Skip to main content

Client Configuration

The BastionClient class is the central entry point for all SDK operations.


1. Initializing with Connection URI​

The simplest way to initialize BastionClient is by passing a connection URI string:

import { BastionClient } from "@liorans3/driver";

// 1. Basic authentication (Local Dev)
const devClient = new BastionClient("bastion://admin:admin@127.0.0.1:27118");

// 2. Programmatic Access Key
const keyClient = new BastionClient("bastion://bk_live_0192a7b8:sk_live_9f83a21b4c7e@127.0.0.1:27118");

// 3. Production HTTPS endpoint
const prodClient = new BastionClient("https://admin:MySecurePassword123!@s3.example.com");

2. Initializing with Options Object​

Alternatively, pass a BastionClientOptions configuration object:

import { BastionClient, type BastionClientOptions } from "@liorans3/driver";

// Basic Authentication
const client = new BastionClient({
host: "127.0.0.1",
port: 27118,
username: "admin",
password: "MySecurePassword123!",
timeoutMs: 30000,
});

// Programmatic Access Key Authentication with TLS
const prodClient = new BastionClient({
host: "s3.example.com",
isTls: true, // Connects over HTTPS (port 443)
accessKey: "bk_live_0192a7b8c9d0",
secretKey: "sk_live_8f3a9b2c1d4e5f6a",
timeoutMs: 60000,
idleTimeoutMs: 120000,
connectTimeoutMs: 10000,
});

3. Configuration Options Reference​

OptionTypeDefaultDescription
uristring—Complete connection URI. Mutually exclusive with individual credential fields.
hoststring"127.0.0.1"Server hostname or IP address.
portnumber27118 (or 443 if TLS)Server TCP listener port.
isTls / sslbooleanfalseEnable TLS / HTTPS connection encryption.
usernamestring—Username for Basic authentication.
passwordstring—Password for Basic authentication.
accessKeystring—Programmatic Access Key ID (bk_...).
secretKeystring—Programmatic Access Key Secret (sk_...).
timeoutMsnumber30000Overall request timeout in milliseconds.
connectTimeoutMsnumber10000TCP connection establishment timeout in milliseconds.
idleTimeoutMsnumber60000Socket idle timeout in milliseconds.
fetchtypeof fetch—Optional custom fetch implementation override.

:::caution Credential Validation Rule The driver strictly forbids specifying both username/password and accessKey/secretKey simultaneously. Passing both will immediately throw an InvalidInputError. :::


4. Zero-Leak Credential Masking​

To prevent accidental credential leaks into monitoring, logging, or debugging dashboards:

const client = new BastionClient("bastion://admin:SecretPass123!@127.0.0.1:27118");

// 1. Safe URI property
console.log(client.safeUri);
// Output: "bastion://admin:***@127.0.0.1:27118"

// 2. Custom Node.js util.inspect
console.log(client);
// Output: BastionClient { uri: "bastion://admin:***@127.0.0.1:27118" }

// 3. Safe JSON serialization
console.log(JSON.stringify(client));
// Output: {"uri":"bastion://admin:***@127.0.0.1:27118","safeUri":"bastion://admin:***@127.0.0.1:27118"}