auditv1

package
v0.2.6 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: May 24, 2026 License: MIT Imports: 5 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

View Source
var File_audit_proto protoreflect.FileDescriptor

Functions

This section is empty.

Types

type AnchorRecord

type AnchorRecord struct {

	// provider is the anchor provider name (e.g. "opentimestamps", "git").
	Provider string `protobuf:"bytes,1,opt,name=provider,proto3" json:"provider,omitempty"`
	// external_id is the provider-specific anchor reference (e.g. Bitcoin tx hash).
	ExternalId string `protobuf:"bytes,2,opt,name=external_id,json=externalId,proto3" json:"external_id,omitempty"`
	// confirmation is the current confirmation state: "pending", "confirmed", or "finalized".
	Confirmation string `protobuf:"bytes,3,opt,name=confirmation,proto3" json:"confirmation,omitempty"`
	// anchored_at is the timestamp when the anchor was submitted (RFC3339).
	AnchoredAt string `protobuf:"bytes,4,opt,name=anchored_at,json=anchoredAt,proto3" json:"anchored_at,omitempty"`
	// contains filtered or unexported fields
}

AnchorRecord is a single anchor result.

func (*AnchorRecord) Descriptor deprecated

func (*AnchorRecord) Descriptor() ([]byte, []int)

Deprecated: Use AnchorRecord.ProtoReflect.Descriptor instead.

func (*AnchorRecord) GetAnchoredAt

func (x *AnchorRecord) GetAnchoredAt() string

func (*AnchorRecord) GetConfirmation

func (x *AnchorRecord) GetConfirmation() string

func (*AnchorRecord) GetExternalId

func (x *AnchorRecord) GetExternalId() string

func (*AnchorRecord) GetProvider

func (x *AnchorRecord) GetProvider() string

func (*AnchorRecord) ProtoMessage

func (*AnchorRecord) ProtoMessage()

func (*AnchorRecord) ProtoReflect

func (x *AnchorRecord) ProtoReflect() protoreflect.Message

func (*AnchorRecord) Reset

func (x *AnchorRecord) Reset()

func (*AnchorRecord) String

func (x *AnchorRecord) String() string

type AnchorRequest

type AnchorRequest struct {

	// ledger is the partition key.
	Ledger string `protobuf:"bytes,1,opt,name=ledger,proto3" json:"ledger,omitempty"`
	// start_sequence is the first entry covered by the anchor range (inclusive).
	StartSequence int64 `protobuf:"varint,2,opt,name=start_sequence,json=startSequence,proto3" json:"start_sequence,omitempty"`
	// end_sequence is the last entry covered by the anchor range (inclusive). 0 = latest.
	EndSequence int64 `protobuf:"varint,3,opt,name=end_sequence,json=endSequence,proto3" json:"end_sequence,omitempty"`
	// providers lists which anchor providers to use; empty = all configured providers.
	Providers []string `protobuf:"bytes,4,rep,name=providers,proto3" json:"providers,omitempty"`
	// contains filtered or unexported fields
}

AnchorRequest is the input for step.audit.anchor.

func (*AnchorRequest) Descriptor deprecated

func (*AnchorRequest) Descriptor() ([]byte, []int)

Deprecated: Use AnchorRequest.ProtoReflect.Descriptor instead.

func (*AnchorRequest) GetEndSequence

func (x *AnchorRequest) GetEndSequence() int64

func (*AnchorRequest) GetLedger

func (x *AnchorRequest) GetLedger() string

func (*AnchorRequest) GetProviders

func (x *AnchorRequest) GetProviders() []string

func (*AnchorRequest) GetStartSequence

func (x *AnchorRequest) GetStartSequence() int64

func (*AnchorRequest) ProtoMessage

func (*AnchorRequest) ProtoMessage()

func (*AnchorRequest) ProtoReflect

func (x *AnchorRequest) ProtoReflect() protoreflect.Message

func (*AnchorRequest) Reset

func (x *AnchorRequest) Reset()

func (*AnchorRequest) String

func (x *AnchorRequest) String() string

type AnchorResponse

type AnchorResponse struct {

	// anchors contains one record per provider that was anchored.
	Anchors []*AnchorRecord `protobuf:"bytes,1,rep,name=anchors,proto3" json:"anchors,omitempty"`
	// contains filtered or unexported fields
}

AnchorResponse is the output from step.audit.anchor.

func (*AnchorResponse) Descriptor deprecated

func (*AnchorResponse) Descriptor() ([]byte, []int)

Deprecated: Use AnchorResponse.ProtoReflect.Descriptor instead.

func (*AnchorResponse) GetAnchors

func (x *AnchorResponse) GetAnchors() []*AnchorRecord

func (*AnchorResponse) ProtoMessage

func (*AnchorResponse) ProtoMessage()

func (*AnchorResponse) ProtoReflect

func (x *AnchorResponse) ProtoReflect() protoreflect.Message

func (*AnchorResponse) Reset

func (x *AnchorResponse) Reset()

func (*AnchorResponse) String

func (x *AnchorResponse) String() string

type AppendRequest

type AppendRequest struct {

	// ledger is the partition key identifying which ledger to append to.
	Ledger string `protobuf:"bytes,1,opt,name=ledger,proto3" json:"ledger,omitempty"`
	// event_type is the application-defined event classification.
	EventType string `protobuf:"bytes,2,opt,name=event_type,json=eventType,proto3" json:"event_type,omitempty"`
	// payload is the canonical JSON (RFC 8785) bytes of the event data.
	Payload []byte `protobuf:"bytes,3,opt,name=payload,proto3" json:"payload,omitempty"`
	// actor is the application-defined identifier of who/what triggered the event.
	Actor string `protobuf:"bytes,4,opt,name=actor,proto3" json:"actor,omitempty"`
	// metadata is optional canonical JSON (RFC 8785) bytes for non-payload metadata.
	Metadata []byte `protobuf:"bytes,5,opt,name=metadata,proto3" json:"metadata,omitempty"`
	// contains filtered or unexported fields
}

AppendRequest is the input for step.audit.append.

func (*AppendRequest) Descriptor deprecated

func (*AppendRequest) Descriptor() ([]byte, []int)

Deprecated: Use AppendRequest.ProtoReflect.Descriptor instead.

func (*AppendRequest) GetActor

func (x *AppendRequest) GetActor() string

func (*AppendRequest) GetEventType

func (x *AppendRequest) GetEventType() string

func (*AppendRequest) GetLedger

func (x *AppendRequest) GetLedger() string

func (*AppendRequest) GetMetadata

func (x *AppendRequest) GetMetadata() []byte

func (*AppendRequest) GetPayload

func (x *AppendRequest) GetPayload() []byte

func (*AppendRequest) ProtoMessage

func (*AppendRequest) ProtoMessage()

func (*AppendRequest) ProtoReflect

func (x *AppendRequest) ProtoReflect() protoreflect.Message

func (*AppendRequest) Reset

func (x *AppendRequest) Reset()

func (*AppendRequest) String

func (x *AppendRequest) String() string

type AppendResponse

type AppendResponse struct {

	// sequence is the monotonic sequence number assigned to the new entry.
	Sequence int64 `protobuf:"varint,1,opt,name=sequence,proto3" json:"sequence,omitempty"`
	// entry_hash is the SHA256 hash of the new entry (hex-encoded).
	EntryHash string `protobuf:"bytes,2,opt,name=entry_hash,json=entryHash,proto3" json:"entry_hash,omitempty"`
	// created_at is the timestamp when the entry was appended (RFC3339).
	CreatedAt string `protobuf:"bytes,3,opt,name=created_at,json=createdAt,proto3" json:"created_at,omitempty"`
	// contains filtered or unexported fields
}

AppendResponse is the output from step.audit.append.

func (*AppendResponse) Descriptor deprecated

func (*AppendResponse) Descriptor() ([]byte, []int)

Deprecated: Use AppendResponse.ProtoReflect.Descriptor instead.

func (*AppendResponse) GetCreatedAt

func (x *AppendResponse) GetCreatedAt() string

func (*AppendResponse) GetEntryHash

func (x *AppendResponse) GetEntryHash() string

func (*AppendResponse) GetSequence

func (x *AppendResponse) GetSequence() int64

func (*AppendResponse) ProtoMessage

func (*AppendResponse) ProtoMessage()

func (*AppendResponse) ProtoReflect

func (x *AppendResponse) ProtoReflect() protoreflect.Message

func (*AppendResponse) Reset

func (x *AppendResponse) Reset()

func (*AppendResponse) String

func (x *AppendResponse) String() string

type Entry

type Entry struct {

	// sequence is the monotonic sequence number.
	Sequence int64 `protobuf:"varint,1,opt,name=sequence,proto3" json:"sequence,omitempty"`
	// ledger is the partition key.
	Ledger string `protobuf:"bytes,2,opt,name=ledger,proto3" json:"ledger,omitempty"`
	// event_type is the application-defined event classification.
	EventType string `protobuf:"bytes,3,opt,name=event_type,json=eventType,proto3" json:"event_type,omitempty"`
	// payload is the canonical JSON (RFC 8785) bytes of the event data.
	Payload []byte `protobuf:"bytes,4,opt,name=payload,proto3" json:"payload,omitempty"`
	// entry_hash is the SHA256 hash of this entry (hex-encoded).
	// Preimage: SHA256 of the RFC-8785 canonical JSON of the object
	//
	//	{ "sequence": <int64>, "ledger": <string>, "event_type": <string>,
	//	  "payload_hash": <hex-SHA256(canonical(payload))>,
	//	  "prev_entry_hash": <string>, "created_at": <RFC3339> }
	//
	// Keys sorted lexicographically, no whitespace. actor and metadata are NOT
	// included in the entry_hash preimage (they are stored but are not load-bearing
	// for chain integrity).
	EntryHash string `protobuf:"bytes,5,opt,name=entry_hash,json=entryHash,proto3" json:"entry_hash,omitempty"`
	// prev_entry_hash is the entry_hash of the preceding entry; empty string for the
	// genesis entry (sequence 1).
	PrevEntryHash string `protobuf:"bytes,6,opt,name=prev_entry_hash,json=prevEntryHash,proto3" json:"prev_entry_hash,omitempty"`
	// created_at is when this entry was appended (RFC3339).
	CreatedAt string `protobuf:"bytes,7,opt,name=created_at,json=createdAt,proto3" json:"created_at,omitempty"`
	// actor is the application-defined identifier of who/what triggered the event.
	// Stored for audit purposes; not included in the entry_hash preimage.
	Actor string `protobuf:"bytes,8,opt,name=actor,proto3" json:"actor,omitempty"`
	// metadata is the canonical JSON (RFC 8785) bytes for non-payload metadata;
	// empty if not set. Not included in the entry_hash preimage.
	Metadata []byte `protobuf:"bytes,9,opt,name=metadata,proto3" json:"metadata,omitempty"`
	// contains filtered or unexported fields
}

Entry is a single audit log entry.

func (*Entry) Descriptor deprecated

func (*Entry) Descriptor() ([]byte, []int)

Deprecated: Use Entry.ProtoReflect.Descriptor instead.

func (*Entry) GetActor

func (x *Entry) GetActor() string

func (*Entry) GetCreatedAt

func (x *Entry) GetCreatedAt() string

func (*Entry) GetEntryHash

func (x *Entry) GetEntryHash() string

func (*Entry) GetEventType

func (x *Entry) GetEventType() string

func (*Entry) GetLedger

func (x *Entry) GetLedger() string

func (*Entry) GetMetadata

func (x *Entry) GetMetadata() []byte

func (*Entry) GetPayload

func (x *Entry) GetPayload() []byte

func (*Entry) GetPrevEntryHash

func (x *Entry) GetPrevEntryHash() string

func (*Entry) GetSequence

func (x *Entry) GetSequence() int64

func (*Entry) ProtoMessage

func (*Entry) ProtoMessage()

func (*Entry) ProtoReflect

func (x *Entry) ProtoReflect() protoreflect.Message

func (*Entry) Reset

func (x *Entry) Reset()

func (*Entry) String

func (x *Entry) String() string

type GitAnchorProviderConfig

type GitAnchorProviderConfig struct {

	// remote is the git remote URL (file path, https, git+ssh, etc.). Required.
	Remote string `protobuf:"bytes,1,opt,name=remote,proto3" json:"remote,omitempty"`
	// branch is the branch to push anchors to. Defaults to "main".
	Branch string `protobuf:"bytes,2,opt,name=branch,proto3" json:"branch,omitempty"`
	// commit_template is a Go text/template string for the commit message.
	// Defaults to "anchor: {{.MerkleRoot}}".
	CommitTemplate string `protobuf:"bytes,3,opt,name=commit_template,json=commitTemplate,proto3" json:"commit_template,omitempty"`
	// author_name is the git commit author name. Defaults to "audit-chain-bot".
	AuthorName string `protobuf:"bytes,4,opt,name=author_name,json=authorName,proto3" json:"author_name,omitempty"`
	// author_email is the git commit author email. Defaults to "audit-chain-bot@localhost".
	AuthorEmail string `protobuf:"bytes,5,opt,name=author_email,json=authorEmail,proto3" json:"author_email,omitempty"`
	// use_ssh_agent uses the system SSH agent for authentication.
	UseSshAgent bool `protobuf:"varint,6,opt,name=use_ssh_agent,json=useSshAgent,proto3" json:"use_ssh_agent,omitempty"`
	// ssh_key_path is the path to a PEM-encoded private key file.
	SshKeyPath string `protobuf:"bytes,7,opt,name=ssh_key_path,json=sshKeyPath,proto3" json:"ssh_key_path,omitempty"`
	// ssh_key_password is the passphrase for the PEM key at ssh_key_path.
	SshKeyPassword string `protobuf:"bytes,8,opt,name=ssh_key_password,json=sshKeyPassword,proto3" json:"ssh_key_password,omitempty"`
	// http_username provides HTTP Basic Auth credentials for HTTPS remotes.
	HttpUsername string `protobuf:"bytes,9,opt,name=http_username,json=httpUsername,proto3" json:"http_username,omitempty"`
	// http_password provides HTTP Basic Auth credentials (or PAT) for HTTPS remotes.
	HttpPassword string `protobuf:"bytes,10,opt,name=http_password,json=httpPassword,proto3" json:"http_password,omitempty"`
	// contains filtered or unexported fields
}

GitAnchorProviderConfig is the typed config for audit.anchor_provider.git.

func (*GitAnchorProviderConfig) Descriptor deprecated

func (*GitAnchorProviderConfig) Descriptor() ([]byte, []int)

Deprecated: Use GitAnchorProviderConfig.ProtoReflect.Descriptor instead.

func (*GitAnchorProviderConfig) GetAuthorEmail

func (x *GitAnchorProviderConfig) GetAuthorEmail() string

func (*GitAnchorProviderConfig) GetAuthorName

func (x *GitAnchorProviderConfig) GetAuthorName() string

func (*GitAnchorProviderConfig) GetBranch

func (x *GitAnchorProviderConfig) GetBranch() string

func (*GitAnchorProviderConfig) GetCommitTemplate

func (x *GitAnchorProviderConfig) GetCommitTemplate() string

func (*GitAnchorProviderConfig) GetHttpPassword

func (x *GitAnchorProviderConfig) GetHttpPassword() string

func (*GitAnchorProviderConfig) GetHttpUsername

func (x *GitAnchorProviderConfig) GetHttpUsername() string

func (*GitAnchorProviderConfig) GetRemote

func (x *GitAnchorProviderConfig) GetRemote() string

func (*GitAnchorProviderConfig) GetSshKeyPassword

func (x *GitAnchorProviderConfig) GetSshKeyPassword() string

func (*GitAnchorProviderConfig) GetSshKeyPath

func (x *GitAnchorProviderConfig) GetSshKeyPath() string

func (*GitAnchorProviderConfig) GetUseSshAgent

func (x *GitAnchorProviderConfig) GetUseSshAgent() bool

func (*GitAnchorProviderConfig) ProtoMessage

func (*GitAnchorProviderConfig) ProtoMessage()

func (*GitAnchorProviderConfig) ProtoReflect

func (x *GitAnchorProviderConfig) ProtoReflect() protoreflect.Message

func (*GitAnchorProviderConfig) Reset

func (x *GitAnchorProviderConfig) Reset()

func (*GitAnchorProviderConfig) String

func (x *GitAnchorProviderConfig) String() string

type LedgerConfig

type LedgerConfig struct {

	// name is the partition key (e.g. "bmw-financial").
	Name string `protobuf:"bytes,1,opt,name=name,proto3" json:"name,omitempty"`
	// description is a human-readable description of the ledger's purpose.
	Description string `protobuf:"bytes,2,opt,name=description,proto3" json:"description,omitempty"`
	// anchor_providers lists the names of active anchor providers for this ledger.
	AnchorProviders []string `protobuf:"bytes,3,rep,name=anchor_providers,json=anchorProviders,proto3" json:"anchor_providers,omitempty"`
	// anchor_schedule is a cron expression controlling when Merkle roots are anchored.
	AnchorSchedule string `protobuf:"bytes,4,opt,name=anchor_schedule,json=anchorSchedule,proto3" json:"anchor_schedule,omitempty"`
	// anchor_min_entries is the minimum number of new entries required before anchoring.
	AnchorMinEntries int32 `protobuf:"varint,5,opt,name=anchor_min_entries,json=anchorMinEntries,proto3" json:"anchor_min_entries,omitempty"`
	// payload_schema is an optional JSON Schema (bytes) for payload validation at append time.
	PayloadSchema []byte `protobuf:"bytes,6,opt,name=payload_schema,json=payloadSchema,proto3" json:"payload_schema,omitempty"`
	// dsn is the PostgreSQL connection string for the backing store
	// (e.g. "postgres://user:pass@host/db?sslmode=disable").
	Dsn string `protobuf:"bytes,7,opt,name=dsn,proto3" json:"dsn,omitempty"`
	// contains filtered or unexported fields
}

LedgerConfig declares a ledger partition with its anchor provider config and scheduling parameters. Used by the audit.ledger module type.

func (*LedgerConfig) Descriptor deprecated

func (*LedgerConfig) Descriptor() ([]byte, []int)

Deprecated: Use LedgerConfig.ProtoReflect.Descriptor instead.

func (*LedgerConfig) GetAnchorMinEntries

func (x *LedgerConfig) GetAnchorMinEntries() int32

func (*LedgerConfig) GetAnchorProviders

func (x *LedgerConfig) GetAnchorProviders() []string

func (*LedgerConfig) GetAnchorSchedule

func (x *LedgerConfig) GetAnchorSchedule() string

func (*LedgerConfig) GetDescription

func (x *LedgerConfig) GetDescription() string

func (*LedgerConfig) GetDsn

func (x *LedgerConfig) GetDsn() string

func (*LedgerConfig) GetName

func (x *LedgerConfig) GetName() string

func (*LedgerConfig) GetPayloadSchema

func (x *LedgerConfig) GetPayloadSchema() []byte

func (*LedgerConfig) ProtoMessage

func (*LedgerConfig) ProtoMessage()

func (*LedgerConfig) ProtoReflect

func (x *LedgerConfig) ProtoReflect() protoreflect.Message

func (*LedgerConfig) Reset

func (x *LedgerConfig) Reset()

func (*LedgerConfig) String

func (x *LedgerConfig) String() string

type MerkleRootRequest

type MerkleRootRequest struct {

	// ledger is the partition key.
	Ledger string `protobuf:"bytes,1,opt,name=ledger,proto3" json:"ledger,omitempty"`
	// start_sequence is the first entry to include in the tree (inclusive).
	StartSequence int64 `protobuf:"varint,2,opt,name=start_sequence,json=startSequence,proto3" json:"start_sequence,omitempty"`
	// end_sequence is the last entry to include in the tree (inclusive). 0 = latest.
	EndSequence int64 `protobuf:"varint,3,opt,name=end_sequence,json=endSequence,proto3" json:"end_sequence,omitempty"`
	// contains filtered or unexported fields
}

MerkleRootRequest is the input for step.audit.merkle_root.

func (*MerkleRootRequest) Descriptor deprecated

func (*MerkleRootRequest) Descriptor() ([]byte, []int)

Deprecated: Use MerkleRootRequest.ProtoReflect.Descriptor instead.

func (*MerkleRootRequest) GetEndSequence

func (x *MerkleRootRequest) GetEndSequence() int64

func (*MerkleRootRequest) GetLedger

func (x *MerkleRootRequest) GetLedger() string

func (*MerkleRootRequest) GetStartSequence

func (x *MerkleRootRequest) GetStartSequence() int64

func (*MerkleRootRequest) ProtoMessage

func (*MerkleRootRequest) ProtoMessage()

func (*MerkleRootRequest) ProtoReflect

func (x *MerkleRootRequest) ProtoReflect() protoreflect.Message

func (*MerkleRootRequest) Reset

func (x *MerkleRootRequest) Reset()

func (*MerkleRootRequest) String

func (x *MerkleRootRequest) String() string

type MerkleRootResponse

type MerkleRootResponse struct {

	// root is the hex-encoded Merkle root hash over entry_hashes in the range.
	Root string `protobuf:"bytes,1,opt,name=root,proto3" json:"root,omitempty"`
	// entries_included is the count of entries included in the tree.
	EntriesIncluded int64 `protobuf:"varint,2,opt,name=entries_included,json=entriesIncluded,proto3" json:"entries_included,omitempty"`
	// start_sequence is the first sequence included in the tree (echoed from request).
	StartSequence int64 `protobuf:"varint,3,opt,name=start_sequence,json=startSequence,proto3" json:"start_sequence,omitempty"`
	// end_sequence is the last sequence included in the tree (the resolved value; useful
	// when the request used 0 = latest).
	EndSequence int64 `protobuf:"varint,4,opt,name=end_sequence,json=endSequence,proto3" json:"end_sequence,omitempty"`
	// contains filtered or unexported fields
}

MerkleRootResponse is the output from step.audit.merkle_root.

func (*MerkleRootResponse) Descriptor deprecated

func (*MerkleRootResponse) Descriptor() ([]byte, []int)

Deprecated: Use MerkleRootResponse.ProtoReflect.Descriptor instead.

func (*MerkleRootResponse) GetEndSequence

func (x *MerkleRootResponse) GetEndSequence() int64

func (*MerkleRootResponse) GetEntriesIncluded

func (x *MerkleRootResponse) GetEntriesIncluded() int64

func (*MerkleRootResponse) GetRoot

func (x *MerkleRootResponse) GetRoot() string

func (*MerkleRootResponse) GetStartSequence

func (x *MerkleRootResponse) GetStartSequence() int64

func (*MerkleRootResponse) ProtoMessage

func (*MerkleRootResponse) ProtoMessage()

func (*MerkleRootResponse) ProtoReflect

func (x *MerkleRootResponse) ProtoReflect() protoreflect.Message

func (*MerkleRootResponse) Reset

func (x *MerkleRootResponse) Reset()

func (*MerkleRootResponse) String

func (x *MerkleRootResponse) String() string

type OpenTimestampsProviderConfig

type OpenTimestampsProviderConfig struct {

	// calendar_servers lists the OTS calendar server base URLs to submit to.
	// At least one is required.
	CalendarServers []string `protobuf:"bytes,1,rep,name=calendar_servers,json=calendarServers,proto3" json:"calendar_servers,omitempty"`
	// http_timeout_ms is the per-request HTTP timeout in milliseconds.
	// 0 means use the default (30 000 ms).
	HttpTimeoutMs int64 `protobuf:"varint,2,opt,name=http_timeout_ms,json=httpTimeoutMs,proto3" json:"http_timeout_ms,omitempty"`
	// contains filtered or unexported fields
}

OpenTimestampsProviderConfig is the typed config for audit.anchor_provider.opentimestamps.

func (*OpenTimestampsProviderConfig) Descriptor deprecated

func (*OpenTimestampsProviderConfig) Descriptor() ([]byte, []int)

Deprecated: Use OpenTimestampsProviderConfig.ProtoReflect.Descriptor instead.

func (*OpenTimestampsProviderConfig) GetCalendarServers

func (x *OpenTimestampsProviderConfig) GetCalendarServers() []string

func (*OpenTimestampsProviderConfig) GetHttpTimeoutMs

func (x *OpenTimestampsProviderConfig) GetHttpTimeoutMs() int64

func (*OpenTimestampsProviderConfig) ProtoMessage

func (*OpenTimestampsProviderConfig) ProtoMessage()

func (*OpenTimestampsProviderConfig) ProtoReflect

func (*OpenTimestampsProviderConfig) Reset

func (x *OpenTimestampsProviderConfig) Reset()

func (*OpenTimestampsProviderConfig) String

type PollAnchorConfirmationConfig added in v0.2.2

type PollAnchorConfirmationConfig struct {

	// anchor_id is the audit_anchors.id (BIGSERIAL, passed as string) of the pending anchor row.
	AnchorId string `protobuf:"bytes,1,opt,name=anchor_id,json=anchorId,proto3" json:"anchor_id,omitempty"`
	// provider is the anchor provider name stored in audit_anchors.provider.
	Provider string `protobuf:"bytes,2,opt,name=provider,proto3" json:"provider,omitempty"`
	// external_id is the provider's anchor reference stored in audit_anchors.external_id.
	ExternalId string `protobuf:"bytes,3,opt,name=external_id,json=externalId,proto3" json:"external_id,omitempty"`
	// proof_data is the opaque provider-specific proof bytes stored in audit_anchors.proof_data.
	//
	// Declared as string (not bytes) because BMW-style YAML pipelines populate
	// this field via a Go template (`"{{ .item.proof_data }}"`) that renders as
	// a raw string. proto3 JSON encoding requires `bytes` fields to be
	// base64-encoded; BMW does not base64-encode, so a `bytes` field would be
	// rejected at the strict-proto boundary (v0.51.5 regression discovered by
	// BMW local smoke). The handler is responsible for decoding from string to
	// bytes if a provider requires raw proof bytes — current providers treat
	// proof_data as an opaque pass-through so no decoding is applied.
	ProofData string `protobuf:"bytes,4,opt,name=proof_data,json=proofData,proto3" json:"proof_data,omitempty"`
	// ledger identifies which ledger's DB handle to use when updating
	// audit_anchors.confirmation after a status change.
	Ledger string `protobuf:"bytes,5,opt,name=ledger,proto3" json:"ledger,omitempty"`
	// contains filtered or unexported fields
}

PollAnchorConfirmationConfig is the YAML config for step.audit.poll_anchor_confirmation. All fields are supplied via the pipeline step's `config:` block; the engine resolves templates against `pc.Current` before dispatching the step. Mirrors PollAnchorConfirmationRequest one-to-one; kept as a separate Config message so STRICT_PROTO validation does not reject YAML keys against the Empty config previously declared.

func (*PollAnchorConfirmationConfig) Descriptor deprecated added in v0.2.2

func (*PollAnchorConfirmationConfig) Descriptor() ([]byte, []int)

Deprecated: Use PollAnchorConfirmationConfig.ProtoReflect.Descriptor instead.

func (*PollAnchorConfirmationConfig) GetAnchorId added in v0.2.2

func (x *PollAnchorConfirmationConfig) GetAnchorId() string

func (*PollAnchorConfirmationConfig) GetExternalId added in v0.2.2

func (x *PollAnchorConfirmationConfig) GetExternalId() string

func (*PollAnchorConfirmationConfig) GetLedger added in v0.2.2

func (x *PollAnchorConfirmationConfig) GetLedger() string

func (*PollAnchorConfirmationConfig) GetProofData added in v0.2.2

func (x *PollAnchorConfirmationConfig) GetProofData() string

func (*PollAnchorConfirmationConfig) GetProvider added in v0.2.2

func (x *PollAnchorConfirmationConfig) GetProvider() string

func (*PollAnchorConfirmationConfig) ProtoMessage added in v0.2.2

func (*PollAnchorConfirmationConfig) ProtoMessage()

func (*PollAnchorConfirmationConfig) ProtoReflect added in v0.2.2

func (*PollAnchorConfirmationConfig) Reset added in v0.2.2

func (x *PollAnchorConfirmationConfig) Reset()

func (*PollAnchorConfirmationConfig) String added in v0.2.2

type PollAnchorConfirmationRequest

type PollAnchorConfirmationRequest struct {

	// anchor_id is the audit_anchors.id (BIGSERIAL, passed as string) of the pending anchor row.
	AnchorId string `protobuf:"bytes,1,opt,name=anchor_id,json=anchorId,proto3" json:"anchor_id,omitempty"`
	// provider is the anchor provider name stored in audit_anchors.provider.
	Provider string `protobuf:"bytes,2,opt,name=provider,proto3" json:"provider,omitempty"`
	// external_id is the provider's anchor reference stored in audit_anchors.external_id.
	ExternalId string `protobuf:"bytes,3,opt,name=external_id,json=externalId,proto3" json:"external_id,omitempty"`
	// proof_data is the opaque provider-specific proof bytes stored in audit_anchors.proof_data.
	ProofData []byte `protobuf:"bytes,4,opt,name=proof_data,json=proofData,proto3" json:"proof_data,omitempty"`
	// ledger identifies which ledger's DB handle to use when updating
	// audit_anchors.confirmation after a status change.
	Ledger string `protobuf:"bytes,5,opt,name=ledger,proto3" json:"ledger,omitempty"`
	// contains filtered or unexported fields
}

PollAnchorConfirmationRequest is the input for step.audit.poll_anchor_confirmation. Used by the periodic confirmation cron (e.g. OpenTimestamps may take hours-to-days to finalize on Bitcoin).

func (*PollAnchorConfirmationRequest) Descriptor deprecated

func (*PollAnchorConfirmationRequest) Descriptor() ([]byte, []int)

Deprecated: Use PollAnchorConfirmationRequest.ProtoReflect.Descriptor instead.

func (*PollAnchorConfirmationRequest) GetAnchorId

func (x *PollAnchorConfirmationRequest) GetAnchorId() string

func (*PollAnchorConfirmationRequest) GetExternalId

func (x *PollAnchorConfirmationRequest) GetExternalId() string

func (*PollAnchorConfirmationRequest) GetLedger

func (x *PollAnchorConfirmationRequest) GetLedger() string

func (*PollAnchorConfirmationRequest) GetProofData

func (x *PollAnchorConfirmationRequest) GetProofData() []byte

func (*PollAnchorConfirmationRequest) GetProvider

func (x *PollAnchorConfirmationRequest) GetProvider() string

func (*PollAnchorConfirmationRequest) ProtoMessage

func (*PollAnchorConfirmationRequest) ProtoMessage()

func (*PollAnchorConfirmationRequest) ProtoReflect

func (*PollAnchorConfirmationRequest) Reset

func (x *PollAnchorConfirmationRequest) Reset()

func (*PollAnchorConfirmationRequest) String

type PollAnchorConfirmationResponse

type PollAnchorConfirmationResponse struct {

	// previous_confirmation is the confirmation state before this poll.
	PreviousConfirmation string `protobuf:"bytes,1,opt,name=previous_confirmation,json=previousConfirmation,proto3" json:"previous_confirmation,omitempty"`
	// current_confirmation is the confirmation state after this poll.
	CurrentConfirmation string `protobuf:"bytes,2,opt,name=current_confirmation,json=currentConfirmation,proto3" json:"current_confirmation,omitempty"`
	// transitioned is true if the confirmation level advanced during this poll.
	Transitioned bool `protobuf:"varint,3,opt,name=transitioned,proto3" json:"transitioned,omitempty"`
	// updated_at is the timestamp of the poll (RFC3339).
	UpdatedAt string `protobuf:"bytes,4,opt,name=updated_at,json=updatedAt,proto3" json:"updated_at,omitempty"`
	// swallowed is true when a transient error was encountered but suppressed.
	Swallowed bool `protobuf:"varint,5,opt,name=swallowed,proto3" json:"swallowed,omitempty"`
	// error_message is populated when swallowed = true, describing the transient error.
	ErrorMessage string `protobuf:"bytes,6,opt,name=error_message,json=errorMessage,proto3" json:"error_message,omitempty"`
	// contains filtered or unexported fields
}

PollAnchorConfirmationResponse is the output from step.audit.poll_anchor_confirmation.

Transient errors (calendar-server unreachable, network partition) MUST be returned as a successful response with current_confirmation = previous_confirmation, transitioned = false, swallowed = true, and error_message populated. Hard errors (invalid proof, malformed payload) return a gRPC error and abort the step. This contract lets cron-audit-anchor-confirm continue iterating across pending anchors when one calendar server is temporarily down.

func (*PollAnchorConfirmationResponse) Descriptor deprecated

func (*PollAnchorConfirmationResponse) Descriptor() ([]byte, []int)

Deprecated: Use PollAnchorConfirmationResponse.ProtoReflect.Descriptor instead.

func (*PollAnchorConfirmationResponse) GetCurrentConfirmation

func (x *PollAnchorConfirmationResponse) GetCurrentConfirmation() string

func (*PollAnchorConfirmationResponse) GetErrorMessage

func (x *PollAnchorConfirmationResponse) GetErrorMessage() string

func (*PollAnchorConfirmationResponse) GetPreviousConfirmation

func (x *PollAnchorConfirmationResponse) GetPreviousConfirmation() string

func (*PollAnchorConfirmationResponse) GetSwallowed

func (x *PollAnchorConfirmationResponse) GetSwallowed() bool

func (*PollAnchorConfirmationResponse) GetTransitioned

func (x *PollAnchorConfirmationResponse) GetTransitioned() bool

func (*PollAnchorConfirmationResponse) GetUpdatedAt

func (x *PollAnchorConfirmationResponse) GetUpdatedAt() string

func (*PollAnchorConfirmationResponse) ProtoMessage

func (*PollAnchorConfirmationResponse) ProtoMessage()

func (*PollAnchorConfirmationResponse) ProtoReflect

func (*PollAnchorConfirmationResponse) Reset

func (x *PollAnchorConfirmationResponse) Reset()

func (*PollAnchorConfirmationResponse) String

type ProofRequest

type ProofRequest struct {

	// ledger is the partition key.
	Ledger string `protobuf:"bytes,1,opt,name=ledger,proto3" json:"ledger,omitempty"`
	// sequence is the entry sequence number for which to generate the proof.
	Sequence int64 `protobuf:"varint,2,opt,name=sequence,proto3" json:"sequence,omitempty"`
	// contains filtered or unexported fields
}

ProofRequest is the input for step.audit.proof.

func (*ProofRequest) Descriptor deprecated

func (*ProofRequest) Descriptor() ([]byte, []int)

Deprecated: Use ProofRequest.ProtoReflect.Descriptor instead.

func (*ProofRequest) GetLedger

func (x *ProofRequest) GetLedger() string

func (*ProofRequest) GetSequence

func (x *ProofRequest) GetSequence() int64

func (*ProofRequest) ProtoMessage

func (*ProofRequest) ProtoMessage()

func (*ProofRequest) ProtoReflect

func (x *ProofRequest) ProtoReflect() protoreflect.Message

func (*ProofRequest) Reset

func (x *ProofRequest) Reset()

func (*ProofRequest) String

func (x *ProofRequest) String() string

type ProofResponse

type ProofResponse struct {

	// entry is the full audit log entry at the requested sequence.
	Entry *Entry `protobuf:"bytes,1,opt,name=entry,proto3" json:"entry,omitempty"`
	// merkle_path is the Merkle inclusion proof (list of hex-encoded sibling hashes).
	MerklePath []string `protobuf:"bytes,2,rep,name=merkle_path,json=merklePath,proto3" json:"merkle_path,omitempty"`
	// merkle_root is the hex-encoded Merkle root of the tree that contains this entry.
	MerkleRoot string `protobuf:"bytes,3,opt,name=merkle_root,json=merkleRoot,proto3" json:"merkle_root,omitempty"`
	// anchors lists all anchor records whose range covers this entry's sequence.
	Anchors []*AnchorRecord `protobuf:"bytes,4,rep,name=anchors,proto3" json:"anchors,omitempty"`
	// contains filtered or unexported fields
}

ProofResponse is the output from step.audit.proof.

func (*ProofResponse) Descriptor deprecated

func (*ProofResponse) Descriptor() ([]byte, []int)

Deprecated: Use ProofResponse.ProtoReflect.Descriptor instead.

func (*ProofResponse) GetAnchors

func (x *ProofResponse) GetAnchors() []*AnchorRecord

func (*ProofResponse) GetEntry

func (x *ProofResponse) GetEntry() *Entry

func (*ProofResponse) GetMerklePath

func (x *ProofResponse) GetMerklePath() []string

func (*ProofResponse) GetMerkleRoot

func (x *ProofResponse) GetMerkleRoot() string

func (*ProofResponse) ProtoMessage

func (*ProofResponse) ProtoMessage()

func (*ProofResponse) ProtoReflect

func (x *ProofResponse) ProtoReflect() protoreflect.Message

func (*ProofResponse) Reset

func (x *ProofResponse) Reset()

func (*ProofResponse) String

func (x *ProofResponse) String() string

type PublicReceiptConfig added in v0.2.2

type PublicReceiptConfig struct {

	// ledger is the partition key.
	Ledger string `protobuf:"bytes,1,opt,name=ledger,proto3" json:"ledger,omitempty"`
	// sequence is the entry sequence number for which to generate the public receipt.
	//
	// Declared as string (not int64) because BMW-style YAML pipelines populate
	// this field via a Go template (`"{{ .item.audit_sequence }}"`) that renders
	// as a raw string. Even with the engine's scalar-coerce in workflow v0.51.5,
	// the strict-proto decoder rejects string→int64 coercion at the typed-config
	// boundary (regression discovered by BMW local smoke). The handler parses
	// this string to int64 internally for DB lookup.
	Sequence string `protobuf:"bytes,2,opt,name=sequence,proto3" json:"sequence,omitempty"`
	// redact_fields lists JSON paths in payload to redact with stable per-receipt
	// pseudonyms (e.g. ["contributor_user_id"]). The redacted-payload + pseudonym
	// mapping is included in the receipt; the entry_hash remains verifiable.
	RedactFields []string `protobuf:"bytes,3,rep,name=redact_fields,json=redactFields,proto3" json:"redact_fields,omitempty"`
	// contains filtered or unexported fields
}

PublicReceiptConfig is the YAML config for step.audit.public_receipt. All fields are supplied via the pipeline step's `config:` block; the engine resolves templates against `pc.Current` before dispatching the step. Mirrors PublicReceiptRequest one-to-one; kept as a separate Config message so STRICT_PROTO validation does not reject YAML keys against the Empty config previously declared.

func (*PublicReceiptConfig) Descriptor deprecated added in v0.2.2

func (*PublicReceiptConfig) Descriptor() ([]byte, []int)

Deprecated: Use PublicReceiptConfig.ProtoReflect.Descriptor instead.

func (*PublicReceiptConfig) GetLedger added in v0.2.2

func (x *PublicReceiptConfig) GetLedger() string

func (*PublicReceiptConfig) GetRedactFields added in v0.2.2

func (x *PublicReceiptConfig) GetRedactFields() []string

func (*PublicReceiptConfig) GetSequence added in v0.2.2

func (x *PublicReceiptConfig) GetSequence() string

func (*PublicReceiptConfig) ProtoMessage added in v0.2.2

func (*PublicReceiptConfig) ProtoMessage()

func (*PublicReceiptConfig) ProtoReflect added in v0.2.2

func (x *PublicReceiptConfig) ProtoReflect() protoreflect.Message

func (*PublicReceiptConfig) Reset added in v0.2.2

func (x *PublicReceiptConfig) Reset()

func (*PublicReceiptConfig) String added in v0.2.2

func (x *PublicReceiptConfig) String() string

type PublicReceiptRequest

type PublicReceiptRequest struct {

	// ledger is the partition key.
	Ledger string `protobuf:"bytes,1,opt,name=ledger,proto3" json:"ledger,omitempty"`
	// sequence is the entry sequence number for which to generate the public receipt.
	Sequence int64 `protobuf:"varint,2,opt,name=sequence,proto3" json:"sequence,omitempty"`
	// redact_fields lists JSON paths in payload to redact with stable per-receipt
	// pseudonyms (e.g. ["contributor_user_id"]). The redacted-payload + pseudonym
	// mapping is included in the receipt; the entry_hash remains verifiable.
	RedactFields []string `protobuf:"bytes,3,rep,name=redact_fields,json=redactFields,proto3" json:"redact_fields,omitempty"`
	// contains filtered or unexported fields
}

PublicReceiptRequest is the input for step.audit.public_receipt.

func (*PublicReceiptRequest) Descriptor deprecated

func (*PublicReceiptRequest) Descriptor() ([]byte, []int)

Deprecated: Use PublicReceiptRequest.ProtoReflect.Descriptor instead.

func (*PublicReceiptRequest) GetLedger

func (x *PublicReceiptRequest) GetLedger() string

func (*PublicReceiptRequest) GetRedactFields

func (x *PublicReceiptRequest) GetRedactFields() []string

func (*PublicReceiptRequest) GetSequence

func (x *PublicReceiptRequest) GetSequence() int64

func (*PublicReceiptRequest) ProtoMessage

func (*PublicReceiptRequest) ProtoMessage()

func (*PublicReceiptRequest) ProtoReflect

func (x *PublicReceiptRequest) ProtoReflect() protoreflect.Message

func (*PublicReceiptRequest) Reset

func (x *PublicReceiptRequest) Reset()

func (*PublicReceiptRequest) String

func (x *PublicReceiptRequest) String() string

type PublicReceiptResponse

type PublicReceiptResponse struct {

	// receipt_url is the canonical URL where the receipt JSON is served.
	ReceiptUrl string `protobuf:"bytes,1,opt,name=receipt_url,json=receiptUrl,proto3" json:"receipt_url,omitempty"`
	// receipt_json is the full verifiable receipt JSON string (entry + proof + anchors + pseudonym map).
	ReceiptJson string `protobuf:"bytes,2,opt,name=receipt_json,json=receiptJson,proto3" json:"receipt_json,omitempty"`
	// receipt_hash is the SHA256 hash of receipt_json (hex-encoded).
	ReceiptHash string `protobuf:"bytes,3,opt,name=receipt_hash,json=receiptHash,proto3" json:"receipt_hash,omitempty"`
	// contains filtered or unexported fields
}

PublicReceiptResponse is the output from step.audit.public_receipt.

func (*PublicReceiptResponse) Descriptor deprecated

func (*PublicReceiptResponse) Descriptor() ([]byte, []int)

Deprecated: Use PublicReceiptResponse.ProtoReflect.Descriptor instead.

func (*PublicReceiptResponse) GetReceiptHash

func (x *PublicReceiptResponse) GetReceiptHash() string

func (*PublicReceiptResponse) GetReceiptJson

func (x *PublicReceiptResponse) GetReceiptJson() string

func (*PublicReceiptResponse) GetReceiptUrl

func (x *PublicReceiptResponse) GetReceiptUrl() string

func (*PublicReceiptResponse) ProtoMessage

func (*PublicReceiptResponse) ProtoMessage()

func (*PublicReceiptResponse) ProtoReflect

func (x *PublicReceiptResponse) ProtoReflect() protoreflect.Message

func (*PublicReceiptResponse) Reset

func (x *PublicReceiptResponse) Reset()

func (*PublicReceiptResponse) String

func (x *PublicReceiptResponse) String() string

type SigstoreProviderConfig

type SigstoreProviderConfig struct {

	// rekor_url is the base URL of the Rekor instance.
	// Defaults to "https://rekor.sigstore.dev" when empty.
	RekorUrl string `protobuf:"bytes,1,opt,name=rekor_url,json=rekorUrl,proto3" json:"rekor_url,omitempty"`
	// contains filtered or unexported fields
}

SigstoreProviderConfig is the typed config for audit.anchor_provider.sigstore.

func (*SigstoreProviderConfig) Descriptor deprecated

func (*SigstoreProviderConfig) Descriptor() ([]byte, []int)

Deprecated: Use SigstoreProviderConfig.ProtoReflect.Descriptor instead.

func (*SigstoreProviderConfig) GetRekorUrl

func (x *SigstoreProviderConfig) GetRekorUrl() string

func (*SigstoreProviderConfig) ProtoMessage

func (*SigstoreProviderConfig) ProtoMessage()

func (*SigstoreProviderConfig) ProtoReflect

func (x *SigstoreProviderConfig) ProtoReflect() protoreflect.Message

func (*SigstoreProviderConfig) Reset

func (x *SigstoreProviderConfig) Reset()

func (*SigstoreProviderConfig) String

func (x *SigstoreProviderConfig) String() string

type VerifyRequest

type VerifyRequest struct {

	// ledger is the partition key to verify.
	Ledger string `protobuf:"bytes,1,opt,name=ledger,proto3" json:"ledger,omitempty"`
	// start_sequence is the first sequence number to verify (inclusive).
	StartSequence int64 `protobuf:"varint,2,opt,name=start_sequence,json=startSequence,proto3" json:"start_sequence,omitempty"`
	// end_sequence is the last sequence number to verify (inclusive). 0 = latest.
	EndSequence int64 `protobuf:"varint,3,opt,name=end_sequence,json=endSequence,proto3" json:"end_sequence,omitempty"`
	// contains filtered or unexported fields
}

VerifyRequest is the input for step.audit.verify.

func (*VerifyRequest) Descriptor deprecated

func (*VerifyRequest) Descriptor() ([]byte, []int)

Deprecated: Use VerifyRequest.ProtoReflect.Descriptor instead.

func (*VerifyRequest) GetEndSequence

func (x *VerifyRequest) GetEndSequence() int64

func (*VerifyRequest) GetLedger

func (x *VerifyRequest) GetLedger() string

func (*VerifyRequest) GetStartSequence

func (x *VerifyRequest) GetStartSequence() int64

func (*VerifyRequest) ProtoMessage

func (*VerifyRequest) ProtoMessage()

func (*VerifyRequest) ProtoReflect

func (x *VerifyRequest) ProtoReflect() protoreflect.Message

func (*VerifyRequest) Reset

func (x *VerifyRequest) Reset()

func (*VerifyRequest) String

func (x *VerifyRequest) String() string

type VerifyResponse

type VerifyResponse struct {

	// valid is true if the chain is intact over the verified range.
	Valid bool `protobuf:"varint,1,opt,name=valid,proto3" json:"valid,omitempty"`
	// first_invalid_sequence is the sequence number of the first broken entry; 0 if valid.
	FirstInvalidSequence int64 `protobuf:"varint,2,opt,name=first_invalid_sequence,json=firstInvalidSequence,proto3" json:"first_invalid_sequence,omitempty"`
	// failure_reason describes why the chain is broken; empty if valid.
	FailureReason string `protobuf:"bytes,3,opt,name=failure_reason,json=failureReason,proto3" json:"failure_reason,omitempty"`
	// entries_verified is the number of entries that were checked.
	EntriesVerified int64 `protobuf:"varint,4,opt,name=entries_verified,json=entriesVerified,proto3" json:"entries_verified,omitempty"`
	// contains filtered or unexported fields
}

VerifyResponse is the output from step.audit.verify.

func (*VerifyResponse) Descriptor deprecated

func (*VerifyResponse) Descriptor() ([]byte, []int)

Deprecated: Use VerifyResponse.ProtoReflect.Descriptor instead.

func (*VerifyResponse) GetEntriesVerified

func (x *VerifyResponse) GetEntriesVerified() int64

func (*VerifyResponse) GetFailureReason

func (x *VerifyResponse) GetFailureReason() string

func (*VerifyResponse) GetFirstInvalidSequence

func (x *VerifyResponse) GetFirstInvalidSequence() int64

func (*VerifyResponse) GetValid

func (x *VerifyResponse) GetValid() bool

func (*VerifyResponse) ProtoMessage

func (*VerifyResponse) ProtoMessage()

func (*VerifyResponse) ProtoReflect

func (x *VerifyResponse) ProtoReflect() protoreflect.Message

func (*VerifyResponse) Reset

func (x *VerifyResponse) Reset()

func (*VerifyResponse) String

func (x *VerifyResponse) String() string

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL