internal/

directory
v0.8.4 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 9, 2026 License: Apache-2.0

Directories

Path Synopsis
Background password-expiry sweep, wired in serve.
Background password-expiry sweep, wired in serve.
Package activity merges alerts + transactions + intelligence_events + audit_events into a single time-ordered feed, with per-source RBAC and seek-cursor pagination.
Package activity merges alerts + transactions + intelligence_events + audit_events into a single time-ordered feed, with per-source RBAC and seek-cursor pagination.
Package alertrouter is the bridge between OpenWatch's in-process event bus (internal/eventbus) and external notification channels (Slack, email, webhook, PagerDuty).
Package alertrouter is the bridge between OpenWatch's in-process event bus (internal/eventbus) and external notification channels (Slack, email, webhook, PagerDuty).
channels/stdout
Package stdout implements an alertrouter.Channel that logs alerts to the structured slog default logger at INFO level.
Package stdout implements an alertrouter.Channel that logs alerts to the structured slog default logger at INFO level.
Package alerts owns the lifecycle service for persisted alerts — acknowledge / silence / resolve / dismiss transitions plus the auto-resolve hook that closes host_unreachable when host_recovered arrives.
Package alerts owns the lifecycle service for persisted alerts — acknowledge / silence / resolve / dismiss transitions plus the auto-resolve hook that closes host_unreachable when host_recovered arrives.
Package apitoken manages API service-account tokens for automation (CI, scripts) that call the REST API without an interactive session.
Package apitoken manages API service-account tokens for automation (CI, scripts) that call the REST API without an interactive session.
Package audit emits and stores audit events per the contract in docs/engineering/audit_event_taxonomy.md and specs/system/audit-emission.spec.yaml.
Package audit emits and stores audit events per the contract in docs/engineering/audit_event_taxonomy.md and specs/system/audit-emission.spec.yaml.
Package auth provides RBAC: a codegen-typed permission registry, built-in roles, and the RequirePermission middleware that combines RBAC and license-gate checks in one pass.
Package auth provides RBAC: a codegen-typed permission registry, built-in roles, and the RequirePermission middleware that combines RBAC and license-gate checks in one pass.
Package authpolicy manages the workspace-wide authentication policy: the require-MFA flag and the session idle/absolute timeout windows.
Package authpolicy manages the workspace-wide authentication policy: the require-MFA flag and the session idle/absolute timeout windows.
Package compliance owns the single definition of a compliance score.
Package compliance owns the single definition of a compliance score.
Package config loads OpenWatch runtime configuration.
Package config loads OpenWatch runtime configuration.
Package connprofile is the per-host "last known good" SSH connection memory shared by every path that talks to a managed host (the liveness privilege probe, OS discovery, OS intelligence collection, and the compliance scan).
Package connprofile is the per-host "last known good" SSH connection memory shared by every path that talks to a managed host (the liveness privilege probe, OS discovery, OS intelligence collection, and the compliance scan).
Package corpus defines which host_rule_state rows still count.
Package corpus defines which host_rule_state rows still count.
Package correlation propagates a request-scoped correlation ID across HTTP entry, audit emission, log lines, and outbound calls.
Package correlation propagates a request-scoped correlation ID across HTTP entry, audit emission, log lines, and outbound calls.
Package credential owns SSH credential storage and the system→host resolver.
Package credential owns SSH credential storage and the system→host resolver.
Package cron is the minimal Stage-0 cron scheduler.
Package cron is the minimal Stage-0 cron scheduler.
db
Package db owns PostgreSQL connectivity for the openwatch binary.
Package db owns PostgreSQL connectivity for the openwatch binary.
corpustest
Package corpustest seeds host_rule_state rows that are actually IN a host's current corpus.
Package corpustest seeds host_rule_state rows that are actually IN a host's current corpus.
dbtest
Package dbtest gives each test BINARY (i.e.
Package dbtest gives each test BINARY (i.e.
migrations
Package migrations embeds the SQL migration files and exposes the goose runner that applies them.
Package migrations embeds the SQL migration files and exposes the goose runner that applies them.
Package dbbackup creates a plain-SQL pg_dump of the OpenWatch database, used as the pre-upgrade restore point before migrations run.
Package dbbackup creates a plain-SQL pg_dump of the OpenWatch database, used as the pre-upgrade restore point before migrations run.
Package drift implements OpenWatch's compliance drift detector.
Package drift implements OpenWatch's compliance drift detector.
Package eventbus implements OpenWatch's in-process typed pub/sub.
Package eventbus implements OpenWatch's in-process typed pub/sub.
Background expiry sweep, wired in serve.
Background expiry sweep, wired in serve.
Package fleetrollup answers "how is my fleet doing right now?" via read-only aggregations over the Slice B persistence layer (host_rule_state, transactions, host_liveness).
Package fleetrollup answers "how is my fleet doing right now?" via read-only aggregations over the Slice B persistence layer (host_rule_state, transactions, host_liveness).
Package framework groups the corpus's per-rule framework reference keys (host_rule_state.framework_refs) into user-facing FAMILIES and lists them for the "default compliance lens" picker.
Package framework groups the corpus's per-rule framework reference keys (host_rule_state.framework_refs) into user-facing FAMILIES and lists them for the "default compliance lens" picker.
Package group implements host groups: operator-curated SITES (manual membership) and OS CATEGORIES (auto membership derived from hosts.os_family, or manual workload groups).
Package group implements host groups: operator-curated SITES (manual membership) and OS CATEGORIES (auto membership derived from hosts.os_family, or manual workload groups).
Package host owns the hosts table — the inventory of machines the platform can talk to.
Package host owns the hosts table — the inventory of machines the platform can talk to.
Package httpclient is the outbound HTTP wrapper that forwards the correlation ID from request context as X-Correlation-Id on every call.
Package httpclient is the outbound HTTP wrapper that forwards the correlation ID from request context as X-Correlation-Id on every call.
Package idempotency provides the middleware that makes mutating HTTP requests safely retryable.
Package idempotency provides the middleware that makes mutating HTTP requests safely retryable.
Package identity owns the auth primitives: password hashing (Argon2id), NIST SP 800-63B password-policy validation, breach-corpus checking, session token lifecycle, RS256 JWT mint/verify, and TOTP MFA.
Package identity owns the auth primitives: password hashing (Argon2id), NIST SP 800-63B password-policy validation, breach-corpus checking, session token lifecycle, RS256 JWT mint/verify, and TOTP MFA.
intelligence
collector
Package collector implements OS Intelligence — the recurring, write-on-change counterpart to OS Discovery.
Package collector implements OS Intelligence — the recurring, write-on-change counterpart to OS Discovery.
discovery
Package discovery owns the one-shot SSH OS-fingerprint flow that captures os_family, os_version, kernel, architecture, hostname / FQDN, SELinux + AppArmor + firewall posture, and a hardware summary for each host on first contact + on-demand.
Package discovery owns the one-shot SSH OS-fingerprint flow that captures os_family, os_version, kernel, architecture, hostname / FQDN, SELinux + AppArmor + firewall posture, and a hardware summary for each host on first contact + on-demand.
discovery/scheduler
Package scheduler is the recurring driver for OS discovery — the loop that finds hosts whose hosts.os_discovered_at column is stale (NULL or older than the policy interval) and enqueues host.discovery jobs through internal/queue so the worker pool picks them up and runs discovery.Service.Discover on them.
Package scheduler is the recurring driver for OS discovery — the loop that finds hosts whose hosts.os_discovered_at column is stale (NULL or older than the policy interval) and enqueues host.discovery jobs through internal/queue so the worker pool picks them up and runs discovery.Service.Discover on them.
probe
Package probe holds pure parsers for the OS-fingerprint commands the Discovery service runs over SSH.
Package probe holds pure parsers for the OS-fingerprint commands the Discovery service runs over SSH.
scheduler
Package scheduler is the recurring driver for OS Intelligence collection — the cron-like loop that turns the one-shot collector.Service.RunCycle into a continuous per-host cadence.
Package scheduler is the recurring driver for OS Intelligence collection — the cron-like loop that turns the one-shot collector.Service.RunCycle into a continuous per-host cadence.
Package internalrace exposes a single helper for adjusting performance budgets when the race detector is on.
Package internalrace exposes a single helper for adjusting performance budgets when the race detector is on.
Package isotree gives a test a private copy of part of the repository.
Package isotree gives a test a private copy of part of the repository.
RuleCatalog — in-memory kensa rule id -> {title, category, severity} lookup for read-path endpoints (the failed-rules listing resolves titles through it).
RuleCatalog — in-memory kensa rule id -> {title, category, severity} lookup for read-path endpoints (the failed-rules listing resolves titles through it).
Package knownhosts is a PostgreSQL-backed ssh.KnownHostsStore.
Package knownhosts is a PostgreSQL-backed ssh.KnownHostsStore.
Package license owns license file loading, JWT validation, atomic state for hot-path IsEnabled checks, the RequireFeature HTTP middleware, and the license.* audit emissions.
Package license owns license file loading, JWT validation, atomic state for hot-path IsEnabled checks, the RequireFeature HTTP middleware, and the license.* audit emissions.
Package liveness implements OpenWatch's periodic host reachability probe loop.
Package liveness implements OpenWatch's periodic host reachability probe loop.
Package log provides the slog handler that automatically tags every log record with the correlation_id from context.
Package log provides the slog handler that automatically tags every log record with the correlation_id from context.
Package notification manages operator-configured alert-delivery channels (Slack, generic webhook).
Package notification manages operator-configured alert-delivery channels (Slack, generic webhook).
Package notifyfeed is the durable, per-user in-app notification feed — the data layer behind the bell.
Package notifyfeed is the durable, per-user in-app notification feed — the data layer behind the bell.
Package perftest gates latency-budget assertions behind an explicit opt-in.
Package perftest gates latency-budget assertions behind an explicit opt-in.
Package policy is the Stage-0 policies-as-data framework.
Package policy is the Stage-0 policies-as-data framework.
Package posture maintains daily per-host compliance posture snapshots and serves the trend reads built on them.
Package posture maintains daily per-host compliance posture snapshots and serves the trend reads built on them.
Package queue is the PostgreSQL-native async job queue.
Package queue is the PostgreSQL-native async job queue.
Remediation execution lifecycle (Phase 7, Tier A free-core).
Remediation execution lifecycle (Phase 7, Tier A free-core).
Package report implements the Reports library: point-in-time, immutable, Ed25519-signed compliance artifacts.
Package report implements the Reports library: point-in-time, immutable, Ed25519-signed compliance artifacts.
Package reportschedule recurs report generation on a daily/weekly/monthly cadence and delivers the rendered PDF by email.
Package reportschedule recurs report generation on a daily/weekly/monthly cadence and delivers the rendered PDF by email.
Package retention holds one registry of retention policies and one sweeper that walks it.
Package retention holds one registry of retention policies and one sweeper that walks it.
Package scanresult persists and reads durable, point-in-time per-scan compliance results plus content-addressed evidence.
Package scanresult persists and reads durable, point-in-time per-scan compliance results plus content-addressed evidence.
Package scanruns owns the scan_runs table — the operational record ("logbook") of compliance-scan attempts.
Package scanruns owns the scan_runs table — the operational record ("logbook") of compliance-scan attempts.
Package scheduler implements the adaptive compliance scan scheduler.
Package scheduler implements the adaptive compliance scan scheduler.
Package secretkey owns the AES-256-GCM data encryption key (DEK) used to encrypt at-rest secrets.
Package secretkey owns the AES-256-GCM data encryption key (DEK) used to encrypt at-rest secrets.
Audit attribution for handler-emitted events: who acted, and on what.
Audit attribution for handler-emitted events: who acted, and on what.
api
Package api provides primitives to interact with the openapi HTTP API.
Package api provides primitives to interact with the openapi HTTP API.
Preflight, plan rendering, execution, and the receipt.
Preflight, plan rendering, execution, and the receipt.
Package specfixture loads acceptance-criteria fixtures out of a Specter spec so tests are driven by the spec rather than by numbers copied beside it.
Package specfixture loads acceptance-criteria fixtures out of a Specter spec so tests are driven by the spec rather than by numbers copied beside it.
Package ssh is the OpenWatch SSH dial layer.
Package ssh is the OpenWatch SSH dial layer.
Package sshprivilege implements liveness.PrivilegeProbeFunc: dial SSH with the host's resolved credential, run `sudo -n true`, and report whether passwordless privilege escalation is configured.
Package sshprivilege implements liveness.PrivilegeProbeFunc: dial SSH with the host's resolved credential, run `sudo -n true`, and report whether passwordless privilege escalation is configured.
Package sso implements single sign-on via OpenID Connect: admin-managed providers (config plane) and the authorization-code sign-in flow (runtime plane).
Package sso implements single sign-on via OpenID Connect: admin-managed providers (config plane) and the authorization-code sign-in flow (runtime plane).
Package systemconfig is the runtime config store.
Package systemconfig is the runtime config store.
Package transactionlog implements OpenWatch's compliance write-on-change persistence layer.
Package transactionlog implements OpenWatch's compliance write-on-change persistence layer.
Package userpref owns per-user UI preferences, stored as the JSONB users.preferences column (migration 0040).
Package userpref owns per-user UI preferences, stored as the JSONB users.preferences column (migration 0040).
Package users owns the users + user_roles tables.
Package users owns the users + user_roles tables.
FIPS reporting, sourced from the runtime rather than from a build flag.
FIPS reporting, sourced from the runtime rather than from a build flag.
JSONB payload + HMAC signing for remediation jobs.
JSONB payload + HMAC signing for remediation jobs.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL