Client Configuration
The BastionClient class is the central entry point for all SDK operations.
1. Initializing with Connection URI
The simplest way to initialize BastionClient is by passing a connection URI string:
import { BastionClient } from "@liorans3/driver";
// 1. Basic authentication (Local Dev)
const devClient = new BastionClient("bastion://admin:admin@127.0.0.1:27118");
// 2. Programmatic Access Key
const keyClient = new BastionClient("bastion://bk_live_0192a7b8:sk_live_9f83a21b4c7e@127.0.0.1:27118");
// 3. Production HTTPS endpoint
const prodClient = new BastionClient("https://admin:MySecurePassword123!@s3.example.com");
2. Initializing with Options Object
Alternatively, pass a BastionClientOptions configuration object:
import { BastionClient, type BastionClientOptions } from "@liorans3/driver";
// Basic Authentication
const client = new BastionClient({
host: "127.0.0.1",
port: 27118,
username: "admin",
password: "MySecurePassword123!",
timeoutMs: 30000,
});
// Programmatic Access Key Authentication with TLS
const prodClient = new BastionClient({
host: "s3.example.com",
isTls: true, // Connects over HTTPS (port 443)
accessKey: "bk_live_0192a7b8c9d0",
secretKey: "sk_live_8f3a9b2c1d4e5f6a",
timeoutMs: 60000,
idleTimeoutMs: 120000,
connectTimeoutMs: 10000,
});
3. Configuration Options Reference
| Option | Type | Default | Description |
|---|---|---|---|
uri | string | — | Complete connection URI. Mutually exclusive with individual credential fields. |
host | string | "127.0.0.1" | Server hostname or IP address. |
port | number | 27118 (or 443 if TLS) | Server TCP listener port. |
isTls / ssl | boolean | false | Enable TLS / HTTPS connection encryption. |
username | string | — | Username for Basic authentication. |
password | string | — | Password for Basic authentication. |
accessKey | string | — | Programmatic Access Key ID (bk_...). |
secretKey | string | — | Programmatic Access Key Secret (sk_...). |
timeoutMs | number | 30000 | Overall request timeout in milliseconds. |
connectTimeoutMs | number | 10000 | TCP connection establishment timeout in milliseconds. |
idleTimeoutMs | number | 60000 | Socket idle timeout in milliseconds. |
fetch | typeof fetch | — | Optional custom fetch implementation override. |
:::caution Credential Validation Rule
The driver strictly forbids specifying both username/password and accessKey/secretKey simultaneously. Passing both will immediately throw an InvalidInputError.
:::
4. Zero-Leak Credential Masking
To prevent accidental credential leaks into monitoring, logging, or debugging dashboards:
const client = new BastionClient("bastion://admin:SecretPass123!@127.0.0.1:27118");
// 1. Safe URI property
console.log(client.safeUri);
// Output: "bastion://admin:***@127.0.0.1:27118"
// 2. Custom Node.js util.inspect
console.log(client);
// Output: BastionClient { uri: "bastion://admin:***@127.0.0.1:27118" }
// 3. Safe JSON serialization
console.log(JSON.stringify(client));
// Output: {"uri":"bastion://admin:***@127.0.0.1:27118","safeUri":"bastion://admin:***@127.0.0.1:27118"}