sdk

module
v0.0.0-...-aeed61c Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 9, 2026 License: MIT

Directories

Path Synopsis
api
forward/v1
Package forwardv1 holds the forwarding contract (anixops.forward.v1): routes as chains of hops with a per-hop engine (nftables, gost, the AnixOps protocol), the per-node desired state the planner renders, the reports nodes send, and the ForwardControl and ForwardNode services.
Package forwardv1 holds the forwarding contract (anixops.forward.v1): routes as chains of hops with a per-hop engine (nftables, gost, the AnixOps protocol), the per-node desired state the planner renders, the reports nodes send, and the ForwardControl and ForwardNode services.
kernelnodeops/v1
Package kernelnodeopsv1 holds the KernelNodeOps contract (anixops.kernelnodeops.v1): typed, idempotent node operations that official packages ask the kernel to carry out, designed in docs/architecture/node-ops-service.md.
Package kernelnodeopsv1 holds the KernelNodeOps contract (anixops.kernelnodeops.v1): typed, idempotent node operations that official packages ask the kernel to carry out, designed in docs/architecture/node-ops-service.md.
forward
driver
Package driver is the boundary between a node's forwarding state and the engines that run it (docs/architecture/forward-sdk.md section 6).
Package driver is the boundary between a node's forwarding state and the engines that run it (docs/architecture/forward-sdk.md section 6).
driver/anixops
Package anixops is the forward driver for ENGINE_ANIXOPS (docs/architecture/anixops-protocol.md section 6.1, phase A3): it runs the anixops hops of a node's state in the relay process of sdk/forward/driver/anixops/relayd, the `anixops-relay` unit the Agent's package ships, under its own systemd unit anixops-relay.service (decision P1), so restarting or upgrading the Agent keeps forwarding.
Package anixops is the forward driver for ENGINE_ANIXOPS (docs/architecture/anixops-protocol.md section 6.1, phase A3): it runs the anixops hops of a node's state in the relay process of sdk/forward/driver/anixops/relayd, the `anixops-relay` unit the Agent's package ships, under its own systemd unit anixops-relay.service (decision P1), so restarting or upgrading the Agent keeps forwarding.
driver/anixops/anixopstest
Package anixopstest runs the anixops relay inside the test process, so the driver (sdk/forward/driver/anixops) is tested against a real relay, real sockets and real files without privileges, a network namespace or systemd: Host is a relay supervisor that starts and stops a relayd.Relay on a control socket in a temporary directory, shares it between driver instances (an Agent restart is a new driver on the same host) and can crash it, fail its next apply or redirect its dials to a local target.
Package anixopstest runs the anixops relay inside the test process, so the driver (sdk/forward/driver/anixops) is tested against a real relay, real sockets and real files without privileges, a network namespace or systemd: Host is a relay supervisor that starts and stops a relayd.Relay on a control socket in a temporary directory, shares it between driver instances (an Agent restart is a new driver on the same host) and can crash it, fail its next apply or redirect its dials to a local target.
driver/anixops/relayctl
Package relayctl is the contract between the anixops forward driver (sdk/forward/driver/anixops, which runs in the Agent) and the relay process it controls (sdk/forward/driver/anixops/relayd, the `anixops-relay` unit): the relay's configuration document, which the driver renders and the relay loads, and the control API the driver reaches the relay with over a unix socket (docs/architecture/anixops-protocol.md section 6.1).
Package relayctl is the contract between the anixops forward driver (sdk/forward/driver/anixops, which runs in the Agent) and the relay process it controls (sdk/forward/driver/anixops/relayd, the `anixops-relay` unit): the relay's configuration document, which the driver renders and the relay loads, and the control API the driver reaches the relay with over a unix socket (docs/architecture/anixops-protocol.md section 6.1).
driver/anixops/relayd
Package relayd is the relay process of the anixops forward engine (docs/architecture/anixops-protocol.md section 6): the hop runtime that the `anixops-relay` unit runs and the driver (sdk/forward/driver/anixops) controls over a unix socket.
Package relayd is the relay process of the anixops forward engine (docs/architecture/anixops-protocol.md section 6): the hop runtime that the `anixops-relay` unit runs and the driver (sdk/forward/driver/anixops) controls over a unix socket.
driver/conformance
Package conformance is the forward driver conformance suite (docs/architecture/forward-sdk.md section 13): one list of scenarios that every driver in sdk/forward/driver must pass: the in-memory fake, the nftables driver (on a real kernel in a network namespace, nftables.TestNetnsConformance) and the gost driver (against the pinned gost in a network namespace, gost.TestNetnsConformance; on a simulated host, gost.TestConformanceFakeHost).
Package conformance is the forward driver conformance suite (docs/architecture/forward-sdk.md section 13): one list of scenarios that every driver in sdk/forward/driver must pass: the in-memory fake, the nftables driver (on a real kernel in a network namespace, nftables.TestNetnsConformance) and the gost driver (against the pinned gost in a network namespace, gost.TestNetnsConformance; on a simulated host, gost.TestConformanceFakeHost).
driver/fake
Package fake is an in-memory forward driver (sdk/forward/driver) for tests: the conformance suite's reference implementation and, later, the Agent's forward component tests.
Package fake is an in-memory forward driver (sdk/forward/driver) for tests: the conformance suite's reference implementation and, later, the Agent's forward component tests.
driver/gost
Package gost is the forward driver for ENGINE_GOST (docs/architecture/forward-sdk.md section 6.2): it runs the gost hops of a node's state in one gost v3 process, the pinned release the Agent ships (PinnedVersion, owner decision H20), under its own systemd unit anixops-gost.service, so restarting or upgrading the Agent keeps forwarding.
Package gost is the forward driver for ENGINE_GOST (docs/architecture/forward-sdk.md section 6.2): it runs the gost hops of a node's state in one gost v3 process, the pinned release the Agent ships (PinnedVersion, owner decision H20), under its own systemd unit anixops-gost.service, so restarting or upgrading the Agent keeps forwarding.
driver/nftables
Package nftables is the forward driver for ENGINE_NFTABLES (docs/architecture/forward-sdk.md section 6.1): kernel DNAT, masquerade, counters per direction, balancing maps, named quotas and connection limits in one table, "inet anixops_fwd", which is the only nftables object it ever touches (owner decision H13).
Package nftables is the forward driver for ENGINE_NFTABLES (docs/architecture/forward-sdk.md section 6.1): kernel DNAT, masquerade, counters per direction, balancing maps, named quotas and connection limits in one table, "inet anixops_fwd", which is the only nftables object it ever touches (owner decision H13).
e2e
Package e2e is the forwarding SDK's multi-namespace end-to-end suite (docs/architecture/forward-sdk.md section 13, F2d).
Package e2e is the forwarding SDK's multi-namespace end-to-end suite (docs/architecture/forward-sdk.md section 13, F2d).
leastconn
Package leastconn approximates LEAST_CONN balancing (forward-sdk.md section 7.1, L1).
Package leastconn approximates LEAST_CONN balancing (forward-sdk.md section 7.1, L1).
model
Package model holds the Go domain types of the forwarding contract (anixops.forward.v1, sdk/api/forward/v1): a Route is a chain of Hops from an entry node through optional relays to an exit, and on to Targets, with a Policy (balancing, health checks, circuit breaker, direct mode, target policy) and Limits enforced on the entry.
Package model holds the Go domain types of the forwarding contract (anixops.forward.v1, sdk/api/forward/v1): a Route is a chain of Hops from an entry node through optional relays to an exit, and on to Targets, with a Policy (balancing, health checks, circuit breaker, direct mode, target policy) and Limits enforced on the entry.
planner
Package planner turns forwarding routes into the desired state of every node (docs/architecture/forward-sdk.md section 5).
Package planner turns forwarding routes into the desired state of every node (docs/architecture/forward-sdk.md section 5).
relay
Package relay is the transport library of the AnixOps relay protocol (docs/architecture/anixops-protocol.md, owner decision H22): the frame format, the stream multiplexer, the QUIC carrier with native UDP, carrier selection and the rules that keep a carrier from outliving its owner, between two nodes of one AnixOps deployment.
Package relay is the transport library of the AnixOps relay protocol (docs/architecture/anixops-protocol.md, owner decision H22): the frame format, the stream multiplexer, the QUIC carrier with native UDP, carrier selection and the rules that keep a carrier from outliving its owner, between two nodes of one AnixOps deployment.
relay/link
Package link makes the connections of the AnixOps relay protocol (docs/architecture/anixops-protocol.md, owner decision H22): the TLS 1.3 connection between two nodes with mutual authentication and per-identity pinning, over TCP or inside QUIC, the plaintext connection of a trusted link, and what guards a listener before and during the handshake.
Package link makes the connections of the AnixOps relay protocol (docs/architecture/anixops-protocol.md, owner decision H22): the TLS 1.3 connection between two nodes with mutual authentication and per-identity pinning, over TCP or inside QUIC, the plaintext connection of a trusted link, and what guards a listener before and during the handshake.
relay/relaytest
Package relaytest builds the credentials the relay packages' tests need without the kernel: a link CA shaped like the one internal/agentpki issues (a self-signed ECDSA P-256 root, name-constrained to spiffe://anixops URIs, signing nothing but link certificates) and node certificates of the H28 shape (the node's identity name as CN and only DNS name, its SPIFFE ID as only URI, serverAuth and clientAuth).
Package relaytest builds the credentials the relay packages' tests need without the kernel: a link CA shaped like the one internal/agentpki issues (a self-signed ECDSA P-256 root, name-constrained to spiffe://anixops URIs, signing nothing but link certificates) and node certificates of the H28 shape (the node's identity name as CN and only DNS name, its SPIFFE ID as only URI, serverAuth and clientAuth).
validate
Package validate holds the forwarding route rules that Control (before it stores a route), the planner (before it plans one) and the Agent (for what it can see) all run, so every side refuses the same routes for the same reasons.
Package validate holds the forwarding route rules that Control (before it stores a route), the planner (before it plans one) and the Agent (for what it can see) all run, so every side refuses the same routes for the same reasons.
wire
Package wire is how forwarding rides the Agent Control stream (anix.agent.v1; docs/architecture/forward-sdk.md section 8 and sdk/api/agent/v1/PROTOCOL.md, "Forwarding").
Package wire is how forwarding rides the Agent Control stream (anix.agent.v1; docs/architecture/forward-sdk.md section 8 and sdk/api/agent/v1/PROTOCOL.md, "Forwarding").
Package identitytoken is the contract for AnixOps identity access tokens: the claims, the published key set (JWKS) and verification.
Package identitytoken is the contract for AnixOps identity access tokens: the claims, the published key set (JWKS) and verification.
Package modulesdk runs a package host as a local child process of the kernel or as a network module.
Package modulesdk runs a package host as a local child process of the kernel or as a network module.
Package moduletls holds the mTLS identity rules shared by the Control kernel and network modules.
Package moduletls holds the mTLS identity rules shared by the Control kernel and network modules.
Package packagebridgesdk is the narrow client surface available to a package-host executable.
Package packagebridgesdk is the narrow client surface available to a package-host executable.
Package packagestoresdk opens a package's own database storage from a kernel storage lease and runs the package's embedded SQL migrations.
Package packagestoresdk opens a package's own database storage from a kernel storage lease and runs the package's embedded SQL migrations.
Package shadowsample builds and sanitizes the samples a package host keeps of shadow-mode mismatches: what differed between a route's legacy and native answer, with every secret and personal value masked.
Package shadowsample builds and sanitizes the samples a package host keeps of shadow-mode mismatches: what differed between a route's legacy and native answer, with every secret and personal value masked.
telemetry
systemdreport
Package systemdreport is the schema of the systemd.services package report: the per-node systemd services table of the machine-telemetry package (docs/architecture/package-reports.md).
Package systemdreport is the schema of the systemd.services package report: the per-node systemd services table of the machine-telemetry package (docs/architecture/package-reports.md).
Package v2compat holds the /api/v2 response conventions shared by the kernel's legacy handlers and package-native implementations, so both produce byte-identical output.
Package v2compat holds the /api/v2 response conventions shared by the kernel's legacy handlers and package-native implementations, so both produce byte-identical output.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL