Documentation
¶
Overview ¶
Package docker inspects a local Docker daemon through the official Docker Engine API client. It only uses read-only API endpoints and never changes containers, images, networks, volumes or daemon configuration.
Index ¶
- Constants
- func ListenerExposure(address string) (loopbackOnly bool)
- func Verify(ctx context.Context, conn *Connection) error
- type API
- type Connection
- type Container
- type Daemon
- type DiskUsage
- type Image
- type Inspector
- type ListenerObservation
- type Mount
- type Snapshot
- type UnavailableError
- type UsageItem
Constants ¶
const PingTimeout = 10 * time.Second
PingTimeout bounds how long Connect waits for the daemon to answer.
const UnencryptedAPIPort = 2375
UnencryptedAPIPort is the conventional port of the unencrypted Docker API.
Variables ¶
This section is empty.
Functions ¶
func ListenerExposure ¶
ListenerExposure classifies a listener address: true when it is reachable only from the local machine.
Types ¶
type API ¶
type API interface {
Ping(ctx context.Context, options client.PingOptions) (client.PingResult, error)
ServerVersion(ctx context.Context, options client.ServerVersionOptions) (client.ServerVersionResult, error)
Info(ctx context.Context, options client.InfoOptions) (client.SystemInfoResult, error)
ContainerList(ctx context.Context, options client.ContainerListOptions) (client.ContainerListResult, error)
ContainerInspect(ctx context.Context, id string, options client.ContainerInspectOptions) (client.ContainerInspectResult, error)
ImageList(ctx context.Context, options client.ImageListOptions) (client.ImageListResult, error)
DiskUsage(ctx context.Context, options client.DiskUsageOptions) (client.DiskUsageResult, error)
Close() error
}
API is the read-only subset of the Docker Engine API used by StackSentry. *client.Client satisfies it; tests provide fakes.
type Connection ¶
type Connection struct {
API API
// Endpoint is the daemon address, e.g. unix:///var/run/docker.sock.
Endpoint string
// TLS reports whether the client was configured with TLS certificates.
TLS bool
}
Connection is an established, verified connection to a Docker daemon.
type Container ¶
type Container struct {
ID string
Name string
Image string
State string
Running bool
// Inspected is true when detailed configuration was read.
Inspected bool
Privileged bool
NetworkMode string
RestartPolicy string
AutoRemove bool
Mounts []Mount
}
Container describes one container.
type Daemon ¶
type Daemon struct {
Version string
APIVersion string
OperatingSystem string
OSType string
Architecture string
KernelVersion string
Name string
RootDir string
Rootless bool
Warnings []string
}
Daemon describes the Docker daemon.
type DiskUsage ¶
type DiskUsage struct {
Images UsageItem
Containers UsageItem
Volumes UsageItem
BuildCache UsageItem
}
DiskUsage summarizes Docker's disk usage by object type.
func (DiskUsage) Reclaimable ¶
Reclaimable returns the combined reclaimable size of all object types.
type Inspector ¶
type Inspector struct {
Conn *Connection
// HostFS is the host root filesystem used to read daemon configuration
// and /proc. It may be nil, in which case those checks are skipped.
HostFS fs.FS
// GOOS is the operating system StackSentry runs on.
GOOS string
}
Inspector collects a Snapshot from a Docker daemon.
type ListenerObservation ¶
type ListenerObservation struct {
// Source names where the observation came from.
Source string
// Address is the listening address, e.g. tcp://0.0.0.0:2375.
Address string
// Detail adds context such as missing TLS verification.
Detail string
Confidence findings.Confidence
}
ListenerObservation is evidence that the Docker API listens on TCP.
type Snapshot ¶
type Snapshot struct {
Endpoint string
Daemon Daemon
// Containers lists all containers, running and stopped, sorted by name.
Containers []Container
// ImagesTotal is the number of images reported by the daemon.
ImagesTotal int
// DanglingImages are untagged images not referenced by any tag.
DanglingImages []Image
// DiskUsage is nil when the daemon did not provide usage data.
DiskUsage *DiskUsage
// Listeners are observations of TCP API listeners.
Listeners []ListenerObservation
// Limitations describe information that could not be collected.
Limitations []string
}
Snapshot is a read-only view of a Docker host collected for host rules.
type UnavailableError ¶
type UnavailableError struct {
}
UnavailableError explains why the Docker daemon could not be used. It is a user-environment problem and maps to exit code 2.
func Classify ¶
func Classify(endpoint string, err error) *UnavailableError
Classify turns a connection error into an actionable UnavailableError.
func (*UnavailableError) Unwrap ¶
func (e *UnavailableError) Unwrap() error
Unwrap returns the underlying error.
Directories
¶
| Path | Synopsis |
|---|---|
|
Package dockertest provides an in-memory fake of the read-only Docker API used by StackSentry, for tests that must not depend on a Docker daemon.
|
Package dockertest provides an in-memory fake of the read-only Docker API used by StackSentry, for tests that must not depend on a Docker daemon. |