Skip to content

Go: dnsid — registry client

Generated from the Go source by scripts/gen-docs.sh — do not edit; run it to regenerate. Canonical deep reference: pkg.go.dev/github.com/dnsid-ai/dnsid-go. Guides and account setup: https://docs.dnsid.ai.

Part of the root package github.com/dnsid-ai/dnsid-go — see Core: IdentityManager for the package overview.

AgentDetail matches the OpenAPI AgentDetail schema.

type AgentDetail struct {
ID string `json:"id"`
Domain string `json:"domain"`
DomainDisplay string `json:"domain_display"`
Name string `json:"name,omitempty"`
Environment string `json:"environment"`
Status string `json:"status"`
StatusURL string `json:"status_url"`
Managed string `json:"managed"`
ProtocolStatus *AgentStatus `json:"protocolStatus,omitempty"`
ServerStatus string `json:"serverStatus,omitempty"`
DNSPublished bool `json:"dns_published"`
DNSPublishedAt *time.Time `json:"dns_published_at,omitempty"`
Challenge string `json:"challenge,omitempty"`
ChallengeExpiresAt *time.Time `json:"challenge_expires_at,omitempty"`
ChainRecordStatus string `json:"chain_record_status,omitempty"`
TransactionID string `json:"transaction_id,omitempty"`
RevocationReason string `json:"revocation_reason,omitempty"`
RevokedAt *time.Time `json:"revoked_at,omitempty"`
IdentityRecordExpiresAt *time.Time `json:"identity_record_expires_at,omitempty"`
IdentityRecordExpiring *bool `json:"identity_record_expiring,omitempty"`
Error *AgentError `json:"error,omitempty"`
PublicationConfig PublicationConfig `json:"publication_config"`
CreatedAt time.Time `json:"created_at"`
UpdatedAt time.Time `json:"updated_at"`
}

func WaitForRegistryStatus(ctx context.Context, client RegistryStatusReader, fqdn string, targetStatuses []string, opts *WaitForStatusOptions) (*AgentDetail, error)

WaitForRegistryStatus polls client until the agent at fqdn reaches one of targetStatuses (compared case-insensitively) and returns that AgentDetail. It returns an error when a terminal registry status is reached first, when polling fails, or when ctx (bounded by opts.Timeout, if set) is done. A nil opts polls every second with no timeout beyond ctx’s own.

AgentEvent matches the OpenAPI AgentEvent schema.

type AgentEvent struct {
ID string `json:"id"`
AgentID string `json:"agent_id"`
EventType string `json:"event_type"`
CreatedAt time.Time `json:"created_at"`
ActorID *string `json:"actor_id,omitempty"`
Details map[string]any `json:"details,omitempty"`
}

AgentListItem matches the OpenAPI Agent schema.

type AgentListItem struct {
ID string `json:"id"`
Domain string `json:"domain"`
DomainDisplay string `json:"domain_display"`
Environment string `json:"environment"`
Status string `json:"status"`
CreatedAt time.Time `json:"created_at"`
UpdatedAt time.Time `json:"updated_at"`
}

AgentListResponse matches the OpenAPI AgentListResponse schema.

type AgentListResponse struct {
Agents []AgentListItem `json:"agents"`
NextCursor string `json:"next_cursor,omitempty"`
}

AgentRegistration is normalized registry workflow state for a local identity.

type AgentRegistration struct {
Domain string `json:"domain"`
PublicationAuthority PublicationAuthority `json:"publicationAuthority"`
RegistryStatus string `json:"registryStatus"`
DNSPublished bool `json:"dnsPublished,omitempty"`
ProtocolStatus *AgentStatus `json:"protocolStatus,omitempty"`
// OIDCIssuerURL is the exact issuer returned by the registry at creation.
OIDCIssuerURL string `json:"oidcIssuerUrl,omitempty"`
RegistryURL string `json:"registryUrl"`
Raw json.RawMessage `json:"raw,omitempty"`
}

AgentRegistrationInput is input for registering a local identity with a registry.

type AgentRegistrationInput struct {
Domain string `json:"domain"`
Metadata map[string]any `json:"metadata,omitempty"`
PublicKeyJWK any `json:"publicKeyJwk,omitempty"`
Environment string `json:"environment,omitempty"`
Managed bool `json:"managed,omitempty"`
}

CanonicalRecordContentResponse is registry-prepared unsigned canonical TXT content.

type CanonicalRecordContentResponse struct {
Canonical string `json:"canonical"`
SigningKid string `json:"signingKid"`
Raw json.RawMessage `json:"raw,omitempty"`
}

ChallengeRequest matches the OpenAPI ChallengeRequest schema.

type ChallengeRequest struct {
Nonce string `json:"nonce"`
Signature string `json:"signature"`
}

CreateAgentRequest matches the OpenAPI CreateAgentRequest schema.

type CreateAgentRequest struct {
Domain string `json:"domain,omitempty"`
Name string `json:"name,omitempty"`
PublicKey any `json:"public_key"`
// Optional fields
Environment string `json:"environment,omitempty"`
Managed bool `json:"managed,omitempty"`
ZoneID string `json:"zone_id,omitempty"`
CapabilitiesURL string `json:"capabilities_url,omitempty"`
}

CreateAgentResponse matches the OpenAPI CreateAgentResponse schema.

type CreateAgentResponse struct {
ID string `json:"id"`
Domain string `json:"domain"`
DomainDisplay string `json:"domain_display"`
Name string `json:"name,omitempty"`
Status string `json:"status"`
StatusURL string `json:"status_url"`
PublicationConfig PublicationConfig `json:"publication_config"`
OIDCIssuerURL string `json:"oidc_issuer_url,omitempty"`
}

EventListOptions contains optional parameters for GetAgentEvents.

type EventListOptions struct {
Limit int
Cursor string
}

EventListResponse matches the OpenAPI EventListResponse schema.

type EventListResponse struct {
Events []AgentEvent `json:"events"`
NextCursor *string `json:"next_cursor,omitempty"`
}

HTTPRegistryClient implements RegistryClient against the standard DNSid registry endpoints.

type HTTPRegistryClient struct {
// contains filtered or unexported fields
}

func NewRegistryClient(baseURL string, transportConfig ...TransportConfig) (*HTTPRegistryClient, error)

NewRegistryClient creates an HTTP registry client for baseURL. An empty baseURL means DefaultRegistryURL (the local registry). HTTPS is required except on loopback hosts.

func NewRegistryClientWithOptions(baseURL string, opts ...RegistryClientOption) (*HTTPRegistryClient, error)

NewRegistryClientWithOptions creates an HTTP registry client with functional options. URL rules follow NewRegistryClient.

func (c *HTTPRegistryClient) CancelAgent(ctx context.Context, fqdn string) (*LifecycleResponse, error)

CancelAgent cancels an in-progress registration workflow for fqdn.

func (c *HTTPRegistryClient) CanonicalRecordContent(ctx context.Context, domain, signingKid string) (*CanonicalRecordContentResponse, error)

CanonicalRecordContent fetches the registry-prepared unsigned canonical TXT content for domain, targeted at the given record-signing kid.

func (c *HTTPRegistryClient) ConfirmReady(ctx context.Context, fqdn string) (*LifecycleResponse, error)

ConfirmReady confirms the agent at fqdn is ready to go live. It is an alias for VerifyAgent.

func (c *HTTPRegistryClient) CreateAgent(ctx context.Context, req *CreateAgentRequest) (*CreateAgentResponse, error)

CreateAgent registers an agent. Pass Domain for a name you control (self-managed), or ZoneID for a registry-assigned name in a delegated zone (managed); the two are mutually exclusive, and Managed requires ZoneID. Environment defaults to “production”; “sandbox” is also accepted. Private JWK members in PublicKey are rejected before anything is sent. Use CreateLiveAgent for Live names.

func (c *HTTPRegistryClient) CreateLiveAgent(ctx context.Context, req *LiveAgentRegistrationInput, idempotencyKey string) (*LiveProvisioningResponse, error)

CreateLiveAgent starts the separate managed Live HTTP 202 flow. It sends tier=“live”, managed=true, and environment=“production”. The idempotency key is required and must be reused for retries.

func (c *HTTPRegistryClient) GetAgentEvents(ctx context.Context, fqdn string, opts *EventListOptions) (*EventListResponse, error)

GetAgentEvents lists registry audit events for the agent at fqdn. A nil opts requests the first page with the server’s default limit.

func (c *HTTPRegistryClient) GetAgentStatus(ctx context.Context, fqdn string) (*AgentDetail, error)

GetAgentStatus returns the registry’s detailed view of the agent at fqdn, including workflow status, DNS publication state, and any workflow error.

func (c *HTTPRegistryClient) GetIdentityRecord(ctx context.Context, fqdn string, req *IdentityRecordRequest) (*IdentityRecordResponse, error)

GetIdentityRecord fetches the registry-prepared canonical identity record content for fqdn, targeted at the signing kid named in req.

func (c *HTTPRegistryClient) GetRegistration(ctx context.Context, fqdn string) (*AgentRegistration, error)

GetRegistration returns normalized registry workflow state for fqdn, mapping the registry’s managed mode (“self” or “dnsid”) to a PublicationAuthority. It returns a *ValidationError for unknown managed modes.

func (c *HTTPRegistryClient) ListAgents(ctx context.Context, opts *ListAgentsOptions) (*AgentListResponse, error)

ListAgents lists the caller’s agents. A nil opts requests the first page with the server’s default limit; use the response’s NextCursor to page.

func (c *HTTPRegistryClient) ListExpiringAgents(ctx context.Context) (*OperationsAgentListResponse, error)

ListExpiringAgents lists agents whose identity records are approaching expiry.

func (c *HTTPRegistryClient) ListFlaggedAgents(ctx context.Context) (*OperationsAgentListResponse, error)

ListFlaggedAgents lists agents the registry has flagged for operator attention.

func (c *HTTPRegistryClient) ListPendingAgents(ctx context.Context) (*OperationsAgentListResponse, error)

ListPendingAgents lists agents whose registration workflows have not yet completed.

func (c *HTTPRegistryClient) PrepareIssuance(ctx context.Context, fqdn, idempotencyKey string) (*PreparedRegistryEvent, error)

PrepareIssuance asks the registry to prepare a transparency-log ISSUANCE event for fqdn. The returned entry bytes are untrusted: parse and validate them against the returned log reference before signing. The idempotency key must be 1 to 200 bytes without surrounding whitespace; reuse the same key when retrying.

func (c *HTTPRegistryClient) PrepareKeyRotation(ctx context.Context, fqdn string, req *KeyRotationPreparationRequest, idempotencyKey string) (*PreparedRegistryEvent, error)

PrepareKeyRotation asks the registry to prepare a transparency-log KEY_ROTATION event for fqdn. Authenticate with an organization session or API key; an agent bearer token is not accepted. The request must name the previous key ID and carry the new public key, which is rejected if it contains private JWK members. As with PrepareIssuance, the returned entry bytes are untrusted and must be validated before signing.

func (c *HTTPRegistryClient) PublishSignature(ctx context.Context, domain, sig string) (*PublishedRecord, error)

PublishSignature submits an encoded record signature for domain and returns the resulting publication state as a PublishedRecord.

func (c *HTTPRegistryClient) ReissueLiveProof(ctx context.Context, fqdn string, req *LiveProofReissueRequest) (*LiveProofReissueResponse, error)

ReissueLiveProof requests a replacement challenge for an expired Live proof. RequestID is also sent as the required Idempotency-Key header.

func (c *HTTPRegistryClient) RejectAgent(ctx context.Context, fqdn string) (*LifecycleResponse, error)

RejectAgent marks the registration workflow for fqdn as rejected.

func (c *HTTPRegistryClient) RetireAgent(ctx context.Context, fqdn string, req *RetireAgentRequest) (*LifecycleResponse, error)

RetireAgent retires the immutable agent identity without revoking its key.

func (c *HTTPRegistryClient) RevokeAgent(ctx context.Context, fqdn string, req *RevokeAgentRequest) (*LifecycleResponse, error)

RevokeAgent revokes the immutable agent identity at fqdn with the supplied reason. Revocation is a terminal lifecycle transition whose persistence and transparency-log append are owned by the registry.

func (c *HTTPRegistryClient) SetAuthToken(token string) error

SetAuthToken updates the Bearer token on an existing client (e.g. after refresh). It returns an error if the client is configured for plaintext HTTP on a non-loopback host without WithInsecureHTTP.

func (c *HTTPRegistryClient) SubmitChallenge(ctx context.Context, fqdn string, req *ChallengeRequest) error

SubmitChallenge submits a signed domain-control challenge response for the agent at fqdn. A nil error means the registry accepted the submission.

func (c *HTTPRegistryClient) SubmitLiveProof(ctx context.Context, fqdn string, req *LiveProofRequest) (*LiveProofResponse, error)

SubmitLiveProof submits proof of possession for a managed Live registration. RequestID is also sent as the required Idempotency-Key header.

func (c *HTTPRegistryClient) SubmitPreparedEvent(ctx context.Context, fqdn string, entryBytes []byte, idempotencyKey string) (*SubmissionResult, error)

SubmitPreparedEvent submits the exact signed entry bytes of a prepared event (1 to 65535 bytes) for transparency-log inclusion. On an accepted result it verifies that the registry’s reported entry hash matches the SHA-256 of the submitted bytes and returns a *ValidationError on mismatch. Retry with the same bytes and idempotency key when the registry reports a retryable state (see RegistryAPIError.RetrySameEntry).

func (c *HTTPRegistryClient) SubmitSignature(ctx context.Context, fqdn string, req *SignatureRequest) (*SignatureResponse, error)

SubmitSignature posts a signature through the legacy self-managed identity-record endpoint.

func (c *HTTPRegistryClient) UnregisterAgent(ctx context.Context, fqdn string) error

UnregisterAgent removes the agent at fqdn. It is best-effort for registry compatibility: an already-absent agent or a registry without DELETE support is treated as a successful no-op.

func (c *HTTPRegistryClient) VerifyAgent(ctx context.Context, fqdn string) (*LifecycleResponse, error)

VerifyAgent asks the registry to run its verification step for fqdn and advance the registration workflow.

func (c *HTTPRegistryClient) VerifyDomainRemote(ctx context.Context, req *VerifyDomainRequest) (*VerifyDomainResponse, error)

VerifyDomainRemote asks the registry to check a domain’s DNSid state from its vantage point. It complements, but does not replace, local IdentityManager.VerifyDomain verification.

func (c *HTTPRegistryClient) WaitForStatus(ctx context.Context, fqdn string, targetStatuses []string, opts *WaitForStatusOptions) (*AgentDetail, error)

WaitForStatus polls the registry until the agent at fqdn reaches one of targetStatuses. It is shorthand for WaitForRegistryStatus with this client.

IdentityRecordRequest matches the OpenAPI IdentityRecordRequest schema.

type IdentityRecordRequest struct {
SigningKid string `json:"signingKid"`
}

IdentityRecordResponse matches the OpenAPI IdentityRecordResponse schema.

type IdentityRecordResponse struct {
FQDN string `json:"fqdn"`
CanonicalContent string `json:"canonicalContent"`
SigningKid string `json:"signingKid"`
ExpiresAt string `json:"expiresAt"`
Tags map[string]string `json:"tags"`
}

KeyRotationPreparationRequest requests a prepared operational-key rotation.

type KeyRotationPreparationRequest struct {
PreviousKeyID string `json:"previous_key_id"`
PublicKey any `json:"public_key"`
}

LifecycleResponse matches the OpenAPI LifecycleResponse schema.

type LifecycleResponse struct {
ID string `json:"id"`
Status string `json:"status"`
StatusNote string `json:"status_note,omitempty"`
}

ListAgentsOptions contains optional parameters for ListAgents.

type ListAgentsOptions struct {
Limit int
Cursor string
}

LiveAgentRegistrationInput is the caller-controlled input for managed Live registration. The client supplies the fixed tier, managed, and environment fields on the wire.

type LiveAgentRegistrationInput struct {
Name string `json:"name,omitempty"`
// PublicKey must be one public OKP/Ed25519 signing JWK with alg=EdDSA.
PublicKey any `json:"public_key"`
Environment string `json:"environment,omitempty"`
CapabilitiesURL string `json:"capabilities_url,omitempty"`
}

LiveChallengeTranscript is the validated proof-of-possession transcript decoded from a Live challenge message.

type LiveChallengeTranscript struct {
Protocol string `json:"protocol"`
OrgID string `json:"org_id"`
AgentID string `json:"agent_id"`
FQDN string `json:"fqdn"`
KeyID string `json:"key_id"`
Nonce string `json:"nonce"`
ExpiresAt time.Time `json:"expires_at"`
}

LiveProofReissueRequest requests a fresh challenge after an expired proof.

type LiveProofReissueRequest struct {
RequestID string `json:"request_id"`
// PublicKey is the original Live registration key and is not sent on the wire.
PublicKey any `json:"-"`
}

LiveProofReissueResponse contains the replacement Live proof challenge. Domain and ChallengeTranscript are derived from the validated latest message.

type LiveProofReissueResponse struct {
RequestID string `json:"request_id"`
AgentID string `json:"agent_id"`
Status string `json:"status"`
Challenge string `json:"challenge"`
ChallengeMessage string `json:"challenge_message"`
Domain string `json:"-"`
ChallengeTranscript *LiveChallengeTranscript `json:"-"`
}

LiveProofRequest proves possession of the key supplied for Live registration.

type LiveProofRequest struct {
RequestID string `json:"request_id"`
// Challenge must come from the latest registration or reissue response.
Challenge string `json:"challenge"`
PublicKey any `json:"public_key"`
// Signature is unpadded base64url Ed25519 over the exact bytes obtained by
// base64url-decoding that response's ChallengeMessage. Do not reserialize
// ChallengeTranscript before signing.
Signature string `json:"signature"`
}

LiveProofResponse reports the durable Live proof handoff status.

type LiveProofResponse struct {
RequestID string `json:"request_id"`
AgentID string `json:"agent_id"`
Status string `json:"status"`
}

LiveProvisioningResponse is the HTTP 202 response for a managed Live registration. Domain and ChallengeTranscript are derived and populated while Status is challenge_pending.

type LiveProvisioningResponse struct {
RequestID string `json:"request_id"`
AgentID string `json:"agent_id"`
Status string `json:"status"`
Challenge string `json:"challenge"`
ChallengeMessage string `json:"challenge_message"`
Domain string `json:"-"`
ChallengeTranscript *LiveChallengeTranscript `json:"-"`
}

OperationsAgent matches the OpenAPI OperationsAgent schema.

type OperationsAgent struct {
ID string `json:"id"`
Domain string `json:"domain"`
DomainDisplay string `json:"domain_display"`
Environment string `json:"environment"`
Status string `json:"status"`
DaysRemaining *int `json:"days_remaining,omitempty"`
IdentityRecordExpiresAt *string `json:"identity_record_expires_at,omitempty"`
Error *AgentError `json:"error,omitempty"`
CreatedAt time.Time `json:"created_at"`
UpdatedAt time.Time `json:"updated_at"`
}

OperationsAgentListResponse matches the OpenAPI OperationsAgentListResponse schema.

type OperationsAgentListResponse struct {
Agents []OperationsAgent `json:"agents"`
}

PreparedRegistryEvent contains the untrusted exact bytes and log reference returned by a registry preparation endpoint. Parse and validate EntryBytes against LogReference with the selected log binding before signing.

type PreparedRegistryEvent struct {
EntryBytes []byte
LogReference string
}

PublicationAuthority identifies who controls the accountable-entity key and signs the DNSid record.

type PublicationAuthority string

PublicationAuthority values: the client holds the entity key and signs the record itself, or the registry does so on the client’s behalf.

const (
PublicationAuthorityClient PublicationAuthority = "client"
PublicationAuthorityRegistry PublicationAuthority = "registry"
)

PublicationConfig is the authoritative set of profile-known values the registry uses to construct an agent’s unsigned identity record.

type PublicationConfig struct {
PublishProfile string `json:"publish_profile"`
GovernanceID string `json:"governance_id"`
KeyURL string `json:"ku_url"` // Operational-key JWKS URL.
EntityKeyURL string `json:"ek_url"` // Accountable-entity JWKS URL.
LogRef string `json:"log_ref"`
StatusURL string `json:"status_url"`
CapabilitiesURL string `json:"capabilities_url,omitempty"`
MaxKeyAge string `json:"max_key_age,omitempty"`
}

PublishedRecord is the result of a registry TXT publication workflow.

type PublishedRecord struct {
Domain string `json:"domain"`
OwnerName string `json:"ownerName"`
TXTRecord string `json:"txtRecord"`
TTL int `json:"ttl"`
PublicationStatus string `json:"publicationStatus"`
ProtocolStatus *AgentStatus `json:"protocolStatus,omitempty"`
Raw json.RawMessage `json:"raw,omitempty"`
}

RegistryClient is the full control-plane client for the DNSid registry API.

type RegistryClient interface {
RegistryPublisher
// Agent CRUD
CreateAgent(ctx context.Context, req *CreateAgentRequest) (*CreateAgentResponse, error)
CreateLiveAgent(ctx context.Context, req *LiveAgentRegistrationInput, idempotencyKey string) (*LiveProvisioningResponse, error)
UnregisterAgent(ctx context.Context, fqdn string) error
ListAgents(ctx context.Context, opts *ListAgentsOptions) (*AgentListResponse, error)
GetAgentStatus(ctx context.Context, fqdn string) (*AgentDetail, error)
GetAgentEvents(ctx context.Context, fqdn string, opts *EventListOptions) (*EventListResponse, error)
// Agent lifecycle
SubmitChallenge(ctx context.Context, fqdn string, req *ChallengeRequest) error
SubmitLiveProof(ctx context.Context, fqdn string, req *LiveProofRequest) (*LiveProofResponse, error)
ReissueLiveProof(ctx context.Context, fqdn string, req *LiveProofReissueRequest) (*LiveProofReissueResponse, error)
RevokeAgent(ctx context.Context, fqdn string, req *RevokeAgentRequest) (*LifecycleResponse, error)
RetireAgent(ctx context.Context, fqdn string, req *RetireAgentRequest) (*LifecycleResponse, error)
CancelAgent(ctx context.Context, fqdn string) (*LifecycleResponse, error)
RejectAgent(ctx context.Context, fqdn string) (*LifecycleResponse, error)
VerifyAgent(ctx context.Context, fqdn string) (*LifecycleResponse, error)
ConfirmReady(ctx context.Context, fqdn string) (*LifecycleResponse, error)
// Identity record (new API paths)
GetIdentityRecord(ctx context.Context, fqdn string, req *IdentityRecordRequest) (*IdentityRecordResponse, error)
SubmitSignature(ctx context.Context, fqdn string, req *SignatureRequest) (*SignatureResponse, error)
// Operations
ListExpiringAgents(ctx context.Context) (*OperationsAgentListResponse, error)
ListFlaggedAgents(ctx context.Context) (*OperationsAgentListResponse, error)
ListPendingAgents(ctx context.Context) (*OperationsAgentListResponse, error)
// Verification
VerifyDomainRemote(ctx context.Context, req *VerifyDomainRequest) (*VerifyDomainResponse, error)
}

RegistryClientControlledPublisher adds the registration state needed to enforce client publication authority before signing.

type RegistryClientControlledPublisher interface {
RegistryPublisher
RegistryRegistrationReader
}

RegistryClientOption configures an HTTPRegistryClient.

type RegistryClientOption func(*HTTPRegistryClient)

func WithAuthToken(token string) RegistryClientOption

WithAuthToken sets a Bearer token for authenticated API calls.

func WithInsecureHTTP() RegistryClientOption

WithInsecureHTTP allows the client to use plaintext HTTP transport. This is intended only for local development and testing; production callers should always use HTTPS.

func WithRegistryHTTPClient(client *http.Client) RegistryClientOption

WithRegistryHTTPClient sets a custom HTTP client for the registry client.

RegistryPreparedEventClient is the capability required for prepared C2SP transparency-log preparation and submission transport.

type RegistryPreparedEventClient interface {
PrepareIssuance(ctx context.Context, fqdn, idempotencyKey string) (*PreparedRegistryEvent, error)
PrepareKeyRotation(ctx context.Context, fqdn string, req *KeyRotationPreparationRequest, idempotencyKey string) (*PreparedRegistryEvent, error)
SubmitPreparedEvent(ctx context.Context, fqdn string, entryBytes []byte, idempotencyKey string) (*SubmissionResult, error)
}

RegistryPublisher is the canonical-record and signature-publication capability shared by registry clients.

type RegistryPublisher interface {
CanonicalRecordContent(ctx context.Context, domain, signingKid string) (*CanonicalRecordContentResponse, error)
PublishSignature(ctx context.Context, domain, sig string) (*PublishedRecord, error)
}

RegistryRegistrationReader reads normalized registry workflow state.

type RegistryRegistrationReader interface {
GetRegistration(ctx context.Context, domain string) (*AgentRegistration, error)
}

RegistryRevocationReason is an owner-authorized registry revocation reason. It is distinct from the protocol REVOCATION reason vocabulary.

type RegistryRevocationReason string

Owner-authorized registry revocation reasons.

const (
RegistryRevocationReasonOwnerRequest RegistryRevocationReason = "owner_request"
RegistryRevocationReasonKeyCompromise RegistryRevocationReason = "key_compromise"
)

RegistryRevoker is the registry capability required for managed revocation.

type RegistryRevoker interface {
RevokeAgent(ctx context.Context, fqdn string, req *RevokeAgentRequest) (*LifecycleResponse, error)
}

RegistryStatusReader is the subset needed by WaitForRegistryStatus.

type RegistryStatusReader interface {
GetAgentStatus(ctx context.Context, fqdn string) (*AgentDetail, error)
}

RetireAgentRequest matches the OpenAPI RetireRequest schema.

type RetireAgentRequest struct {
AgentID string `json:"agent_id"`
}

RevokeAgentRequest matches the OpenAPI RevokeRequest schema.

type RevokeAgentRequest struct {
AgentID string `json:"agent_id"`
Reason RegistryRevocationReason `json:"reason"`
}

SignatureRequest matches the OpenAPI SignatureRequest schema.

type SignatureRequest struct {
Signature string `json:"signature"`
}

SignatureResponse is the legacy response for POST /agent/{fqdn}/signature. Its Status is publication workflow state, not protocol AgentStatus.

type SignatureResponse struct {
FQDN string `json:"fqdn"`
Status string `json:"status"`
Message string `json:"message,omitempty"`
Records []DNSRecord `json:"records"`
ZoneFile string `json:"zoneFile,omitempty"`
}

SubmissionResult reports registry transparency-log submission state.

type SubmissionResult struct {
State SubmissionState `json:"state"`
EntryHash string `json:"entry_hash"`
Index *uint64 `json:"index,omitempty"`
KeyID string `json:"key_id,omitempty"`
LogRef string `json:"lr,omitempty"`
ErrorCode string `json:"error_code,omitempty"`
}

SubmissionState is durable registry transparency-log submission state.

type SubmissionState string

SubmissionState values. SubmissionStateAccepted and SubmissionStateRejected are terminal; SubmissionStateIndeterminate means the outcome is unknown and the same bytes should be resubmitted with the same idempotency key.

const (
SubmissionStatePending SubmissionState = "pending"
SubmissionStatePrepared SubmissionState = "prepared"
SubmissionStateSubmitting SubmissionState = "submitting"
SubmissionStateAccepted SubmissionState = "accepted"
SubmissionStateRejected SubmissionState = "rejected"
SubmissionStateIndeterminate SubmissionState = "indeterminate"
)

VerifyDomainRequest matches the OpenAPI VerifyDomainRequest schema.

type VerifyDomainRequest struct {
Domain string `json:"domain"`
}

VerifyDomainResponse matches the OpenAPI VerifyDomainResponse schema.

type VerifyDomainResponse struct {
Domain string `json:"domain"`
Registered bool `json:"registered"`
AgentStatus *string `json:"agent_status,omitempty"`
Reachable *bool `json:"reachable,omitempty"`
KeyMatch *bool `json:"key_match,omitempty"`
VerifiedAt *string `json:"verified_at,omitempty"`
ErrorTitle string `json:"error_title,omitempty"`
ErrorDetail string `json:"error_detail,omitempty"`
Remediation string `json:"remediation,omitempty"`
}

WaitForStatusOptions configures registry status polling.

type WaitForStatusOptions struct {
PollInterval time.Duration
Timeout time.Duration
}

Generated by gomarkdoc