" ReasonTLSValidation FailureReason = "tls_validation_failure" ReasonBind FailureReason = "bind_failure" ReasonIdleTimeout FailureReason = "idle_timeout" ReasonMaxLifetime FailureReason = "max_lifetime" ReasonMaxIdle FailureReason = "max_idle" ReasonCredentialRotation FailureReason = "credential_rotation" ReasonTransport FailureReason = "transport_error" ReasonProtocol FailureReason = "protocol_error" ReasonRequestTimeout FailureReason = "request_timeout" ReasonContextCancellation FailureReason = "context_cancellation" ReasonCallbackPanic FailureReason = "callback_panic" ReasonDependencyPanic FailureReason = "dependency_panic" ReasonLeaseReturnedBusy FailureReason = "lease_returned_busy" ReasonPoolClose FailureReason = "pool_close" ReasonInitialization FailureReason = "initialization_failure" ReasonCloseFailure FailureReason = "close_failure" )
type FailureStage ¶
type FailureStage string
FailureStage identifies a sanitized lifecycle stage.
const ( // StageNone means no failure stage has been recorded. StageNone FailureStage = "none" // StageAcquire identifies acquisition and waiter failures. StageAcquire FailureStage = "acquire" // StageDial identifies raw transport creation. StageDial FailureStage = "dial" // StageTLS identifies TLS establishment or verification. StageTLS FailureStage = "tls" // StageBind identifies fixed-identity authentication. StageBind FailureStage = "bind" // StageOperation identifies a public LDAP operation. StageOperation FailureStage = "operation" // StageClose identifies physical resource cleanup. StageClose FailureStage = "close" )
type Observer ¶
type Observer interface {
Observe(Event)
}
Observer receives events from a bounded asynchronous dispatcher. Observe must return promptly. A panic is recovered and a blocked observer cannot block Pool operations, although it can permanently occupy its dispatcher.
type Operation ¶
type Operation string
Operation identifies a supported LDAP operation without including request data.
const ( // OperationSearch identifies Search. OperationSearch Operation = "search" // OperationSearchWithPaging identifies SearchWithPaging. OperationSearchWithPaging Operation = "search_with_paging" // OperationDirSync identifies synchronous DirSync. OperationDirSync Operation = "dir_sync" // OperationCompare identifies Compare. OperationCompare Operation = "compare" // OperationAdd identifies Add. OperationAdd Operation = "add" // OperationModify identifies Modify. OperationModify Operation = "modify" // OperationDelete identifies Del. OperationDelete Operation = "delete" // OperationModifyDN identifies ModifyDN. OperationModifyDN Operation = "modify_dn" // OperationPasswordModify identifies PasswordModify. OperationPasswordModify Operation = "password_modify" )
type OperationError ¶
type OperationError struct {
// Operation identifies the LDAP operation.
Operation Operation
// Delivery describes whether the request could have reached the server.
Delivery DeliveryState
// Code is a standard LDAP result code when HasCode is true.
Code uint16
// HasCode reports whether a complete server LDAP result was received.
HasCode bool
// Cause retains a redacted, programmatically inspectable chain.
Cause error
// contains filtered or unexported fields
}
OperationError reports a sanitized LDAP operation failure.
func (*OperationError) Error ¶
func (e *OperationError) Error() string
func (*OperationError) ResultCode ¶
func (e *OperationError) ResultCode() (uint16, bool)
ResultCode returns a server LDAP result code when the operation received a complete LDAP result.
func (*OperationError) Unwrap ¶
func (e *OperationError) Unwrap() []error
type PanicError ¶
type PanicError struct {
// Source is a fixed internal dependency-boundary category.
Source string
}
PanicError describes a recovered panic without retaining or printing its payload.
func (*PanicError) Error ¶
func (e *PanicError) Error() string
func (*PanicError) Unwrap ¶
func (e *PanicError) Unwrap() error
type Pool ¶
type Pool struct {
// contains filtered or unexported fields
}
Pool owns reusable physical LDAP connections for one fixed identity. Its zero value is invalid; construct it with New. Its state is held behind an opaque pointer so accidental value formatting cannot traverse secrets.
func New ¶
New validates static configuration and returns a cold Pool. It performs no DNS lookup, network dial, TLS handshake, or Bind.
func (*Pool) Close ¶
Close stops acquisition, allows in-flight operations to finish within the shutdown budget, and then force-closes remaining transports. It is idempotent.
func (*Pool) ForceClose ¶
ForceClose stops acquisition and immediately closes every transport. It is idempotent and shares the same terminal lifecycle as Close.
func (*Pool) ResetCredentialGuard ¶
ResetCredentialGuard explicitly clears the process-local credential guard. It does not change credentials or revive existing connections.
func (*Pool) RotateCredentials ¶
RotateCredentials replaces the simple-Bind password, increments the Pool identity generation, cancels an old connection attempt, and retires all old generation connections. The Bind principal cannot be changed.
func (*Pool) Warmup ¶
Warmup establishes enough authenticated connections for the Pool to have at least target healthy open connections at one instant. Excess idle connections above MaxIdle are closed within one cleanup budget before Warmup returns; cleanup failures are returned. A failure does not close or permanently poison the Pool.
func (*Pool) WithConnection ¶
func (p *Pool) WithConnection(ctx context.Context, callback func(*Connection) error) (returnErr error)
WithConnection acquires a FIFO callback-scoped lease. The Connection becomes permanently invalid when callback returns. callback must not be nil and must not allow an LDAP operation to outlive it; a busy return invalidates the lease, force-closes its transport, and waits only for the cleanup budget.
Example ¶
package main
import (
"context"
"time"
"github.com/go-ldap/ldap/v3"
"github.com/imbrooklyn/ldappool"
)
func main() {
pool, err := ldappool.New(ldappool.Config{
Endpoint: "ldaps://ldap.example.com",
Auth: ldappool.AuthConfig{
Mode: ldappool.AuthSimple,
BindPrincipal: "cn=service,dc=example,dc=com",
Password: ldappool.NewSecret([]byte("load-from-a-secret-store")),
},
})
if err != nil {
return
}
defer func() {
ctx, cancel := context.WithTimeout(context.Background(), 10*time.Second)
defer cancel()
_ = pool.Close(ctx)
}()
ctx, cancel := context.WithTimeout(context.Background(), 5*time.Second)
defer cancel()
request := ldap.NewSearchRequest(
"dc=example,dc=com",
ldap.ScopeWholeSubtree,
ldap.NeverDerefAliases,
100,
5,
false,
"(objectClass=person)",
[]string{"dn"},
nil,
)
_ = pool.WithConnection(ctx, func(connection *ldappool.Connection) error {
_, searchErr := connection.Search(ctx, request)
return searchErr
})
}
Output:
type PoolState ¶
type PoolState string
PoolState is a read-only projection of lifecycle and connectivity state.
const ( PoolCold PoolState = "cold" PoolConnecting PoolState = "connecting" PoolReady PoolState = "ready" PoolTransientBackoff PoolState = "transient_backoff" PoolCredentialDelayed PoolState = "credential_delayed" PoolCredentialBlocked PoolState = "credential_blocked" PoolClosing PoolState = "closing" PoolClosed PoolState = "closed" )
type Secret ¶
type Secret struct {
// contains filtered or unexported fields
}
Secret contains sensitive authentication material.
NewSecret copies its input. Pool construction and credential rotation copy a Secret again so the caller may discard its copy immediately. Go strings made by the LDAP dependency cannot be reliably erased from memory.
type Snapshot ¶
type Snapshot struct {
// CapturedAt is the snapshot time.
CapturedAt time.Time
// State is the projected pool lifecycle/connectivity state.
State PoolState
// Counts is captured atomically under the Pool lock.
Counts Counts
// Generation is the current fixed-identity credential generation.
Generation uint64
// RetryAt is the ordinary connection-creation retry time.
RetryAt time.Time
// ConnectFailures is the current consecutive ordinary failure count.
ConnectFailures uint64
// LastFailureStage is the last sanitized connection lifecycle stage.
LastFailureStage FailureStage
// LastFailureReason is the last sanitized connection lifecycle reason.
LastFailureReason FailureReason
// CredentialState is sampled separately from Counts.
CredentialState CredentialState
// CredentialReason is the current sanitized guard reason.
CredentialReason CredentialReason
// CredentialRetryAt is the next delayed half-open probe time.
CredentialRetryAt time.Time
// CredentialFailures is the guard backoff failure count.
CredentialFailures uint64
// ObserverDropped is the cumulative number of events dropped at enqueue.
ObserverDropped uint64
}
Snapshot is a passive, redacted view of in-memory state. Counts are mutually consistent; credential fields are sampled separately and may straddle one concurrent transition.
type TLSConfig ¶
type TLSConfig struct {
// Mode selects implicit TLS, StartTLS, or the explicit plaintext escape
// hatch. Its zero value is TLSAuto.
Mode TLSMode
// ServerName is the DNS name or IP reference identity used for verification.
// An empty value uses the endpoint host.
ServerName string
// RootCAs replaces the system trust roots when non-nil. Nil uses the system
// roots.
RootCAs *x509.CertPool
// ClientCertificates contains optional client certificate chains and keys.
// Certificate slices and DER are copied; arbitrary private-key signers are
// retained by reference and must be immutable after New.
ClientCertificates []tls.Certificate
// MinVersion is either tls.VersionTLS12 or tls.VersionTLS13. Zero defaults
// to TLS 1.2.
MinVersion uint16
}
TLSConfig configures server authentication and optional client certificates.
type TLSMode ¶
type TLSMode uint8
TLSMode controls how transport security is established.
const ( // TLSAuto selects implicit TLS for ldaps:// and StartTLS for ldap://. TLSAuto TLSMode = iota // TLSStartTLS upgrades an ldap:// connection before authentication. TLSStartTLS // TLSImplicit establishes TLS before starting LDAP. TLSImplicit // TLSPlaintext disables transport encryption. Simple authentication also // requires AllowInsecurePlaintextCredentials and is intended only for // isolated development environments. TLSPlaintext )