edge

package
v1.0.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 1, 2026 License: Apache-2.0 Imports: 30 Imported by: 0

Documentation

Overview

Package edge is the agent: enrollment, the session with the central, the check scheduler and the local result buffer.

Index

Constants

View Source
const DefaultDeny = "0.0.0.0/8,127.0.0.0/8,169.254.0.0/16,::1/128,fe80::/10"

DefaultDeny are the addresses an edge refuses to probe unless told otherwise: its own loopback and link-local networks, cloud metadata (169.254.169.254) included. A central must not reach them through an edge.

Variables

View Source
var DefaultLimits = Limits{MaxChecks: 200, MinInterval: 5 * time.Second, MaxCount: 20, MaxPPS: 100, Privileged: true}

DefaultLimits are the limits used when no flag overrides them.

View Source
var ErrNotEnrolled = errors.New("edge is not enrolled")

ErrNotEnrolled: no identity in the state directory.

Functions

This section is empty.

Types

type Agent

type Agent struct {
	// contains filtered or unexported fields
}

Agent keeps the edge connected, runs its checks and uploads the results.

func NewAgent

func NewAgent(s *State, opts Options) *Agent

func (*Agent) Run

func (a *Agent) Run(ctx context.Context) error

Run measures and keeps a session open until ctx ends. Checks keep running while the central is unreachable.

type Buffer

type Buffer struct {
	// contains filtered or unexported fields
}

Buffer keeps results on disk until the central acknowledges them. When full, the oldest results are dropped.

func OpenBuffer

func OpenBuffer(path string, max int) (*Buffer, error)

OpenBuffer opens (or creates) the buffer file.

func (*Buffer) Add

func (b *Buffer) Add(results ...*netprobev1.CheckResult) error

Add appends results, dropping the oldest ones beyond the limit.

func (*Buffer) Close

func (b *Buffer) Close() error

func (*Buffer) Delete

func (b *Buffer) Delete(keys [][]byte) error

Delete removes acknowledged results.

func (*Buffer) Len

func (b *Buffer) Len() int

Len is the number of buffered results.

func (*Buffer) Peek

func (b *Buffer) Peek(n int) ([][]byte, []*netprobev1.CheckResult, error)

Peek returns up to n of the oldest results and their keys.

type Limits

type Limits struct {
	MaxChecks   int
	MinInterval time.Duration
	MaxCount    int
	MaxPPS      int
	Deny        []netip.Prefix
	Privileged  bool // raw ICMP sockets
}

Limits are enforced by the edge whatever the central asks.

type Options

type Options struct {
	Version   string
	Limits    Limits
	BufferMax int
}

Options configure an agent.

type Scheduler

type Scheduler struct {
	// contains filtered or unexported fields
}

Scheduler runs the assigned checks and writes results to the buffer.

func NewScheduler

func NewScheduler(ctx context.Context, limits Limits, buf *Buffer) *Scheduler

func (*Scheduler) Apply

Apply replaces the running checks. Versions are immutable, so a check already running is left alone. Returns the refused checks.

func (*Scheduler) Running

func (s *Scheduler) Running() int

Running is the number of running checks.

type State

type State struct {
	Dir        string            `json:"-"`
	EdgeID     string            `json:"edge_id"`
	Name       string            `json:"name"`
	CentralURL string            `json:"central_url"`
	Key        crypto.Signer     `json:"-"`
	Cert       *x509.Certificate `json:"-"`
	CA         *x509.Certificate `json:"-"`
}

State is the edge identity on disk. The key never leaves it.

func Enroll

func Enroll(ctx context.Context, dir, centralURL, token, caHash, version string) (*State, error)

Enroll trades a token for an identity, pinning the CA by fingerprint.

func Load

func Load(dir string) (*State, error)

func (*State) LoadAssignment

func (s *State) LoadAssignment() (*netprobev1.Assignment, error)

LoadAssignment returns the cached assignment, or nil if there is none.

func (*State) Save

func (s *State) Save() error

Save writes every file atomically.

func (*State) SaveAssignment

func (s *State) SaveAssignment(a *netprobev1.Assignment) error

SaveAssignment caches the last assignment, used when the central is down at start.

func (*State) SaveCert

func (s *State) SaveCert(cert *x509.Certificate) error

SaveCert stores a renewed certificate.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL