alerting

package
v1.0.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 1, 2026 License: Apache-2.0 Imports: 25 Imported by: 0

Documentation

Overview

Package alerting turns rules into alerts and alerts into signed webhooks.

Index

Constants

View Source
const (
	EventFiring   = "alert.firing"
	EventResolved = "alert.resolved"
	EventTest     = "test"
)

Events sent to webhooks.

Variables

View Source
var ErrNotPublic = errors.New("address is private or local")

ErrNotPublic refuses a webhook address inside a private or local network: the central would otherwise be a way into them (SSRF).

Functions

func CheckURL

func CheckURL(raw string, allowPrivate bool) error

CheckURL refuses at save time what the dialer would refuse anyway: an address written as a local IP or a local name.

func Describe

func Describe(err error) string

Describe is the error shown to users: a category, never the raw network error, which would tell open ports from closed ones inside a network.

func NewSecret

func NewSecret() (string, error)

NewSecret returns a random signing secret.

func Sign

func Sign(secret string, ts int64, body []byte) string

Sign returns the X-Netprobe-Signature value for a body sent at ts: "sha256=" + hex(HMAC-SHA256(secret, ts + "." + body)).

Types

type AlertPayload

type AlertPayload struct {
	ID         int64      `json:"id"`
	Rule       string     `json:"rule"`
	Kind       string     `json:"kind"`
	Edge       string     `json:"edge"`
	EdgeID     string     `json:"edge_id"`
	CheckID    int64      `json:"check_id,omitempty"`
	Summary    string     `json:"summary"`
	Value      float64    `json:"value"`
	StartedAt  time.Time  `json:"started_at"`
	ResolvedAt *time.Time `json:"resolved_at,omitempty"`
}

type Deliverer

type Deliverer struct {
	Store  DelivererStore
	Sender *Sender
	// contains filtered or unexported fields
}

Deliverer sends queued deliveries, with retries.

func (*Deliverer) Once

func (d *Deliverer) Once(ctx context.Context) error

Once sends the due deliveries.

func (*Deliverer) Run

func (d *Deliverer) Run(ctx context.Context)

Run delivers until ctx ends. Finished deliveries are kept 30 days.

type DelivererStore

type DelivererStore interface {
	ClaimDeliveries(ctx context.Context, now, lease time.Time, limit int) ([]store.Delivery, error)
	Webhook(ctx context.Context, id int64) (store.Webhook, error)
	RecordAttempt(ctx context.Context, id int64, ok bool, status int, errText string, next *time.Time, now time.Time) error
	PurgeDeliveries(ctx context.Context, before time.Time) (int64, error)
}

DelivererStore is the delivery queue.

type Evaluator

type Evaluator struct {
	Store    EvaluatorStore
	Online   func(edge uuid.UUID) bool
	Interval time.Duration
	// contains filtered or unexported fields
}

Evaluator checks every enabled rule on a fixed interval.

func (*Evaluator) Evaluate

func (e *Evaluator) Evaluate(ctx context.Context) error

Evaluate opens and resolves alerts once.

func (*Evaluator) Run

func (e *Evaluator) Run(ctx context.Context)

Run evaluates until ctx ends.

type EvaluatorStore

type EvaluatorStore interface {
	ListRules(ctx context.Context) ([]store.Rule, error)
	ListEdges(ctx context.Context) ([]store.Edge, error)
	ListTargets(ctx context.Context) ([]store.Target, error)
	FiringAlerts(ctx context.Context) ([]store.Alert, error)
	WindowStats(ctx context.Context, since time.Time) ([]store.WindowStat, error)
	PathChangesSince(ctx context.Context, since time.Time) ([]store.LatestPathChange, error)
	OpenAlert(ctx context.Context, a store.Alert) (int64, error)
	ResolveAlert(ctx context.Context, id int64, at time.Time) error
	EnqueueDelivery(ctx context.Context, webhookIDs []int64, event, summary string, payload any, now time.Time) error
}

EvaluatorStore is what the evaluator reads and writes.

type Payload

type Payload struct {
	Event  string        `json:"event"`
	Text   string        `json:"text"`
	Alert  *AlertPayload `json:"alert,omitempty"`
	SentAt time.Time     `json:"sent_at"`
}

Payload is the JSON body of a delivery. "text" makes it readable as is by Slack and Mattermost incoming webhooks.

func NewPayload

func NewPayload(event string, a store.Alert, now time.Time) Payload

type Sender

type Sender struct {
	Client  *http.Client
	Version string
	// Allow webhooks inside private or local networks (an internal chat server).
	AllowPrivate bool
	// Opens the signing secrets, sealed in the database. Nil: stored as is.
	Secrets *secrets.Box
}

Sender posts signed payloads.

func NewSender

func NewSender(version string, allowPrivate bool) *Sender

NewSender does not follow redirects: a hook answers or fails. Unless allowPrivate, it only connects to public addresses.

func (*Sender) SealSecret

func (s *Sender) SealSecret(plain string) (string, error)

SealSecret is how a new signing secret is stored.

func (*Sender) Send

func (s *Sender) Send(ctx context.Context, w store.Webhook, event string, deliveryID int64, body []byte, now time.Time) (status int, err error)

Send posts body to w; ok is true on a 2xx answer.

func (*Sender) Test

func (s *Sender) Test(ctx context.Context, st interface {
	LogDelivery(ctx context.Context, d store.Delivery) error
}, w store.Webhook, now time.Time) (int, error)

Test sends a test event now and logs it in the history.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL