webtessera/mirror
Copies a log into S3-compatible storage or any ObjectStore.
It ports the Go package tessera/cmd/experimental/mirror.
Its source is src/mirror/index.ts.
Functions
isRecoverable- isRecoverable reports whether err was not marked with unrecoverable, like retry-go's
IsRecoverable. newS3Sink- newS3Sink returns a Sink that stores objects in a bucket of any service that speaks the S3 API, signing requests with AWS Signature Version 4: AWS S3, Cloudflare R2, Google Cloud Storage (XML API, with HMAC keys), Backblaze B2, MinIO, Ceph, Wasabi and the like.
newSinkTarget- newSinkTarget returns the mirror Target that writes each resource to the sink under its tlog-tiles path (
checkpoint,tile/0/x001/234,tile/entries/000.p/7, ...), so that the sink ends up holding a static tlog-tiles log that any file server, CDN or public bucket can serve as it is. newSourceFetch- newSourceFetch returns a fetch function for reading a log that is not trusted, to hand to
newHTTPFetcheras the source of a mirror: - It does not follow redirects. tlog-tiles says its resources "MUST NOT serve redirect responses", and following one would let the source send the mirror anywhere. - It refuses any response body larger than maxBytes, from its declared length or while streaming, so that a hostile source cannot exhaust the mirror's memory. newVerifiedMirror- newVerifiedMirror returns a Mirror that copies a log only as far as it can verify it: every resource is checked against the source's signed checkpoint, and that checkpoint against the target's, before anything is written, and the checkpoint is written last.
newVerifyingSource- newVerifyingSource wraps a mirror Source so that it returns only verified resources: - readCheckpoint returns the source's checkpoint once it carries a valid signature from verifier for origin, the source's partial tiles hash to its root, and (with a target) it is consistent with the mirror's current checkpoint; - readTile returns a tile once it is proven part of that tree: a partial tile by the root itself, a full one by its hash in the verified tile above it; - readEntryBundle returns an entry bundle once its entries hash to the verified level-0 tile.
signV4- signV4 signs a request with AWS Signature Version 4, in the form S3 specifies: the path URI-encoded once and not normalised ("Each path segment must be URI-encoded twice" holds for every other AWS service, not for S3), the query parameters sorted by encoded name then value, every header the request carries signed, and the payload hash both signed and, by convention of the caller, sent as
x-amz-content-sha256. unrecoverable- unrecoverable marks err as one retry must not retry, the counterpart of retry-go's
retry.Unrecoverable: a verification failure, say, which would only fail again.
Classes
Mirror- Mirror is a struct which knows how to use the Src and Store functions to copy a tlog-tiles compliant log from one location to another.
RetryError- RetryError is what retry throws once every attempt has failed: the port of retry-go's
Error(a[]error), with the same message, and the sameIs, which matches if any attempt's error does. S3Error- S3Error reports a request the service refused.
S3Sink- S3Sink is a Sink backed by an S3-compatible bucket.
SinkTarget- SinkTarget is a mirror Target, and a Source, over a Sink.
VerifyingSource- VerifyingSource is a Source that verifies.
Interfaces
AwsCredentials- AwsCredentials are the credentials a request is signed with.
MirrorProgress- MirrorProgress is what Mirror.progress returns.
S3SinkOptions- S3SinkOptions configures newS3Sink.
SignedV4- SignedV4 is the outcome of signing: the headers to add, and the intermediate values.
SignV4Input- SignV4Input is a request to sign.
Sink- Sink is the minimal storage a log can be mirrored into: something that stores bytes under slash-separated keys.
SinkTargetOptions- SinkTargetOptions configures newSinkTarget.
Source- Source describes a type which can fetch static resources from a source log, like the .*Fetcher implementations in the client package.
SourceFetchOptions- SourceFetchOptions configures newSourceFetch.
Target- Target describes a type which can store log static resources.
VerifiedMirrorOptions- VerifiedMirrorOptions configures newVerifiedMirror.
VerifyingSourceOptions- VerifyingSourceOptions configures newVerifyingSource.
Types
SinkObject- SinkObject is what a sink's
getmay resolve to: the bytes themselves, or a body to read them from.
Constants and variables
MaxCheckpointBytes- MaxCheckpointBytes caps the checkpoints a VerifyingSource accepts.
MaxResourceBytes- MaxResourceBytes is the size of the largest resource a tlog-tiles log can serve: a full entry bundle of 256 entries of 65535 bytes, each with its two-byte length prefix.