mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-02 07:34:45 +08:00
* chore(deps): replace ring with AWS-LC Signed-off-by: Simon Scatton <sscatton@nvidia.com> * fix(lint): address warnings after dependency upgrades Signed-off-by: Simon Scatton <sscatton@nvidia.com> * fix(tls): limit provider initialization to reqwest clients Signed-off-by: Simon Scatton <sscatton@nvidia.com> --------- Signed-off-by: Simon Scatton <sscatton@nvidia.com>
137 lines
4.5 KiB
TOML
137 lines
4.5 KiB
TOML
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
|
|
# SPDX-License-Identifier: Apache-2.0
|
|
|
|
[package]
|
|
name = "openshell-server"
|
|
description = "OpenShell gRPC/HTTP server with protocol multiplexing"
|
|
version.workspace = true
|
|
edition.workspace = true
|
|
rust-version.workspace = true
|
|
license.workspace = true
|
|
repository.workspace = true
|
|
|
|
[dependencies]
|
|
openshell-bootstrap = { path = "../openshell-bootstrap" }
|
|
openshell-core = { path = "../openshell-core", default-features = false, features = ["oauth"] }
|
|
openshell-driver-db-credstore = { path = "../openshell-driver-db-credstore" }
|
|
openshell-driver-kubernetes-secrets = { path = "../openshell-driver-kubernetes-secrets" }
|
|
openshell-driver-vault = { path = "../openshell-driver-vault" }
|
|
openshell-extension-core = { path = "../openshell-extension-core" }
|
|
openshell-gateway-interceptors = { path = "../openshell-gateway-interceptors" }
|
|
openshell-ocsf = { path = "../openshell-ocsf" }
|
|
openshell-otel = { path = "../openshell-otel" }
|
|
openshell-policy = { path = "../openshell-policy" }
|
|
openshell-prover = { path = "../openshell-prover" }
|
|
openshell-providers = { path = "../openshell-providers" }
|
|
openshell-router = { path = "../openshell-router" }
|
|
openshell-supervisor-middleware = { path = "../openshell-supervisor-middleware" }
|
|
openshell-supervisor-middleware-builtins = { path = "../openshell-supervisor-middleware-builtins" }
|
|
|
|
# Kubernetes client used by ServiceAccount bootstrap authentication and the
|
|
# `generate-certs` subcommand.
|
|
kube = { workspace = true }
|
|
k8s-openapi = { workspace = true }
|
|
|
|
# Async runtime
|
|
tokio = { workspace = true }
|
|
socket2 = { workspace = true }
|
|
nix = { workspace = true }
|
|
|
|
# gRPC
|
|
tonic = { workspace = true, features = ["channel", "tls-native-roots"] }
|
|
prost = { workspace = true }
|
|
prost-reflect = { workspace = true }
|
|
prost-types = { workspace = true }
|
|
|
|
# HTTP server
|
|
axum = { workspace = true }
|
|
tower = { workspace = true }
|
|
tower-http = { workspace = true }
|
|
hyper = { workspace = true }
|
|
hyper-util = { workspace = true, features = ["client", "http1", "http2"] }
|
|
http = { workspace = true }
|
|
http-body = { workspace = true }
|
|
http-body-util = { workspace = true }
|
|
|
|
# TLS
|
|
tokio-rustls = { workspace = true }
|
|
rustls = { workspace = true }
|
|
rustls-pemfile = { workspace = true }
|
|
|
|
# CLI
|
|
clap = { workspace = true }
|
|
|
|
# Error handling
|
|
miette = { workspace = true }
|
|
thiserror = { workspace = true }
|
|
anyhow = { workspace = true }
|
|
|
|
# Logging
|
|
tracing = { workspace = true }
|
|
tracing-subscriber = { workspace = true }
|
|
|
|
# OpenTelemetry (OTLP trace export, opt-in via [openshell.gateway.otlp])
|
|
opentelemetry = { workspace = true }
|
|
opentelemetry_sdk = { workspace = true }
|
|
tracing-opentelemetry = { workspace = true }
|
|
|
|
# Metrics
|
|
metrics = { workspace = true }
|
|
metrics-exporter-prometheus = { workspace = true }
|
|
|
|
# Utilities
|
|
base64 = { workspace = true }
|
|
futures = { workspace = true }
|
|
bytes = { workspace = true }
|
|
pin-project-lite = { workspace = true }
|
|
serde = { workspace = true }
|
|
serde_json = { workspace = true }
|
|
toml = { workspace = true }
|
|
tokio-stream = { workspace = true }
|
|
sqlx = { workspace = true }
|
|
sqlx-core = { workspace = true }
|
|
reqwest = { workspace = true }
|
|
aws-config = { workspace = true }
|
|
aws-sdk-sts = { workspace = true }
|
|
uuid = { workspace = true }
|
|
hmac = "0.12"
|
|
sha2 = { workspace = true }
|
|
jsonwebtoken = { workspace = true }
|
|
spiffe = { workspace = true }
|
|
async-trait = "0.1"
|
|
url = { workspace = true }
|
|
glob = { workspace = true }
|
|
hex = "0.4"
|
|
russh = "0.62"
|
|
rand = { workspace = true }
|
|
petname = "2"
|
|
ipnet = "2"
|
|
tempfile = "3"
|
|
rustix = { workspace = true }
|
|
x509-parser = "0.16"
|
|
arc-swap = "1"
|
|
notify = "8"
|
|
|
|
[features]
|
|
default = ["telemetry"]
|
|
## Compile in anonymous telemetry emission (forwards to openshell-core/telemetry).
|
|
## On by default; build with `--no-default-features` for a telemetry-free gateway
|
|
## that contains no telemetry endpoint, HTTP client, or emission code.
|
|
telemetry = ["openshell-core/telemetry"]
|
|
bundled-z3 = ["openshell-prover/bundled-z3"]
|
|
test-support = []
|
|
|
|
[dev-dependencies]
|
|
base64 = { workspace = true }
|
|
hyper-rustls = { version = "0.27", default-features = false, features = ["native-tokio", "http1", "tls12", "logging", "aws-lc-rs"] }
|
|
rcgen = { workspace = true }
|
|
rsa = { version = "0.9", features = ["pem"] }
|
|
tokio-tungstenite = { workspace = true }
|
|
futures-util = "0.3"
|
|
wiremock = "0.6"
|
|
# `testing` provides InMemorySpanExporter, so span assertions do not need a
|
|
# collector, a network hop, or a flush barrier.
|
|
opentelemetry_sdk = { workspace = true, features = ["testing"] }
|
|
[lints]
|
|
workspace = true
|