What this family covers
Ten named outcomes, all raised by Api\ResellerFault. This class is not an exception — it is a classification a caller reads off a result object, because a fault here is often the answer this module was actually hoping for (see not_found below). Every one of these is about talking to IDrive e2's own reseller control plane: creating and managing sub-users, keys and regions. It is a different vendor surface from the S3 storage gateway covered in "S3 gateway, bucket and object faults" — both classes happen to name a code unreachable, and they mean the same kind of thing about two different endpoints.
The pair that must never be confused (and once was)
auth and rate_limited look similar — both are refusals from the same endpoint — and were briefly reported as one thing in an early diagnostic on this project, which told operators to re-paste a token that was perfectly fine. They are opposites: auth means the credential itself was refused, and the fix is to re-paste the reseller token into the server entry's Password field. rate_limited means the credential is completely fine and the 40-requests-per-60-seconds budget is simply spent; the result carries exactly how many seconds to wait, and the one thing not to do is touch, re-paste or revoke the token.
The pair that must never be confused for a mutating call
unreachable and timeout were one name until this project separated them: unreachable means the request never left this server at all, so nothing at the vendor was changed by it. timeout means a connection WAS made and the vendor may have already carried out the request before the answer failed to arrive — measured live, a removal call once returned nothing for twenty seconds three times running, and the removal completed anyway on two of those three. Never blindly re-send a mutating call on a timeout; read the account's actual state at the vendor first.
Answers that are not this module having a problem
not_found is frequently the expected answer, not an error: a convergence read asking "does this user already exist?" wants exactly this response when it does not. precondition means the vendor refused because the account is already in some state (already enabled, already has that region, not empty, and so on) — read which vendor code came back and converge or refuse deliberately, because retrying returns the identical answer. stats_not_cached is the bucket-statistics equivalent: a 404 here means the vendor has not computed figures for that bucket yet, not that the bucket is missing — show the last known figure, or nothing, and let the next scheduled sweep pick it up.
The two that point back at this module or at something answering wrongly
invalid_params means this module itself sent something the vendor rejected — a bug in this module, not an operator mistake, and worth reporting with the named parameters and the operation. bad_response means something that is not the reseller API answered at all, or its body does not carry what the call asked for; check the server entry's Hostname field and whether anything (a proxy, a captive portal) sits in front of it. vendor_error is the catch-all: the reseller API itself reported a fault in its own words, which this module passes through rather than reinterpreting.