Documentation
¶
Overview ¶
Package probe runs network measurements and knows nothing about the central.
Index ¶
- Constants
- Variables
- func Validate(c api.Check) error
- type Outcome
- type Policy
- type Prober
- func (p *Prober) Banner(ctx context.Context, target, expect string) Outcome
- func (p *Prober) Closed(ctx context.Context, target string) Outcome
- func (p *Prober) DNS(ctx context.Context, target, expect string) Outcome
- func (p *Prober) Domain(ctx context.Context, target, expect string) Outcome
- func (p *Prober) Download(ctx context.Context, target, expect string) Outcome
- func (p *Prober) HTTP(ctx context.Context, target string) Outcome
- func (p *Prober) NTP(ctx context.Context, target, expect string) Outcome
- func (p *Prober) Ping(ctx context.Context, target, expect string) Outcome
- func (p *Prober) Run(ctx context.Context, c api.Check) Outcome
- func (p *Prober) TCP(ctx context.Context, target string) Outcome
- func (p *Prober) TLS(ctx context.Context, target, expect string) Outcome
- func (p *Prober) Traceroute(ctx context.Context, target, expect string) Outcome
Constants ¶
const DenyNone = "none"
DenyNone is the --deny value that denies nothing.
Variables ¶
var DefaultDeny = []string{
"127.0.0.0/8", "::1/128",
"169.254.0.0/16", "fe80::/10",
"0.0.0.0/8", "::/128",
"224.0.0.0/4", "ff00::/8",
"100.100.100.200/32", "192.0.0.192/32", "168.63.129.16/32", "fd00:ec2::254/128",
}
DefaultDeny are the ranges an edge never connects to unless told otherwise: loopback, link-local, unspecified, multicast and the metadata services of the clouds. Private ranges are allowed: probing an intranet is the point.
Functions ¶
Types ¶
type Policy ¶ added in v1.1.0
type Policy struct {
// contains filtered or unexported fields
}
Policy lists the address ranges a probe must not connect to. The zero value denies nothing.
func DefaultPolicy ¶ added in v1.1.0
func DefaultPolicy() Policy
DefaultPolicy is the policy of DefaultDeny.
func ParsePolicy ¶ added in v1.1.0
ParsePolicy builds a policy from CIDR prefixes.
type Prober ¶
type Prober struct {
// contains filtered or unexported fields
}
Prober runs measurements. Every connection it opens goes through the policy.
func (*Prober) Banner ¶ added in v1.1.0
Banner opens a connection and reads what the service says first: the line of an SSH, SMTP, FTP, IMAP or POP3 server, or the greeting of a database. It fails when nothing comes, or when expect is not in the line. The time is the connection and the first line.
func (*Prober) Closed ¶ added in v1.1.0
Closed checks that a port is not reachable: it is a good result when the connection is refused or goes unanswered, a failure when it opens. Use it for what must stay behind a firewall: a database, a management port.
func (*Prober) DNS ¶ added in v1.1.0
DNS measures the time to resolve a name. A good answer has at least one record, and when expect is given, one of them holds that text.
func (*Prober) Domain ¶ added in v1.1.0
Domain asks the RDAP service of the registry when a domain expires, and fails when it is within expect days (30 by default). The time is the whole query.
func (*Prober) Download ¶ added in v1.1.0
Download takes up to 8 MiB of a file. The time is the whole download. With expect, it fails when the speed is lower, in megabits per second.
func (*Prober) HTTP ¶ added in v1.1.0
HTTP measures the time until the response headers of a GET arrive. A status of 400 or more is a failure.
func (*Prober) NTP ¶ added in v1.1.0
NTP asks a time server for the time. The time is the round trip. It fails when the clock of this machine is further than expect from the server's, so it also tells when the edge itself has drifted.
func (*Prober) Ping ¶ added in v1.1.0
Ping sends four ICMP echoes. It fails when more than expect percent of them are lost (50 by default); the time is the mean of the answers.
It needs no privilege on Linux when the group of the process may open ping sockets (net.ipv4.ping_group_range), and otherwise a raw socket.
func (*Prober) TLS ¶ added in v1.1.0
TLS measures the time to open a connection and finish the handshake. It fails when the certificate is not trusted, does not match the name, or expires in fewer days than expect (14 by default).
func (*Prober) Traceroute ¶ added in v1.1.0
Traceroute follows the path to a host, one router at a time. It is good when the host is reached in at most expect hops (30 by default); otherwise it says where the path ended: the last router that answered, and how far it was. The time is the round trip to the host.
It needs Linux, and no privilege: it sends UDP packets with a short time to live and reads the ICMP errors that come back.