Directories
¶
| Path | Synopsis |
|---|---|
|
Background password-expiry sweep, wired in serve.
|
Background password-expiry sweep, wired in serve. |
|
Package activity merges alerts + transactions + intelligence_events + audit_events into a single time-ordered feed, with per-source RBAC and seek-cursor pagination.
|
Package activity merges alerts + transactions + intelligence_events + audit_events into a single time-ordered feed, with per-source RBAC and seek-cursor pagination. |
|
Package alertrouter is the bridge between OpenWatch's in-process event bus (internal/eventbus) and external notification channels (Slack, email, webhook, PagerDuty).
|
Package alertrouter is the bridge between OpenWatch's in-process event bus (internal/eventbus) and external notification channels (Slack, email, webhook, PagerDuty). |
|
channels/stdout
Package stdout implements an alertrouter.Channel that logs alerts to the structured slog default logger at INFO level.
|
Package stdout implements an alertrouter.Channel that logs alerts to the structured slog default logger at INFO level. |
|
Package alerts owns the lifecycle service for persisted alerts — acknowledge / silence / resolve / dismiss transitions plus the auto-resolve hook that closes host_unreachable when host_recovered arrives.
|
Package alerts owns the lifecycle service for persisted alerts — acknowledge / silence / resolve / dismiss transitions plus the auto-resolve hook that closes host_unreachable when host_recovered arrives. |
|
Package apitoken manages API service-account tokens for automation (CI, scripts) that call the REST API without an interactive session.
|
Package apitoken manages API service-account tokens for automation (CI, scripts) that call the REST API without an interactive session. |
|
Package audit emits and stores audit events per the contract in docs/engineering/audit_event_taxonomy.md and specs/system/audit-emission.spec.yaml.
|
Package audit emits and stores audit events per the contract in docs/engineering/audit_event_taxonomy.md and specs/system/audit-emission.spec.yaml. |
|
Package auth provides RBAC: a codegen-typed permission registry, built-in roles, and the RequirePermission middleware that combines RBAC and license-gate checks in one pass.
|
Package auth provides RBAC: a codegen-typed permission registry, built-in roles, and the RequirePermission middleware that combines RBAC and license-gate checks in one pass. |
|
Package authpolicy manages the workspace-wide authentication policy: the require-MFA flag and the session idle/absolute timeout windows.
|
Package authpolicy manages the workspace-wide authentication policy: the require-MFA flag and the session idle/absolute timeout windows. |
|
Package compliance owns the single definition of a compliance score.
|
Package compliance owns the single definition of a compliance score. |
|
Package config loads OpenWatch runtime configuration.
|
Package config loads OpenWatch runtime configuration. |
|
Package connprofile is the per-host "last known good" SSH connection memory shared by every path that talks to a managed host (the liveness privilege probe, OS discovery, OS intelligence collection, and the compliance scan).
|
Package connprofile is the per-host "last known good" SSH connection memory shared by every path that talks to a managed host (the liveness privilege probe, OS discovery, OS intelligence collection, and the compliance scan). |
|
Package corpus defines which host_rule_state rows still count.
|
Package corpus defines which host_rule_state rows still count. |
|
Package correlation propagates a request-scoped correlation ID across HTTP entry, audit emission, log lines, and outbound calls.
|
Package correlation propagates a request-scoped correlation ID across HTTP entry, audit emission, log lines, and outbound calls. |
|
Package credential owns SSH credential storage and the system→host resolver.
|
Package credential owns SSH credential storage and the system→host resolver. |
|
Package cron is the minimal Stage-0 cron scheduler.
|
Package cron is the minimal Stage-0 cron scheduler. |
|
Package db owns PostgreSQL connectivity for the openwatch binary.
|
Package db owns PostgreSQL connectivity for the openwatch binary. |
|
corpustest
Package corpustest seeds host_rule_state rows that are actually IN a host's current corpus.
|
Package corpustest seeds host_rule_state rows that are actually IN a host's current corpus. |
|
dbtest
Package dbtest gives each test BINARY (i.e.
|
Package dbtest gives each test BINARY (i.e. |
|
migrations
Package migrations embeds the SQL migration files and exposes the goose runner that applies them.
|
Package migrations embeds the SQL migration files and exposes the goose runner that applies them. |
|
Package dbbackup creates a plain-SQL pg_dump of the OpenWatch database, used as the pre-upgrade restore point before migrations run.
|
Package dbbackup creates a plain-SQL pg_dump of the OpenWatch database, used as the pre-upgrade restore point before migrations run. |
|
Package drift implements OpenWatch's compliance drift detector.
|
Package drift implements OpenWatch's compliance drift detector. |
|
Package eventbus implements OpenWatch's in-process typed pub/sub.
|
Package eventbus implements OpenWatch's in-process typed pub/sub. |
|
Background expiry sweep, wired in serve.
|
Background expiry sweep, wired in serve. |
|
Package fleetrollup answers "how is my fleet doing right now?" via read-only aggregations over the Slice B persistence layer (host_rule_state, transactions, host_liveness).
|
Package fleetrollup answers "how is my fleet doing right now?" via read-only aggregations over the Slice B persistence layer (host_rule_state, transactions, host_liveness). |
|
Package framework groups the corpus's per-rule framework reference keys (host_rule_state.framework_refs) into user-facing FAMILIES and lists them for the "default compliance lens" picker.
|
Package framework groups the corpus's per-rule framework reference keys (host_rule_state.framework_refs) into user-facing FAMILIES and lists them for the "default compliance lens" picker. |
|
Package group implements host groups: operator-curated SITES (manual membership) and OS CATEGORIES (auto membership derived from hosts.os_family, or manual workload groups).
|
Package group implements host groups: operator-curated SITES (manual membership) and OS CATEGORIES (auto membership derived from hosts.os_family, or manual workload groups). |
|
Package host owns the hosts table — the inventory of machines the platform can talk to.
|
Package host owns the hosts table — the inventory of machines the platform can talk to. |
|
Package httpclient is the outbound HTTP wrapper that forwards the correlation ID from request context as X-Correlation-Id on every call.
|
Package httpclient is the outbound HTTP wrapper that forwards the correlation ID from request context as X-Correlation-Id on every call. |
|
Package idempotency provides the middleware that makes mutating HTTP requests safely retryable.
|
Package idempotency provides the middleware that makes mutating HTTP requests safely retryable. |
|
Package identity owns the auth primitives: password hashing (Argon2id), NIST SP 800-63B password-policy validation, breach-corpus checking, session token lifecycle, RS256 JWT mint/verify, and TOTP MFA.
|
Package identity owns the auth primitives: password hashing (Argon2id), NIST SP 800-63B password-policy validation, breach-corpus checking, session token lifecycle, RS256 JWT mint/verify, and TOTP MFA. |
|
intelligence
|
|
|
collector
Package collector implements OS Intelligence — the recurring, write-on-change counterpart to OS Discovery.
|
Package collector implements OS Intelligence — the recurring, write-on-change counterpart to OS Discovery. |
|
discovery
Package discovery owns the one-shot SSH OS-fingerprint flow that captures os_family, os_version, kernel, architecture, hostname / FQDN, SELinux + AppArmor + firewall posture, and a hardware summary for each host on first contact + on-demand.
|
Package discovery owns the one-shot SSH OS-fingerprint flow that captures os_family, os_version, kernel, architecture, hostname / FQDN, SELinux + AppArmor + firewall posture, and a hardware summary for each host on first contact + on-demand. |
|
discovery/scheduler
Package scheduler is the recurring driver for OS discovery — the loop that finds hosts whose hosts.os_discovered_at column is stale (NULL or older than the policy interval) and enqueues host.discovery jobs through internal/queue so the worker pool picks them up and runs discovery.Service.Discover on them.
|
Package scheduler is the recurring driver for OS discovery — the loop that finds hosts whose hosts.os_discovered_at column is stale (NULL or older than the policy interval) and enqueues host.discovery jobs through internal/queue so the worker pool picks them up and runs discovery.Service.Discover on them. |
|
probe
Package probe holds pure parsers for the OS-fingerprint commands the Discovery service runs over SSH.
|
Package probe holds pure parsers for the OS-fingerprint commands the Discovery service runs over SSH. |
|
scheduler
Package scheduler is the recurring driver for OS Intelligence collection — the cron-like loop that turns the one-shot collector.Service.RunCycle into a continuous per-host cadence.
|
Package scheduler is the recurring driver for OS Intelligence collection — the cron-like loop that turns the one-shot collector.Service.RunCycle into a continuous per-host cadence. |
|
Package internalrace exposes a single helper for adjusting performance budgets when the race detector is on.
|
Package internalrace exposes a single helper for adjusting performance budgets when the race detector is on. |
|
Package isotree gives a test a private copy of part of the repository.
|
Package isotree gives a test a private copy of part of the repository. |
|
RuleCatalog — in-memory kensa rule id -> {title, category, severity} lookup for read-path endpoints (the failed-rules listing resolves titles through it).
|
RuleCatalog — in-memory kensa rule id -> {title, category, severity} lookup for read-path endpoints (the failed-rules listing resolves titles through it). |
|
Package knownhosts is a PostgreSQL-backed ssh.KnownHostsStore.
|
Package knownhosts is a PostgreSQL-backed ssh.KnownHostsStore. |
|
Package license owns license file loading, JWT validation, atomic state for hot-path IsEnabled checks, the RequireFeature HTTP middleware, and the license.* audit emissions.
|
Package license owns license file loading, JWT validation, atomic state for hot-path IsEnabled checks, the RequireFeature HTTP middleware, and the license.* audit emissions. |
|
Package liveness implements OpenWatch's periodic host reachability probe loop.
|
Package liveness implements OpenWatch's periodic host reachability probe loop. |
|
Package log provides the slog handler that automatically tags every log record with the correlation_id from context.
|
Package log provides the slog handler that automatically tags every log record with the correlation_id from context. |
|
Package notification manages operator-configured alert-delivery channels (Slack, generic webhook).
|
Package notification manages operator-configured alert-delivery channels (Slack, generic webhook). |
|
Package notifyfeed is the durable, per-user in-app notification feed — the data layer behind the bell.
|
Package notifyfeed is the durable, per-user in-app notification feed — the data layer behind the bell. |
|
Package perftest gates latency-budget assertions behind an explicit opt-in.
|
Package perftest gates latency-budget assertions behind an explicit opt-in. |
|
Package policy is the Stage-0 policies-as-data framework.
|
Package policy is the Stage-0 policies-as-data framework. |
|
Package posture maintains daily per-host compliance posture snapshots and serves the trend reads built on them.
|
Package posture maintains daily per-host compliance posture snapshots and serves the trend reads built on them. |
|
Package queue is the PostgreSQL-native async job queue.
|
Package queue is the PostgreSQL-native async job queue. |
|
Remediation execution lifecycle (Phase 7, Tier A free-core).
|
Remediation execution lifecycle (Phase 7, Tier A free-core). |
|
Package report implements the Reports library: point-in-time, immutable, Ed25519-signed compliance artifacts.
|
Package report implements the Reports library: point-in-time, immutable, Ed25519-signed compliance artifacts. |
|
Package reportschedule recurs report generation on a daily/weekly/monthly cadence and delivers the rendered PDF by email.
|
Package reportschedule recurs report generation on a daily/weekly/monthly cadence and delivers the rendered PDF by email. |
|
Package retention holds one registry of retention policies and one sweeper that walks it.
|
Package retention holds one registry of retention policies and one sweeper that walks it. |
|
Package scanresult persists and reads durable, point-in-time per-scan compliance results plus content-addressed evidence.
|
Package scanresult persists and reads durable, point-in-time per-scan compliance results plus content-addressed evidence. |
|
Package scanruns owns the scan_runs table — the operational record ("logbook") of compliance-scan attempts.
|
Package scanruns owns the scan_runs table — the operational record ("logbook") of compliance-scan attempts. |
|
Package scheduler implements the adaptive compliance scan scheduler.
|
Package scheduler implements the adaptive compliance scan scheduler. |
|
Package secretkey owns the AES-256-GCM data encryption key (DEK) used to encrypt at-rest secrets.
|
Package secretkey owns the AES-256-GCM data encryption key (DEK) used to encrypt at-rest secrets. |
|
Audit attribution for handler-emitted events: who acted, and on what.
|
Audit attribution for handler-emitted events: who acted, and on what. |
|
api
Package api provides primitives to interact with the openapi HTTP API.
|
Package api provides primitives to interact with the openapi HTTP API. |
|
Preflight, plan rendering, execution, and the receipt.
|
Preflight, plan rendering, execution, and the receipt. |
|
Package specfixture loads acceptance-criteria fixtures out of a Specter spec so tests are driven by the spec rather than by numbers copied beside it.
|
Package specfixture loads acceptance-criteria fixtures out of a Specter spec so tests are driven by the spec rather than by numbers copied beside it. |
|
Package ssh is the OpenWatch SSH dial layer.
|
Package ssh is the OpenWatch SSH dial layer. |
|
Package sshprivilege implements liveness.PrivilegeProbeFunc: dial SSH with the host's resolved credential, run `sudo -n true`, and report whether passwordless privilege escalation is configured.
|
Package sshprivilege implements liveness.PrivilegeProbeFunc: dial SSH with the host's resolved credential, run `sudo -n true`, and report whether passwordless privilege escalation is configured. |
|
Package sso implements single sign-on via OpenID Connect: admin-managed providers (config plane) and the authorization-code sign-in flow (runtime plane).
|
Package sso implements single sign-on via OpenID Connect: admin-managed providers (config plane) and the authorization-code sign-in flow (runtime plane). |
|
Package systemconfig is the runtime config store.
|
Package systemconfig is the runtime config store. |
|
Package transactionlog implements OpenWatch's compliance write-on-change persistence layer.
|
Package transactionlog implements OpenWatch's compliance write-on-change persistence layer. |
|
Package userpref owns per-user UI preferences, stored as the JSONB users.preferences column (migration 0040).
|
Package userpref owns per-user UI preferences, stored as the JSONB users.preferences column (migration 0040). |
|
Package users owns the users + user_roles tables.
|
Package users owns the users + user_roles tables. |
|
FIPS reporting, sourced from the runtime rather than from a build flag.
|
FIPS reporting, sourced from the runtime rather than from a build flag. |
|
JSONB payload + HMAC signing for remediation jobs.
|
JSONB payload + HMAC signing for remediation jobs. |
Click to show internal directories.
Click to hide internal directories.