HTTP service entrypoint exposes DeltaScope audit and metadata-aware review over JSON APIs.
Files
File
Responsibility
main.go
Parses process flags, loads runtime config, merges logging settings, and starts the HTTP service
main_test.go
Verifies CLI flag parsing, -version ldflags vs ReportedVersion() fallback, logging config from flags, and runtime config merge helpers
main_e2e_test.go
Runs Docker-backed MySQL/TiDB metadata-aware HTTP e2e coverage against the real server binary using registry-backed connection_id payloads, DML target-table existence cases, and no-leak assertions
Verifies Docker-backed PG17 COUNT(1) query-access behavior through the HTTP connection_id surface, including foreign-table fail-closed
Notes
This command is intentionally thin and delegates HTTP wiring to internal/interfaces/http.
POST /v1/audit accepts offline requests and metadata-aware requests that select a registry-backed, authorized connection_id. Clients never supply direct database endpoints, credentials, secret sources, or TLS settings on the request.
GET /v1/rules, GET /v1/rules/{rule_id}, and GET /v1/capabilities expose rule discovery and HTTP contract metadata.
-auth-enabled, -auth-keys, and -auth-allow-paths configure optional X-API-Key protection.
-rate-limit-enabled, -rate-limit-rps, -rate-limit-burst, and -rate-limit-key configure optional request throttling.
-trusted-proxies controls which proxy CIDRs are trusted for client IP extraction (empty means trust none).
-metrics-enabled controls whether /metrics is exposed in Prometheus text format.
-log-level sets log verbosity: debug, info (default), warn, error.
-version prints the build version. Release ldflags print the tag. Source and go install @main builds print pkg/deltascope.ReportedVersion() (module version or VCS devel-<rev>). DefaultVersion is used only when build information is absent.
-runtime-config <path> loads a runtime YAML config for logging and other service settings. Explicit flags override runtime config values; runtime config overrides hardcoded defaults.
metadata.connect_timeout in runtime config sets the default metadata connect timeout for HTTP metadata-aware audit. Omitted or empty means no default (uses the opener's internal default). Invalid or negative values cause startup to fail with exit code 2.
main_e2e_postgresql_query_access_test.go is retained as HTTP real-route evidence; semantic shape breadth belongs to the unified SDK suite.
Update Rule
If members/interfaces/dependencies change, update this file in same change.
Package main starts the DeltaScope HTTP service.
input: process flags for listen address, optional config path, shutdown timeout, and version printing
output: a long-running JSON HTTP server process over the offline audit engine
pos: HTTP service entrypoint above the internal HTTP adapter
note: if this file changes, update this header and module README.md.