/** * Shared service-account credential-pool ownership (Batch A). * * This module owns the N-`GoogleAuth` pool every provider line paces and * signs with: one auth per key file (one Google quota principal), the * deterministic round-robin cursor, and the per-identity index binding that * ties admission to transport (the admitted identity IS the signing * identity). Providers build their API clients (`sheets({ version, auth })` * stays provider-side) from the selected auths; the pacing pool * (`CredentialPacingPool` in ikisaki) meets this pool at the existing * admission→transport index binding, which is unchanged. * * Out-of-range selection fails CLOSED through the caller-supplied * `onInvalidSelection` (same parameterization as the key loader's `fail`): * signing with a different identity than the one admission paced against * would silently defeat the per-identity quota contract. */ import type { GoogleAuth } from "google-auth-library"; import { type ServiceAccountKeyLoadOptions } from "./serviceAccountKey.js"; /** * Advances (and returns) the next round-robin client index for a pool. * * A preferred (provider-admitted) index is returned WITHOUT advancing the * cursor, so admission-bound calls never skew the fallback rotation. The * cursor is a mutable carrier so callers keep the rotation across requests; * `clientCount` must be ≥ 1. */ export declare function nextPooledClientIndex(cursor: { next: number; }, clientCount: number, preferredIndex: number | undefined): number; /** Selection failure mapping (must throw, never return). */ export interface ServiceAccountAuthPoolSelection { readonly onInvalidSelection: (message: string) => never; } /** Key-file pool construction: scopes plus both failure mappings. */ export interface ServiceAccountAuthPoolKeyFilesOptions extends ServiceAccountKeyLoadOptions, ServiceAccountAuthPoolSelection { /** OAuth scopes the pooled auths request (provider-owned, e.g. Sheets/Drive). */ readonly scopes: readonly string[]; } /** * The N-`GoogleAuth` credential pool plus its rotation cursor. * * Generic over the auth value so providers wrap their own auth flavor * (injected test auths, the ADC default) together with the file-backed * `GoogleAuth` instances under ONE selection cursor. */ export declare class ServiceAccountAuthPool { /** Every pooled credential; index-aligned with the provider's clients. */ readonly auths: readonly TAuth[]; private readonly selection; /** Fallback rotation cursor for requests WITHOUT an admitted index. */ private readonly poolCursor; constructor( /** Every pooled credential; index-aligned with the provider's clients. */ auths: readonly TAuth[], selection: ServiceAccountAuthPoolSelection); /** * Builds the file-backed pool: each key file is read and turned into its * own `GoogleAuth` at construction (fail fast on unreadable or malformed * files). Error payloads carry the PATH only — never file contents, * client emails, or key material. */ static loadFromKeyFiles(keyFiles: readonly string[], options: ServiceAccountAuthPoolKeyFilesOptions): ServiceAccountAuthPool; /** Number of pooled credentials (quota principals). */ get size(): number; /** * Picks the pool index for one request: the admitted identity when the * request carries one, otherwise the next round-robin entry (a 1-auth * pool always selects index 0 — the historical single-auth path). */ selectIndex(preferredIndex: number | undefined): number; } //# sourceMappingURL=serviceAccountAuthPool.d.ts.map