package config import ( "fmt" "time" "proxy-pool/internal/domain/clientpolicy" ) // MaximumCheckURLs bounds per-upstream EGRESS references. The bound keeps // scheduling and proxy cleanup proportional to a fixed configuration limit. const MaximumCheckURLs = 16 // MaximumTargetProfilesPerUpstream bounds the Cartesian expansion of enabled // Routing target checks and their referenced upstreams. TARGET scheduling // materializes one bounded due reference per live proxy and target profile. const MaximumTargetProfilesPerUpstream = 64 const ( MaximumPoolSize = 1_000_000 MaximumExactCounter = int64(1<<53 - 1) MaximumUpstreams = 4_096 ) type Duration time.Duration func (d *Duration) UnmarshalText(text []byte) error { value, err := time.ParseDuration(string(text)) if err != nil { return fmt.Errorf("parse duration %q: %w", text, err) } *d = Duration(value) return nil } func (d Duration) Value() time.Duration { return time.Duration(d) } type Config struct { Version int `yaml:"version"` Defaults Defaults `yaml:"defaults"` Security Security `yaml:"security"` Gateway Listener `yaml:"gateway"` Distribution Distribution `yaml:"distribution"` Admin Listener `yaml:"admin"` ControlPlane ControlPlane `yaml:"controlPlane"` Metrics Metrics `yaml:"metrics"` Storage Storage `yaml:"storage"` Routing []Routing `yaml:"routing"` Upstreams map[string]Upstream `yaml:"upstreams"` } type Defaults struct { Fetch Fetch `yaml:"fetch"` Check Check `yaml:"check"` } type Security struct { RequireProtectionOnPublicListen bool `yaml:"requireProtectionOnPublicListen"` } type Listener struct { Enabled bool `yaml:"enabled"` Listen string `yaml:"listen"` Access Access `yaml:"access"` Auth Auth `yaml:"auth"` Limits Limits `yaml:"limits"` Retry Retry `yaml:"retry"` StickySession StickySession `yaml:"stickySession"` Transport GatewayTransport `yaml:"transport"` DestinationPolicy DestinationPolicy `yaml:"destinationPolicy"` } type Distribution struct { Listener `yaml:",inline"` ClientIdentification ClientIdentification `yaml:"clientIdentification"` Extraction Extraction `yaml:"extraction"` } type Access struct { AllowCIDRs []string `yaml:"allowCIDRs"` TrustedProxies []string `yaml:"trustedProxies"` } type Auth struct { Mode string `yaml:"mode"` Permissions []string `yaml:"permissions"` ClientPolicy clientpolicy.Policy `yaml:"client"` Username string `yaml:"username"` Password string `yaml:"password"` PasswordFile string `yaml:"passwordFile"` Token string `yaml:"token"` TokenFile string `yaml:"tokenFile"` Header string `yaml:"header"` CIDRs []string `yaml:"cidrs"` Methods []AuthMethod `yaml:"methods"` } type AuthMethod struct { Mode string `yaml:"mode"` Permissions []string `yaml:"permissions"` ClientPolicy clientpolicy.Policy `yaml:"client"` Username string `yaml:"username"` Password string `yaml:"password"` PasswordFile string `yaml:"passwordFile"` Header string `yaml:"header"` Value string `yaml:"value"` ValueFile string `yaml:"valueFile"` CIDRs []string `yaml:"cidrs"` } type Limits struct { MaxConcurrentConnections int `yaml:"maxConcurrentConnections"` RequestsPerMinute int `yaml:"requestsPerMinute"` RequestsPerMinutePerClient int `yaml:"requestsPerMinutePerClient"` } type Retry struct { MaxAttempts int `yaml:"maxAttempts"` RetryMethods []string `yaml:"retryMethods"` } // StickySession configures per-Worker, bounded Gateway affinity. It does not // store Proxy details or session identifiers in PostgreSQL or Redis. type StickySession struct { Enabled bool `yaml:"enabled"` Header string `yaml:"header"` TTL Duration `yaml:"ttl"` MaxEntries int `yaml:"maxEntries"` } // GatewayTransport configures the local Gateway process connection pools and // tunnel I/O. It intentionally contains no remote state or provider settings. type GatewayTransport struct { DialTimeout Duration `yaml:"dialTimeout"` HandshakeTimeout Duration `yaml:"handshakeTimeout"` ResponseHeaderTimeout Duration `yaml:"responseHeaderTimeout"` IdleConnTimeout Duration `yaml:"idleConnTimeout"` MaxIdleConns int `yaml:"maxIdleConns"` MaxIdleConnsPerHost int `yaml:"maxIdleConnsPerHost"` MaxConnsPerHost int `yaml:"maxConnsPerHost"` TunnelBufferBytes int `yaml:"tunnelBufferBytes"` TunnelIdleTimeout Duration `yaml:"tunnelIdleTimeout"` } type DestinationPolicy struct { DenyPrivateNetworks *bool `yaml:"denyPrivateNetworks"` DenyLoopback *bool `yaml:"denyLoopback"` DenyLinkLocal *bool `yaml:"denyLinkLocal"` DenyCIDRs []string `yaml:"denyCIDRs"` AllowedPorts []uint16 `yaml:"allowedPorts"` } type ClientIdentification struct { Mode string `yaml:"mode"` } type Extraction struct { Fulfillment string `yaml:"fulfillment"` MaxCountPerRequest int `yaml:"maxCountPerRequest"` MinRemainingTTL Duration `yaml:"minRemainingTTL"` MaxHealthCheckAge Duration `yaml:"maxHealthCheckAge"` ReserveForGateway int `yaml:"reserveForGateway"` IdempotencyTTL Duration `yaml:"idempotencyTTL"` } type Metrics struct { Enabled bool `yaml:"enabled"` Listen string `yaml:"listen"` } type ControlPlane struct { Enabled bool `yaml:"enabled"` Listen string `yaml:"listen"` ProtocolVersion uint32 `yaml:"protocolVersion"` HeartbeatInterval Duration `yaml:"heartbeatInterval"` SessionTTL Duration `yaml:"sessionTTL"` MaxStaleAge Duration `yaml:"maxStaleAge"` MaxMessageBytes int `yaml:"maxMessageBytes"` MaxRuntimeCounters int `yaml:"maxRuntimeCounters"` MaxConcurrentStreams uint32 `yaml:"maxConcurrentStreams"` TLS ControlPlaneTLS `yaml:"tls"` GatewayTLS ClientTLS `yaml:"gatewayTLS"` CheckerTLS ClientTLS `yaml:"checkerTLS"` } type ControlPlaneTLS struct { Mode string `yaml:"mode"` CertFile string `yaml:"certFile"` KeyFile string `yaml:"keyFile"` ClientCAFile string `yaml:"clientCAFile"` TrustDomain string `yaml:"trustDomain"` Environment string `yaml:"environment"` } // ClientTLS holds client-only mTLS material. Each control-plane client type // owns a distinct certificate so its SPIFFE identity cannot be confused with // another process role. type ClientTLS struct { CertFile string `yaml:"certFile"` KeyFile string `yaml:"keyFile"` ServerCAFile string `yaml:"serverCAFile"` } // GatewayTLS remains as a source-compatible alias for callers that construct // Gateway control-plane configuration in Go. type GatewayTLS = ClientTLS type Storage struct { PostgresURL string `yaml:"postgresURL"` RedisURL string `yaml:"redisURL"` } type Routing struct { Name string `yaml:"name"` Enabled bool `yaml:"enabled"` Purpose string `yaml:"purpose"` Match RoutingMatch `yaml:"match"` Upstreams []string `yaml:"upstreams"` Strategy Strategy `yaml:"strategy"` OnUnavailable OnUnavailable `yaml:"onUnavailable"` Check RoutingCheck `yaml:"check"` } // RoutingCheck defines target-specific health probes. Unlike upstream Check, // these facts are isolated by Routing and never mutate global proxy health. type RoutingCheck struct { Targets []string `yaml:"targets"` } type RoutingMatch struct { HostRegex string `yaml:"hostRegex"` Methods []string `yaml:"methods"` PathRegex string `yaml:"pathRegex"` Headers map[string]string `yaml:"headers"` } type Strategy struct { Type string `yaml:"type"` SwitchAfterEmptyFetch int `yaml:"switchAfterEmptyFetch"` EndBehavior string `yaml:"endBehavior"` Weights map[string]int `yaml:"weights"` } type OnUnavailable struct { Action string `yaml:"action"` WaitTimeout Duration `yaml:"waitTimeout"` } type Upstream struct { Enabled bool `yaml:"enabled"` Exposure []string `yaml:"exposure"` Provider Provider `yaml:"provider"` API ProviderAPI `yaml:"api"` ProxyAuth ProxyAuth `yaml:"proxyAuth"` Pool Pool `yaml:"pool"` Capacity Capacity `yaml:"capacity"` Refill Refill `yaml:"refill"` Lifecycle Lifecycle `yaml:"lifecycle"` Fetch Fetch `yaml:"fetch"` Check Check `yaml:"check"` } type Provider struct { BillingMode string `yaml:"billingMode"` Protocols []string `yaml:"protocols"` } type ProviderAPI struct { URL string `yaml:"url"` Method string `yaml:"method"` Auth ProviderAuth `yaml:"auth"` Headers map[string]string `yaml:"headers"` Query map[string]string `yaml:"query"` Body APIBody `yaml:"body"` Template string `yaml:"template"` } type ProviderAuth struct { Type string `yaml:"type"` Username string `yaml:"username"` Password string `yaml:"password"` PasswordFile string `yaml:"passwordFile"` Token string `yaml:"token"` TokenFile string `yaml:"tokenFile"` Location string `yaml:"location"` Name string `yaml:"name"` Value string `yaml:"value"` ValueFile string `yaml:"valueFile"` } type APIBody struct { Type string `yaml:"type"` Value map[string]string `yaml:"value"` } type ProxyAuth struct { Type string `yaml:"type"` Username string `yaml:"username"` Password string `yaml:"password"` PasswordFile string `yaml:"passwordFile"` } type Pool struct { MaxSize int `yaml:"maxSize"` ShrinkDelay Duration `yaml:"shrinkDelay"` } type Capacity struct { MaxConcurrencyPerProxy int `yaml:"maxConcurrencyPerProxy"` } type Refill struct { ReconcileInterval Duration `yaml:"reconcileInterval"` MinimumAvailableSlots int64 `yaml:"minimumAvailableSlots"` TargetAvailableSlots int64 `yaml:"targetAvailableSlots"` } type Lifecycle struct { TTL Duration `yaml:"ttl"` AllocationSafetyMargin Duration `yaml:"allocationSafetyMargin"` } type Fetch struct { EstimatedIPsPerCall int `yaml:"estimatedIPsPerCall"` RequestInterval Duration `yaml:"requestInterval"` Timeout Duration `yaml:"timeout"` MaxAttempts int `yaml:"maxAttempts"` MaxInFlight int `yaml:"maxInFlight"` MaxTotal int `yaml:"maxTotal"` MaxResponseBytes int64 `yaml:"maxResponseBytes"` TemplateTimeout Duration `yaml:"templateTimeout"` Retry Backoff `yaml:"retry"` } type Backoff struct { Initial Duration `yaml:"initial"` Max Duration `yaml:"max"` Jitter int `yaml:"jitter"` } type Check struct { Interval Duration `yaml:"interval"` Jitter int `yaml:"jitter"` MaxInFlight int `yaml:"maxInFlight"` Timeout Duration `yaml:"timeout"` MaxAttempts int `yaml:"maxAttempts"` MaxConsecutiveFailures int `yaml:"maxConsecutiveFailures"` UnhealthyRemoveAfter Duration `yaml:"unhealthyRemoveAfter"` URLs []string `yaml:"urls"` }