rbac-proxy::on-config-change
Internal: hot-reload rbac-proxy from the authoritative configuration — rebinds the public listener on a host/port change (last-good on failure), else swaps the per-connection snapshot.
- idstring
- okbooleanrequired
RBAC boundary proxy for the iii worker protocol — auth, gating, namespacing, middleware, and engine:: result filtering on its own port.
exact versions are immutable; binary and bundle artifacts are digest-pinned.
Internal: hot-reload rbac-proxy from the authoritative configuration — rebinds the public listener on a host/port change (last-good on failure), else swaps the per-connection snapshot.
Internal: invalidate the discovery catalog cache when the engine's available function set changes.
Health/identity probe: bound host/port, the (credential-redacted) upstream engine URL, whether an auth function is configured, and the live downstream connection count.
Live downstream connections.
Upstream engine URL, with any `user:pass@` credentials redacted.
Bound public host.
Bound public RBAC port.
Whether an `auth_function_id` is configured.
Worker version (matches `Cargo.toml`).