audit

package
v1.0.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 1, 2026 License: Apache-2.0 Imports: 12 Imported by: 0

Documentation

Overview

Package audit records every change made through the admin API.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func Action

func Action(procedure string) string

Action is the method name of a procedure: "/netprobe.v1.AdminService/SaveTarget" -> "SaveTarget".

func ClientIP

func ClientIP(addr string) string

func Outcome

func Outcome(err error) string

Outcome is "ok" or the Connect code of err.

func Redact

func Redact(msg proto.Message) json.RawMessage

Redact returns msg as JSON without any password or secret.

Types

type Recorder

type Recorder struct {
	Store Store
	// contains filtered or unexported fields
}

Recorder writes audit entries. Failures are logged, never returned: an action that happened must not report an error because of its audit.

func (*Recorder) Interceptor

func (r *Recorder) Interceptor(who func(context.Context) string) connect.UnaryInterceptorFunc

Interceptor records every call that may change something (any procedure not marked NO_SIDE_EFFECTS), with the user found by who. Put it inside the auth interceptor.

func (*Recorder) Record

func (r *Recorder) Record(ctx context.Context, actor, action string, err error, clientIP string, req proto.Message)

Record stores one entry. req may be nil.

func (*Recorder) RecordCLI

func (r *Recorder) RecordCLI(ctx context.Context, action string, err error, detail map[string]any)

RecordCLI stores an action run on the central itself, with plain details.

type Store

type Store interface {
	Audit(ctx context.Context, e store.AuditEntry) error
}

Store is where entries go.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL