Documentation
¶
Overview ¶
Package edge is the agent: enrollment, the session with the central, the check scheduler and the local result buffer.
Index ¶
Constants ¶
const DefaultDeny = "0.0.0.0/8,127.0.0.0/8,169.254.0.0/16,::1/128,fe80::/10"
DefaultDeny are the addresses an edge refuses to probe unless told otherwise: its own loopback and link-local networks, cloud metadata (169.254.169.254) included. A central must not reach them through an edge.
Variables ¶
var DefaultLimits = Limits{MaxChecks: 200, MinInterval: 5 * time.Second, MaxCount: 20, MaxPPS: 100, Privileged: true}
DefaultLimits are the limits used when no flag overrides them.
var ErrNotEnrolled = errors.New("edge is not enrolled")
ErrNotEnrolled: no identity in the state directory.
Functions ¶
This section is empty.
Types ¶
type Agent ¶
type Agent struct {
// contains filtered or unexported fields
}
Agent keeps the edge connected, runs its checks and uploads the results.
type Buffer ¶
type Buffer struct {
// contains filtered or unexported fields
}
Buffer keeps results on disk until the central acknowledges them. When full, the oldest results are dropped.
func OpenBuffer ¶
OpenBuffer opens (or creates) the buffer file.
func (*Buffer) Add ¶
func (b *Buffer) Add(results ...*netprobev1.CheckResult) error
Add appends results, dropping the oldest ones beyond the limit.
func (*Buffer) Peek ¶
func (b *Buffer) Peek(n int) ([][]byte, []*netprobev1.CheckResult, error)
Peek returns up to n of the oldest results and their keys.
type Limits ¶
type Limits struct {
MaxChecks int
MinInterval time.Duration
MaxCount int
MaxPPS int
Deny []netip.Prefix
Privileged bool // raw ICMP sockets
}
Limits are enforced by the edge whatever the central asks.
type Scheduler ¶
type Scheduler struct {
// contains filtered or unexported fields
}
Scheduler runs the assigned checks and writes results to the buffer.
func (*Scheduler) Apply ¶
func (s *Scheduler) Apply(a *netprobev1.Assignment) []*netprobev1.RejectedCheck
Apply replaces the running checks. Versions are immutable, so a check already running is left alone. Returns the refused checks.
type State ¶
type State struct {
Dir string `json:"-"`
EdgeID string `json:"edge_id"`
Name string `json:"name"`
CentralURL string `json:"central_url"`
Key crypto.Signer `json:"-"`
Cert *x509.Certificate `json:"-"`
CA *x509.Certificate `json:"-"`
}
State is the edge identity on disk. The key never leaves it.
func (*State) LoadAssignment ¶
func (s *State) LoadAssignment() (*netprobev1.Assignment, error)
LoadAssignment returns the cached assignment, or nil if there is none.
func (*State) SaveAssignment ¶
func (s *State) SaveAssignment(a *netprobev1.Assignment) error
SaveAssignment caches the last assignment, used when the central is down at start.