api

package
v0.8.4 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 9, 2026 License: Apache-2.0 Imports: 7 Imported by: 0

Documentation

Overview

Package api provides primitives to interact with the openapi HTTP API.

Code generated by github.com/oapi-codegen/oapi-codegen/v2 version v2.7.0 DO NOT EDIT.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func Handler

func Handler(si ServerInterface) http.Handler

Handler creates http.Handler with routing matching OpenAPI spec.

func HandlerFromMux

func HandlerFromMux(si ServerInterface, r chi.Router) http.Handler

HandlerFromMux creates http.Handler with routing matching OpenAPI spec based on the provided mux.

func HandlerFromMuxWithBaseURL

func HandlerFromMuxWithBaseURL(si ServerInterface, r chi.Router, baseURL string) http.Handler

func HandlerWithOptions

func HandlerWithOptions(si ServerInterface, options ChiServerOptions) http.Handler

HandlerWithOptions creates http.Handler with additional options

Types

type Activity

type Activity struct {
	HostId     *openapi_types.UUID `json:"host_id,omitempty"`
	Id         openapi_types.UUID  `json:"id"`
	OccurredAt time.Time           `json:"occurred_at"`
	Severity   ActivitySeverity    `json:"severity"`
	Source     ActivitySource      `json:"source"`
	Summary    *string             `json:"summary,omitempty"`
	Title      string              `json:"title"`
}

Activity defines model for Activity.

type ActivityPage

type ActivityPage struct {
	HiddenCount int        `json:"hidden_count"`
	Items       []Activity `json:"items"`
	NextCursor  *string    `json:"next_cursor,omitempty"`
}

ActivityPage defines model for ActivityPage.

type ActivitySeverity

type ActivitySeverity string

ActivitySeverity defines model for Activity.Severity.

const (
	ActivitySeverityCritical ActivitySeverity = "critical"
	ActivitySeverityHigh     ActivitySeverity = "high"
	ActivitySeverityInfo     ActivitySeverity = "info"
	ActivitySeverityLow      ActivitySeverity = "low"
	ActivitySeverityMedium   ActivitySeverity = "medium"
)

Defines values for ActivitySeverity.

func (ActivitySeverity) Valid

func (e ActivitySeverity) Valid() bool

Valid indicates whether the value is a known member of the ActivitySeverity enum.

type ActivitySource

type ActivitySource string

ActivitySource defines model for Activity.Source.

const (
	ActivitySourceAlert        ActivitySource = "alert"
	ActivitySourceAudit        ActivitySource = "audit"
	ActivitySourceIntelligence ActivitySource = "intelligence"
	ActivitySourceMonitoring   ActivitySource = "monitoring"
	ActivitySourceTransaction  ActivitySource = "transaction"
)

Defines values for ActivitySource.

func (ActivitySource) Valid

func (e ActivitySource) Valid() bool

Valid indicates whether the value is a known member of the ActivitySource enum.

type AdminRolesResponse

type AdminRolesResponse struct {
	Roles []RoleEntry `json:"roles"`
}

AdminRolesResponse defines model for AdminRolesResponse.

type AggregateScore added in v0.8.0

type AggregateScore struct {
	// CoveragePct Share of in-scope rules that produced a verdict, to one decimal. Non-null if and only if coverage_status is available.
	CoveragePct *float64 `json:"coverage_pct"`

	// CoverageStatus Whether the share of in-scope rules that produced a verdict can be stated, and when it cannot, why. unavailable_unclassified_skips means at least one skip carries no machine-readable reason, so an inapplicable rule cannot be told from an unevaluated one; the number is withheld rather than guessed.
	CoverageStatus AggregateScoreCoverageStatus `json:"coverage_status"`
	Envelope       ScoreEnvelope                `json:"envelope"`

	// Error Outcomes that errored, summed across the population.
	Error int64 `json:"error"`

	// Failing Rule outcomes that failed, summed across the population.
	Failing int64 `json:"failing"`

	// HostsScored Hosts that produced a score. The population the mean is over.
	HostsScored int `json:"hosts_scored"`

	// HostsTotal Active hosts. Always hosts_scored + hosts_without_score.
	HostsTotal int `json:"hosts_total"`

	// HostsWithoutScore Active hosts that produced no score: never scanned, scanned with no verdict, or carrying no rule that matches the lens.
	HostsWithoutScore int `json:"hosts_without_score"`

	// Passing Rule outcomes that passed, summed across the population.
	Passing int64 `json:"passing"`

	// ScorePct Equal-host mean of the per-host scores, to one decimal, so each host counts once whatever its rule count. NULL when no host produced a verdict, which is a different fact from every host failing every rule (that scores 0). It replaces a pooled ratio that weighted hosts by rule count and could not express absence.
	ScorePct *float64 `json:"score_pct"`

	// Skipped Outcomes that produced no verdict, summed across the population. They enter neither side of score_pct.
	Skipped int64 `json:"skipped"`
}

AggregateScore defines model for AggregateScore.

type AggregateScoreCoverageStatus added in v0.8.0

type AggregateScoreCoverageStatus string

AggregateScoreCoverageStatus Whether the share of in-scope rules that produced a verdict can be stated, and when it cannot, why. unavailable_unclassified_skips means at least one skip carries no machine-readable reason, so an inapplicable rule cannot be told from an unevaluated one; the number is withheld rather than guessed.

const (
	AggregateScoreCoverageStatusAvailable                    AggregateScoreCoverageStatus = "available"
	AggregateScoreCoverageStatusUnavailableNoOutcomes        AggregateScoreCoverageStatus = "unavailable_no_outcomes"
	AggregateScoreCoverageStatusUnavailableUnclassifiedSkips AggregateScoreCoverageStatus = "unavailable_unclassified_skips"
)

Defines values for AggregateScoreCoverageStatus.

func (AggregateScoreCoverageStatus) Valid added in v0.8.0

Valid indicates whether the value is a known member of the AggregateScoreCoverageStatus enum.

type Alert

type Alert struct {
	AcknowledgedAt *time.Time          `json:"acknowledged_at,omitempty"`
	AcknowledgedBy *openapi_types.UUID `json:"acknowledged_by,omitempty"`
	AlertType      string              `json:"alert_type"`
	Body           *string             `json:"body,omitempty"`
	CreatedAt      *time.Time          `json:"created_at,omitempty"`
	DedupKey       string              `json:"dedup_key"`
	DismissedAt    *time.Time          `json:"dismissed_at,omitempty"`
	DismissedBy    *openapi_types.UUID `json:"dismissed_by,omitempty"`
	HostId         *openapi_types.UUID `json:"host_id,omitempty"`
	Id             openapi_types.UUID  `json:"id"`
	OccurredAt     time.Time           `json:"occurred_at"`
	ResolvedAt     *time.Time          `json:"resolved_at,omitempty"`
	ResolvedBy     *openapi_types.UUID `json:"resolved_by,omitempty"`
	RuleId         *string             `json:"rule_id,omitempty"`
	Severity       AlertSeverity       `json:"severity"`
	SilencedBy     *openapi_types.UUID `json:"silenced_by,omitempty"`
	SilencedUntil  *time.Time          `json:"silenced_until,omitempty"`
	State          AlertState          `json:"state"`
	Tags           *map[string]string  `json:"tags,omitempty"`
	Title          string              `json:"title"`
	UpdatedAt      *time.Time          `json:"updated_at,omitempty"`
}

Alert defines model for Alert.

type AlertLifecycleRequest

type AlertLifecycleRequest struct {
	Reason *string    `json:"reason,omitempty"`
	Until  *time.Time `json:"until,omitempty"`
}

AlertLifecycleRequest Optional body for POST lifecycle endpoints. silence accepts an optional until; all accept a reason for the audit detail.

type AlertSeverity

type AlertSeverity string

AlertSeverity defines model for Alert.Severity.

const (
	AlertSeverityCritical AlertSeverity = "critical"
	AlertSeverityHigh     AlertSeverity = "high"
	AlertSeverityInfo     AlertSeverity = "info"
	AlertSeverityLow      AlertSeverity = "low"
	AlertSeverityMedium   AlertSeverity = "medium"
)

Defines values for AlertSeverity.

func (AlertSeverity) Valid

func (e AlertSeverity) Valid() bool

Valid indicates whether the value is a known member of the AlertSeverity enum.

type AlertState

type AlertState string

AlertState defines model for Alert.State.

const (
	AlertStateAcknowledged AlertState = "acknowledged"
	AlertStateActive       AlertState = "active"
	AlertStateDismissed    AlertState = "dismissed"
	AlertStateResolved     AlertState = "resolved"
	AlertStateSilenced     AlertState = "silenced"
)

Defines values for AlertState.

func (AlertState) Valid

func (e AlertState) Valid() bool

Valid indicates whether the value is a known member of the AlertState enum.

type AlertsPage

type AlertsPage struct {
	Items      []Alert `json:"items"`
	NextCursor *string `json:"next_cursor,omitempty"`
}

AlertsPage defines model for AlertsPage.

type ApiToken

type ApiToken struct {
	CreatedAt  time.Time          `json:"created_at"`
	ExpiresAt  *time.Time         `json:"expires_at,omitempty"`
	Id         openapi_types.UUID `json:"id"`
	LastUsedAt *time.Time         `json:"last_used_at,omitempty"`
	Name       string             `json:"name"`

	// Prefix Non-secret display prefix (e.g. owk_a1b2c3d4)
	Prefix    string     `json:"prefix"`
	RevokedAt *time.Time `json:"revoked_at,omitempty"`

	// RoleId The role whose permissions the token carries
	RoleId string `json:"role_id"`
}

ApiToken API token metadata. The secret is NEVER included.

type ApiTokenCreateRequest

type ApiTokenCreateRequest struct {
	ExpiresAt *time.Time `json:"expires_at,omitempty"`
	Name      string     `json:"name"`

	// RoleId Role the token acts as (must be a known role)
	RoleId string `json:"role_id"`
}

ApiTokenCreateRequest defines model for ApiTokenCreateRequest.

type ApiTokenCreated

type ApiTokenCreated struct {
	// ApiToken API token metadata. The secret is NEVER included.
	ApiToken ApiToken `json:"api_token"`

	// Token The raw secret. Shown once.
	Token string `json:"token"`
}

ApiTokenCreated The raw token is shown ONCE, in this create response only. Store it now; it cannot be retrieved again.

type ApiTokenList

type ApiTokenList struct {
	Tokens []ApiToken `json:"tokens"`
}

ApiTokenList defines model for ApiTokenList.

type ApproveRemediationJSONRequestBody

type ApproveRemediationJSONRequestBody = RemediationReview

ApproveRemediationJSONRequestBody defines body for ApproveRemediation for application/json ContentType.

type AuditEvent

type AuditEvent struct {
	Action        string                  `json:"action"`
	ActorId       *string                 `json:"actor_id,omitempty"`
	ActorLabel    *string                 `json:"actor_label,omitempty"`
	ActorType     string                  `json:"actor_type"`
	CorrelationId string                  `json:"correlation_id"`
	Detail        *map[string]interface{} `json:"detail,omitempty"`
	Id            openapi_types.UUID      `json:"id"`
	Message       *string                 `json:"message,omitempty"`
	OccurredAt    time.Time               `json:"occurred_at"`
	RecordedAt    *time.Time              `json:"recorded_at,omitempty"`
	Redactions    *[]string               `json:"redactions,omitempty"`
	ResourceId    *string                 `json:"resource_id,omitempty"`
	ResourceType  *string                 `json:"resource_type,omitempty"`
	Severity      *string                 `json:"severity,omitempty"`
}

AuditEvent defines model for AuditEvent.

type AuditEventsPage

type AuditEventsPage struct {
	Items []AuditEvent `json:"items"`

	// NextCursor Opaque cursor; pass as ?cursor= to fetch the next page
	NextCursor *string `json:"next_cursor"`
}

AuditEventsPage defines model for AuditEventsPage.

type AuthLoginRequest

type AuthLoginRequest struct {
	Otp      *string `json:"otp,omitempty"`
	Password string  `json:"password"`
	Username string  `json:"username"`
}

AuthLoginRequest defines model for AuthLoginRequest.

type AuthLoginResponse

type AuthLoginResponse struct {
	AccessToken string `json:"access_token"`

	// MfaEnrollmentRequired True when workspace policy requires MFA but the user has not enrolled. The session is still issued (soft enforcement); the client must force MFA enrollment before anything else.
	MfaEnrollmentRequired *bool          `json:"mfa_enrollment_required,omitempty"`
	RefreshToken          string         `json:"refresh_token"`
	User                  AuthMeResponse `json:"user"`
}

AuthLoginResponse defines model for AuthLoginResponse.

type AuthMFAEnrollResponse

type AuthMFAEnrollResponse struct {
	ProvisioningUri string `json:"provisioning_uri"`
}

AuthMFAEnrollResponse defines model for AuthMFAEnrollResponse.

type AuthMFAVerifyRequest

type AuthMFAVerifyRequest struct {
	Otp string `json:"otp"`
}

AuthMFAVerifyRequest defines model for AuthMFAVerifyRequest.

type AuthMePermissionsResponse

type AuthMePermissionsResponse struct {
	Identity struct {
		Id          string `json:"id"`
		IsAnonymous bool   `json:"is_anonymous"`
		Role        string `json:"role"`
	} `json:"identity"`
	Permissions []string `json:"permissions"`
}

AuthMePermissionsResponse defines model for AuthMePermissionsResponse.

type AuthMeResponse

type AuthMeResponse struct {
	// DisplayName Editable profile field (may be empty)
	DisplayName *string `json:"display_name,omitempty"`
	Email       string  `json:"email"`

	// FullName Editable profile field (may be empty)
	FullName *string            `json:"full_name,omitempty"`
	Id       openapi_types.UUID `json:"id"`

	// JobTitle Editable profile field (may be empty)
	JobTitle *string `json:"job_title,omitempty"`

	// Phone Editable profile field (may be empty)
	Phone *string `json:"phone,omitempty"`
	Role  string  `json:"role"`

	// Timezone IANA timezone
	Timezone *string `json:"timezone,omitempty"`
	Username string  `json:"username"`
}

AuthMeResponse defines model for AuthMeResponse.

type AuthMeUpdateRequest added in v0.4.0

type AuthMeUpdateRequest struct {
	DisplayName *string `json:"display_name,omitempty"`

	// Email Sign-in identity; must be unique among active users
	Email    *string `json:"email,omitempty"`
	FullName *string `json:"full_name,omitempty"`
	JobTitle *string `json:"job_title,omitempty"`
	Phone    *string `json:"phone,omitempty"`
	Timezone *string `json:"timezone,omitempty"`
}

AuthMeUpdateRequest Partial self-profile update. Every field is optional; a present field replaces the stored value (empty string clears it). Omitted fields are left unchanged.

type AuthPasswordChangeRequest

type AuthPasswordChangeRequest struct {
	CurrentPassword string `json:"current_password"`
	NewPassword     string `json:"new_password"`
}

AuthPasswordChangeRequest defines model for AuthPasswordChangeRequest.

type AuthPolicy

type AuthPolicy struct {
	// RequireMfa When true, every user must have MFA enrolled (soft-enforced at login).
	RequireMfa bool `json:"require_mfa"`

	// SessionAbsoluteTimeoutSeconds Absolute lifetime cap regardless of activity, in seconds.
	SessionAbsoluteTimeoutSeconds int `json:"session_absolute_timeout_seconds"`

	// SessionIdleTimeoutSeconds Inactivity window. A session expires this many seconds after its last use.
	SessionIdleTimeoutSeconds int                 `json:"session_idle_timeout_seconds"`
	UpdatedAt                 time.Time           `json:"updated_at"`
	UpdatedBy                 *openapi_types.UUID `json:"updated_by,omitempty"`
}

AuthPolicy Workspace-wide authentication policy.

type AuthPolicyUpdateRequest

type AuthPolicyUpdateRequest struct {
	RequireMfa                    bool `json:"require_mfa"`
	SessionAbsoluteTimeoutSeconds int  `json:"session_absolute_timeout_seconds"`
	SessionIdleTimeoutSeconds     int  `json:"session_idle_timeout_seconds"`
}

AuthPolicyUpdateRequest Replaces the whole policy. Bounds (enforced server-side): idle 300..86400 s, absolute 3600..2592000 s, absolute >= idle.

type AuthRefreshRequest

type AuthRefreshRequest struct {
	RefreshToken string `json:"refresh_token"`
}

AuthRefreshRequest defines model for AuthRefreshRequest.

type BadRequest

type BadRequest = ErrorEnvelope

BadRequest defines model for BadRequest.

type CapabilitiesResponse added in v0.7.0

type CapabilitiesResponse struct {
	Capabilities []Capability               `json:"capabilities"`
	Status       CapabilitiesResponseStatus `json:"status"`
	Tier         CapabilitiesResponseTier   `json:"tier"`
}

CapabilitiesResponse defines model for CapabilitiesResponse.

type CapabilitiesResponseStatus added in v0.7.0

type CapabilitiesResponseStatus string

CapabilitiesResponseStatus defines model for CapabilitiesResponse.Status.

const (
	CapabilitiesResponseStatusActive    CapabilitiesResponseStatus = "active"
	CapabilitiesResponseStatusExpired   CapabilitiesResponseStatus = "expired"
	CapabilitiesResponseStatusGrace     CapabilitiesResponseStatus = "grace"
	CapabilitiesResponseStatusInvalid   CapabilitiesResponseStatus = "invalid"
	CapabilitiesResponseStatusNoLicense CapabilitiesResponseStatus = "no_license"
)

Defines values for CapabilitiesResponseStatus.

func (CapabilitiesResponseStatus) Valid added in v0.7.0

func (e CapabilitiesResponseStatus) Valid() bool

Valid indicates whether the value is a known member of the CapabilitiesResponseStatus enum.

type CapabilitiesResponseTier added in v0.7.0

type CapabilitiesResponseTier string

CapabilitiesResponseTier defines model for CapabilitiesResponse.Tier.

const (
	CapabilitiesResponseTierEnterprise CapabilitiesResponseTier = "enterprise"
	CapabilitiesResponseTierFree       CapabilitiesResponseTier = "free"
)

Defines values for CapabilitiesResponseTier.

func (CapabilitiesResponseTier) Valid added in v0.7.0

func (e CapabilitiesResponseTier) Valid() bool

Valid indicates whether the value is a known member of the CapabilitiesResponseTier enum.

type Capability added in v0.7.0

type Capability struct {
	// Available Whether THIS deployment may use it now
	Available   bool   `json:"available"`
	Description string `json:"description"`

	// Id Registry id, e.g. remediation_execution
	Id   string         `json:"id"`
	Tier CapabilityTier `json:"tier"`
}

Capability defines model for Capability.

type CapabilityTier added in v0.7.0

type CapabilityTier string

CapabilityTier defines model for Capability.Tier.

const (
	CapabilityTierEnterprise CapabilityTier = "enterprise"
	CapabilityTierFree       CapabilityTier = "free"
)

Defines values for CapabilityTier.

func (CapabilityTier) Valid added in v0.7.0

func (e CapabilityTier) Valid() bool

Valid indicates whether the value is a known member of the CapabilityTier enum.

type CategoryEntry

type CategoryEntry struct {
	Description string `json:"description"`
	Id          string `json:"id"`
}

CategoryEntry defines model for CategoryEntry.

type CategoryFreshness added in v0.6.0

type CategoryFreshness map[string]FreshnessEntry

CategoryFreshness Map of fact category -> freshness. Absent categories were never observed. Discovery keys: os_release, uname, memory, disk, hostname, fqdn, selinux, apparmor, firewall. Intelligence keys: users, groups, ports, interfaces, routes, firewall, packages, services, kernel, uptime, mounts, config.

type ChiServerOptions

type ChiServerOptions struct {
	BaseURL          string
	BaseRouter       chi.Router
	Middlewares      []MiddlewareFunc
	ErrorHandlerFunc func(w http.ResponseWriter, r *http.Request, err error)
}

type ComplianceConfig added in v0.4.0

type ComplianceConfig struct {
	// DefaultFramework Framework family id
	DefaultFramework string `json:"default_framework"`

	// EnabledFrameworks Allowlist of framework family ids offered as lenses. Empty (or omitted) means every family found in the corpus is available.
	EnabledFrameworks *[]string `json:"enabled_frameworks,omitempty"`
}

ComplianceConfig Org-wide compliance-display config. default_framework is the default lens the score surfaces (dashboard/hosts avg compliance, host detail) project to: a framework family id (e.g. "stig", "cis") or empty for All rules (the full Kensa corpus). Resolved per-host to the OS key at query time. enabled_frameworks is the allowlist of families offered as lenses; empty means all corpus families are available. A non-empty default_framework must be in a non-empty enabled_frameworks.

type ComplianceFramework added in v0.4.0

type ComplianceFramework struct {
	// Id Family id (e.g. "stig")
	Id string `json:"id"`

	// Keys Concrete corpus keys in this family (e.g. stig_rhel9, stig_rhel10)
	Keys []string `json:"keys"`

	// Label Display label (e.g. "STIG")
	Label string `json:"label"`
}

ComplianceFramework defines model for ComplianceFramework.

type ComplianceFrameworksResponse added in v0.4.0

type ComplianceFrameworksResponse struct {
	Frameworks []ComplianceFramework `json:"frameworks"`
}

ComplianceFrameworksResponse defines model for ComplianceFrameworksResponse.

type ConnectivityBreakdown

type ConnectivityBreakdown struct {
	// Critical unreachable + consecutive_failures<3
	Critical int64 `json:"critical"`

	// Degraded reachable + consecutive_failures>=1
	Degraded int64 `json:"degraded"`

	// Down consecutive_failures>=3
	Down int64 `json:"down"`

	// NeverProbed no host_liveness row exists
	NeverProbed int64 `json:"never_probed"`

	// Online reachable + consecutive_failures=0
	Online int64 `json:"online"`
}

ConnectivityBreakdown defines model for ConnectivityBreakdown.

type ConnectivityCheckResult

type ConnectivityCheckResult struct {
	// ErrorType tcp_timeout, connection_refused, banner_mismatch, or tcp_error; null on success
	ErrorType *string `json:"error_type,omitempty"`

	// NewReachabilityStatus Post-hysteresis status (same value the periodic loop would write)
	NewReachabilityStatus ConnectivityCheckResultNewReachabilityStatus `json:"new_reachability_status"`
	ProbedAt              time.Time                                    `json:"probed_at"`
	Reachable             bool                                         `json:"reachable"`

	// ResponseTimeMs 0 on failure
	ResponseTimeMs int `json:"response_time_ms"`
}

ConnectivityCheckResult defines model for ConnectivityCheckResult.

type ConnectivityCheckResultNewReachabilityStatus

type ConnectivityCheckResultNewReachabilityStatus string

ConnectivityCheckResultNewReachabilityStatus Post-hysteresis status (same value the periodic loop would write)

const (
	ConnectivityCheckResultNewReachabilityStatusReachable   ConnectivityCheckResultNewReachabilityStatus = "reachable"
	ConnectivityCheckResultNewReachabilityStatusUnknown     ConnectivityCheckResultNewReachabilityStatus = "unknown"
	ConnectivityCheckResultNewReachabilityStatusUnreachable ConnectivityCheckResultNewReachabilityStatus = "unreachable"
)

Defines values for ConnectivityCheckResultNewReachabilityStatus.

func (ConnectivityCheckResultNewReachabilityStatus) Valid

Valid indicates whether the value is a known member of the ConnectivityCheckResultNewReachabilityStatus enum.

type ConnectivityConfig

type ConnectivityConfig struct {
	// CriticalSec Probe interval for unreachable hosts below the threshold (60..86400). Default 120 (2m)
	CriticalSec int `json:"critical_sec"`

	// DegradedSec Probe interval for reachable hosts with consecutive_failures>=1 (60..86400). Default 300 (5m)
	DegradedSec int `json:"degraded_sec"`

	// DownSec Probe interval for hosts at or above the threshold (60..86400). Default 1800 (30m)
	DownSec int `json:"down_sec"`

	// MaintenanceGlobal When true, probe loop ticks but probes no hosts
	MaintenanceGlobal bool `json:"maintenance_global"`

	// MaintenanceSec Persisted band interval for hosts in maintenance (60..86400). Default 3600 (60m). Not yet auto-applied; tracked for the per-host maintenance slice
	MaintenanceSec int `json:"maintenance_sec"`

	// OnlineSec Probe interval for reachable hosts with consecutive_failures=0 (60..86400). Default 900 (15m)
	OnlineSec int `json:"online_sec"`

	// RateLimit Max concurrent SSH connections during fleet sweeps (1..200)
	RateLimit int `json:"rate_limit"`

	// TimeoutSec Per-probe TCP-banner timeout in seconds (1..30)
	TimeoutSec int `json:"timeout_sec"`

	// UnreachableThreshold Consecutive failures before reachable→unreachable (1..10)
	UnreachableThreshold int `json:"unreachable_threshold"`
}

ConnectivityConfig defines model for ConnectivityConfig.

type ConnectivityConfigResponse

type ConnectivityConfigResponse struct {
	Config   ConnectivityConfig `json:"config"`
	Defaults ConnectivityConfig `json:"defaults"`
}

ConnectivityConfigResponse defines model for ConnectivityConfigResponse.

type ConnectivityStatus

type ConnectivityStatus struct {
	// LastProbeAt Most recent probe-start time; null until the first tick
	LastProbeAt *time.Time `json:"last_probe_at,omitempty"`

	// MaintenanceActive Mirrors connectivity_config.maintenance_global
	MaintenanceActive    bool  `json:"maintenance_active"`
	ProbeCount           int64 `json:"probe_count"`
	ProbeFailureCount    int64 `json:"probe_failure_count"`
	ProbeSuccessCount    int64 `json:"probe_success_count"`
	StateTransitionCount int64 `json:"state_transition_count"`
}

ConnectivityStatus defines model for ConnectivityStatus.

type CreateReportScheduleJSONRequestBody

type CreateReportScheduleJSONRequestBody = CreateReportScheduleRequest

CreateReportScheduleJSONRequestBody defines body for CreateReportSchedule for application/json ContentType.

type CreateReportScheduleRequest

type CreateReportScheduleRequest struct {
	// ChannelId An email notification channel.
	ChannelId openapi_types.UUID `json:"channel_id"`

	// DayOfMonth Required for monthly.
	DayOfMonth *int                                 `json:"day_of_month,omitempty"`
	Framework  *string                              `json:"framework,omitempty"`
	Frequency  CreateReportScheduleRequestFrequency `json:"frequency"`
	GroupId    *openapi_types.UUID                  `json:"group_id,omitempty"`

	// Hour Defaults to 6.
	Hour       *int                            `json:"hour,omitempty"`
	Kind       CreateReportScheduleRequestKind `json:"kind"`
	Name       string                          `json:"name"`
	PeriodDays *int                            `json:"period_days,omitempty"`

	// Weekday Required for weekly.
	Weekday *int `json:"weekday,omitempty"`
}

CreateReportScheduleRequest defines model for CreateReportScheduleRequest.

type CreateReportScheduleRequestFrequency

type CreateReportScheduleRequestFrequency string

CreateReportScheduleRequestFrequency defines model for CreateReportScheduleRequest.Frequency.

const (
	CreateReportScheduleRequestFrequencyDaily   CreateReportScheduleRequestFrequency = "daily"
	CreateReportScheduleRequestFrequencyMonthly CreateReportScheduleRequestFrequency = "monthly"
	CreateReportScheduleRequestFrequencyWeekly  CreateReportScheduleRequestFrequency = "weekly"
)

Defines values for CreateReportScheduleRequestFrequency.

func (CreateReportScheduleRequestFrequency) Valid

Valid indicates whether the value is a known member of the CreateReportScheduleRequestFrequency enum.

type CreateReportScheduleRequestKind

type CreateReportScheduleRequestKind string

CreateReportScheduleRequestKind defines model for CreateReportScheduleRequest.Kind.

const (
	CreateReportScheduleRequestKindAttestation CreateReportScheduleRequestKind = "attestation"
	CreateReportScheduleRequestKindException   CreateReportScheduleRequestKind = "exception"
	CreateReportScheduleRequestKindExecutive   CreateReportScheduleRequestKind = "executive"
	CreateReportScheduleRequestKindRemediation CreateReportScheduleRequestKind = "remediation"
)

Defines values for CreateReportScheduleRequestKind.

func (CreateReportScheduleRequestKind) Valid

Valid indicates whether the value is a known member of the CreateReportScheduleRequestKind enum.

type CredentialCloneRequest

type CredentialCloneRequest struct {
	// IsDefault Mark this clone as the system default (only valid when scope=system)
	IsDefault *bool `json:"is_default,omitempty"`

	// Name Defaults to '<source name> (clone)' when omitted
	Name  *string                     `json:"name,omitempty"`
	Scope CredentialCloneRequestScope `json:"scope"`

	// ScopeId Required when scope=host
	ScopeId *openapi_types.UUID `json:"scope_id,omitempty"`
}

CredentialCloneRequest defines model for CredentialCloneRequest.

type CredentialCloneRequestScope

type CredentialCloneRequestScope string

CredentialCloneRequestScope defines model for CredentialCloneRequest.Scope.

const (
	CredentialCloneRequestScopeHost   CredentialCloneRequestScope = "host"
	CredentialCloneRequestScopeSystem CredentialCloneRequestScope = "system"
)

Defines values for CredentialCloneRequestScope.

func (CredentialCloneRequestScope) Valid

Valid indicates whether the value is a known member of the CredentialCloneRequestScope enum.

type CredentialCreateRequest

type CredentialCreateRequest struct {
	AuthMethod           CredentialCreateRequestAuthMethod `json:"auth_method"`
	Description          *string                           `json:"description,omitempty"`
	IsDefault            *bool                             `json:"is_default,omitempty"`
	Name                 string                            `json:"name"`
	Password             *string                           `json:"password,omitempty"`
	PrivateKey           *string                           `json:"private_key,omitempty"`
	PrivateKeyPassphrase *string                           `json:"private_key_passphrase,omitempty"`
	Scope                CredentialCreateRequestScope      `json:"scope"`

	// ScopeId Required when scope=host (the host id); must be absent when scope=system.
	ScopeId  *openapi_types.UUID `json:"scope_id,omitempty"`
	Username string              `json:"username"`
}

CredentialCreateRequest defines model for CredentialCreateRequest.

type CredentialCreateRequestAuthMethod

type CredentialCreateRequestAuthMethod string

CredentialCreateRequestAuthMethod defines model for CredentialCreateRequest.AuthMethod.

const (
	CredentialCreateRequestAuthMethodBoth     CredentialCreateRequestAuthMethod = "both"
	CredentialCreateRequestAuthMethodPassword CredentialCreateRequestAuthMethod = "password"
	CredentialCreateRequestAuthMethodSshKey   CredentialCreateRequestAuthMethod = "ssh_key"
)

Defines values for CredentialCreateRequestAuthMethod.

func (CredentialCreateRequestAuthMethod) Valid

Valid indicates whether the value is a known member of the CredentialCreateRequestAuthMethod enum.

type CredentialCreateRequestScope

type CredentialCreateRequestScope string

CredentialCreateRequestScope defines model for CredentialCreateRequest.Scope.

const (
	CredentialCreateRequestScopeHost   CredentialCreateRequestScope = "host"
	CredentialCreateRequestScopeSystem CredentialCreateRequestScope = "system"
)

Defines values for CredentialCreateRequestScope.

func (CredentialCreateRequestScope) Valid

Valid indicates whether the value is a known member of the CredentialCreateRequestScope enum.

type CredentialListResponse

type CredentialListResponse struct {
	Credentials []CredentialResponse `json:"credentials"`
}

CredentialListResponse defines model for CredentialListResponse.

type CredentialResponse

type CredentialResponse struct {
	AuthMethod        CredentialResponseAuthMethod `json:"auth_method"`
	CreatedAt         *time.Time                   `json:"created_at,omitempty"`
	CreatedBy         *openapi_types.UUID          `json:"created_by,omitempty"`
	Description       *string                      `json:"description,omitempty"`
	Id                openapi_types.UUID           `json:"id"`
	IsActive          bool                         `json:"is_active"`
	IsDefault         bool                         `json:"is_default"`
	Name              string                       `json:"name"`
	Scope             CredentialResponseScope      `json:"scope"`
	ScopeId           *openapi_types.UUID          `json:"scope_id,omitempty"`
	SshKeyBits        *int                         `json:"ssh_key_bits,omitempty"`
	SshKeyComment     *string                      `json:"ssh_key_comment,omitempty"`
	SshKeyFingerprint *string                      `json:"ssh_key_fingerprint,omitempty"`
	SshKeyType        *string                      `json:"ssh_key_type,omitempty"`
	UpdatedAt         *time.Time                   `json:"updated_at,omitempty"`
	Username          string                       `json:"username"`
}

CredentialResponse defines model for CredentialResponse.

type CredentialResponseAuthMethod

type CredentialResponseAuthMethod string

CredentialResponseAuthMethod defines model for CredentialResponse.AuthMethod.

const (
	CredentialResponseAuthMethodBoth     CredentialResponseAuthMethod = "both"
	CredentialResponseAuthMethodPassword CredentialResponseAuthMethod = "password"
	CredentialResponseAuthMethodSshKey   CredentialResponseAuthMethod = "ssh_key"
)

Defines values for CredentialResponseAuthMethod.

func (CredentialResponseAuthMethod) Valid

Valid indicates whether the value is a known member of the CredentialResponseAuthMethod enum.

type CredentialResponseScope

type CredentialResponseScope string

CredentialResponseScope defines model for CredentialResponse.Scope.

const (
	Host   CredentialResponseScope = "host"
	System CredentialResponseScope = "system"
)

Defines values for CredentialResponseScope.

func (CredentialResponseScope) Valid

func (e CredentialResponseScope) Valid() bool

Valid indicates whether the value is a known member of the CredentialResponseScope enum.

type CredentialUpdateRequest

type CredentialUpdateRequest struct {
	AuthMethod  *CredentialUpdateRequestAuthMethod `json:"auth_method,omitempty"`
	Description *string                            `json:"description,omitempty"`

	// IsDefault Setting true on a system credential atomically demotes the previous system default
	IsDefault *bool   `json:"is_default,omitempty"`
	Name      *string `json:"name,omitempty"`

	// Password Re-encrypts and replaces the stored password when non-empty; omit to keep the current secret
	Password *string `json:"password,omitempty"`

	// PrivateKey Re-encrypts and replaces the stored key when non-empty; omit to keep the current secret
	PrivateKey *string `json:"private_key,omitempty"`

	// PrivateKeyPassphrase Re-encrypts and replaces the stored passphrase when non-empty; omit to keep the current secret
	PrivateKeyPassphrase *string `json:"private_key_passphrase,omitempty"`
	Username             *string `json:"username,omitempty"`
}

CredentialUpdateRequest defines model for CredentialUpdateRequest.

type CredentialUpdateRequestAuthMethod

type CredentialUpdateRequestAuthMethod string

CredentialUpdateRequestAuthMethod defines model for CredentialUpdateRequest.AuthMethod.

const (
	Both     CredentialUpdateRequestAuthMethod = "both"
	Password CredentialUpdateRequestAuthMethod = "password"
	SshKey   CredentialUpdateRequestAuthMethod = "ssh_key"
)

Defines values for CredentialUpdateRequestAuthMethod.

func (CredentialUpdateRequestAuthMethod) Valid

Valid indicates whether the value is a known member of the CredentialUpdateRequestAuthMethod enum.

type CustomRoleCreateRequest

type CustomRoleCreateRequest struct {
	Description string   `json:"description"`
	Id          string   `json:"id"`
	Permissions []string `json:"permissions"`
}

CustomRoleCreateRequest defines model for CustomRoleCreateRequest.

type CustomRoleResponse

type CustomRoleResponse struct {
	Description string   `json:"description"`
	Id          string   `json:"id"`
	IsBuiltIn   bool     `json:"is_built_in"`
	Permissions []string `json:"permissions"`
}

CustomRoleResponse defines model for CustomRoleResponse.

type DiscoveryConfig

type DiscoveryConfig struct {
	// DetectOnFirstContact When true, POST /api/v1/hosts auto-enqueues a host.discovery job for the new host before returning 201. When false, new hosts stay at hosts.os_discovered_at NULL until the scheduler picks them up or an operator clicks Re-run discovery
	DetectOnFirstContact bool `json:"detect_on_first_contact"`

	// IntervalSec Per-host cadence — a host's discovery becomes due once now() - hosts.os_discovered_at exceeds this many seconds. 3600..604800. Default 86400 (24h)
	IntervalSec int `json:"interval_sec"`

	// MaintenanceGlobal When true, the scheduler loop ticks but enqueues no jobs and the host-create gate behaves as if detect_on_first_contact is false
	MaintenanceGlobal bool `json:"maintenance_global"`

	// RateLimit Max host.discovery jobs enqueued per scheduler tick (1..500). Default 25. Bounds thundering-herd on a fleet that hits NULL os_discovered_at simultaneously
	RateLimit int `json:"rate_limit"`
}

DiscoveryConfig defines model for DiscoveryConfig.

type DiscoveryConfigResponse

type DiscoveryConfigResponse struct {
	Config   DiscoveryConfig `json:"config"`
	Defaults DiscoveryConfig `json:"defaults"`
}

DiscoveryConfigResponse defines model for DiscoveryConfigResponse.

type DiscoverySweepResponse

type DiscoverySweepResponse struct {
	// Enqueued Count of host.discovery jobs persisted by this sweep. Zero is a valid steady state (every host already discovered, or fleet empty)
	Enqueued int `json:"enqueued"`
}

DiscoverySweepResponse defines model for DiscoverySweepResponse.

type EchoRequest

type EchoRequest struct {
	Message string `json:"message"`
}

EchoRequest defines model for EchoRequest.

type EchoResponse

type EchoResponse struct {
	AuditEventId  *openapi_types.UUID `json:"audit_event_id,omitempty"`
	CorrelationId string              `json:"correlation_id"`
	Echoed        string              `json:"echoed"`
}

EchoResponse defines model for EchoResponse.

type EnqueueTestJobResponse

type EnqueueTestJobResponse struct {
	CorrelationId string             `json:"correlation_id"`
	JobId         openapi_types.UUID `json:"job_id"`
}

EnqueueTestJobResponse defines model for EnqueueTestJobResponse.

type ErrorEnvelope

type ErrorEnvelope struct {
	Error struct {
		Code          string                  `json:"code"`
		CorrelationId *string                 `json:"correlation_id,omitempty"`
		Detail        *map[string]interface{} `json:"detail,omitempty"`
		Fault         ErrorEnvelopeErrorFault `json:"fault"`
		HumanMessage  string                  `json:"human_message"`
		Retryable     bool                    `json:"retryable"`
	} `json:"error"`
}

ErrorEnvelope defines model for ErrorEnvelope.

type ErrorEnvelopeErrorFault

type ErrorEnvelopeErrorFault string

ErrorEnvelopeErrorFault defines model for ErrorEnvelope.Error.Fault.

const (
	Client   ErrorEnvelopeErrorFault = "client"
	External ErrorEnvelopeErrorFault = "external"
	Policy   ErrorEnvelopeErrorFault = "policy"
	Server   ErrorEnvelopeErrorFault = "server"
)

Defines values for ErrorEnvelopeErrorFault.

func (ErrorEnvelopeErrorFault) Valid

func (e ErrorEnvelopeErrorFault) Valid() bool

Valid indicates whether the value is a known member of the ErrorEnvelopeErrorFault enum.

type EvaluateAlertRequest

type EvaluateAlertRequest struct {
	Score int `json:"score"`
}

EvaluateAlertRequest defines model for EvaluateAlertRequest.

type Exception

type Exception struct {
	ExpiresAt *time.Time         `json:"expires_at,omitempty"`
	HostId    openapi_types.UUID `json:"host_id"`

	// HostName Hostname, populated on list responses (empty on single-row lifecycle results)
	HostName    *string             `json:"host_name,omitempty"`
	Id          openapi_types.UUID  `json:"id"`
	Reason      string              `json:"reason"`
	RequestedAt time.Time           `json:"requested_at"`
	RequestedBy openapi_types.UUID  `json:"requested_by"`
	ReviewNote  *string             `json:"review_note,omitempty"`
	ReviewedAt  *time.Time          `json:"reviewed_at,omitempty"`
	ReviewedBy  *openapi_types.UUID `json:"reviewed_by,omitempty"`
	RuleId      string              `json:"rule_id"`
	Status      ExceptionStatus     `json:"status"`
}

Exception defines model for Exception.

type ExceptionList

type ExceptionList struct {
	Exceptions []Exception `json:"exceptions"`
}

ExceptionList defines model for ExceptionList.

type ExceptionRequest

type ExceptionRequest struct {
	// ExpiresAt Optional expiry; null means active until revoked
	ExpiresAt *time.Time `json:"expires_at,omitempty"`
	Reason    string     `json:"reason"`
	RuleId    string     `json:"rule_id"`
}

ExceptionRequest defines model for ExceptionRequest.

type ExceptionReview

type ExceptionReview struct {
	// Note Optional reviewer note
	Note *string `json:"note,omitempty"`
}

ExceptionReview defines model for ExceptionReview.

type ExceptionStatus

type ExceptionStatus string

ExceptionStatus defines model for Exception.Status.

const (
	ExceptionStatusApproved  ExceptionStatus = "approved"
	ExceptionStatusExpired   ExceptionStatus = "expired"
	ExceptionStatusRejected  ExceptionStatus = "rejected"
	ExceptionStatusRequested ExceptionStatus = "requested"
	ExceptionStatusRevoked   ExceptionStatus = "revoked"
)

Defines values for ExceptionStatus.

func (ExceptionStatus) Valid

func (e ExceptionStatus) Valid() bool

Valid indicates whether the value is a known member of the ExceptionStatus enum.

type FleetComplianceStates

type FleetComplianceStates struct {
	// States One entry per ComplianceState in ladder order; zero-count states included
	States []struct {
		HostCount int                              `json:"host_count"`
		State     FleetComplianceStatesStatesState `json:"state"`
	} `json:"states"`
}

FleetComplianceStates defines model for FleetComplianceStates.

type FleetComplianceStatesStatesState

type FleetComplianceStatesStatesState string

FleetComplianceStatesStatesState defines model for FleetComplianceStates.States.State.

const (
	FleetComplianceStatesStatesStateCompliant       FleetComplianceStatesStatesState = "compliant"
	FleetComplianceStatesStatesStateCritical        FleetComplianceStatesStatesState = "critical"
	FleetComplianceStatesStatesStateMostlyCompliant FleetComplianceStatesStatesState = "mostly_compliant"
	FleetComplianceStatesStatesStateNonCompliant    FleetComplianceStatesStatesState = "non_compliant"
	FleetComplianceStatesStatesStatePartial         FleetComplianceStatesStatesState = "partial"
	FleetComplianceStatesStatesStateUnknown         FleetComplianceStatesStatesState = "unknown"
)

Defines values for FleetComplianceStatesStatesState.

func (FleetComplianceStatesStatesState) Valid

Valid indicates whether the value is a known member of the FleetComplianceStatesStatesState enum.

type FleetComplianceTrend

type FleetComplianceTrend struct {
	// Days One entry per day with snapshots, oldest first
	Days []struct {
		CriticalHosts int                `json:"critical_hosts"`
		Date          openapi_types.Date `json:"date"`
		Envelope      ScoreEnvelope      `json:"envelope"`
		Failing       int                `json:"failing"`

		// FormulaStatus mixed means the day's snapshots were produced by MORE THAN ONE formula. Those measure different things, so the day reports no score rather than their average. legacy_unknown means every snapshot predates the current formula; its score is preserved and is not comparable with an identified one.
		FormulaStatus FleetComplianceTrendDaysFormulaStatus `json:"formula_status"`

		// FormulaVersion 2 when formula_status is identified, otherwise null.
		FormulaVersion *int `json:"formula_version"`

		// Hosts Every host with a snapshot that day, including hosts that produced no score and are therefore not in score_pct.
		Hosts int `json:"hosts"`

		// HostsScored Hosts that produced a score that day.
		HostsScored int `json:"hosts_scored"`

		// HostsWithoutScore Hosts with a snapshot that day but no score.
		HostsWithoutScore int `json:"hosts_without_score"`

		// ScorePct Equal-host mean over the hosts that produced a score that day, to one decimal. Not a pooled ratio, so a host with many rules does not outweigh one with few. NULL when no host produced a score, and NULL when formula_status is mixed.
		ScorePct *float32 `json:"score_pct"`
	} `json:"days"`
}

FleetComplianceTrend defines model for FleetComplianceTrend.

type FleetComplianceTrendDaysFormulaStatus added in v0.8.0

type FleetComplianceTrendDaysFormulaStatus string

FleetComplianceTrendDaysFormulaStatus mixed means the day's snapshots were produced by MORE THAN ONE formula. Those measure different things, so the day reports no score rather than their average. legacy_unknown means every snapshot predates the current formula; its score is preserved and is not comparable with an identified one.

const (
	FleetComplianceTrendDaysFormulaStatusIdentified    FleetComplianceTrendDaysFormulaStatus = "identified"
	FleetComplianceTrendDaysFormulaStatusLegacyUnknown FleetComplianceTrendDaysFormulaStatus = "legacy_unknown"
	FleetComplianceTrendDaysFormulaStatusMixed         FleetComplianceTrendDaysFormulaStatus = "mixed"
)

Defines values for FleetComplianceTrendDaysFormulaStatus.

func (FleetComplianceTrendDaysFormulaStatus) Valid added in v0.8.0

Valid indicates whether the value is a known member of the FleetComplianceTrendDaysFormulaStatus enum.

type FleetHostFailure

type FleetHostFailure struct {
	FailingRuleCount int64              `json:"failing_rule_count"`
	HostId           openapi_types.UUID `json:"host_id"`
}

FleetHostFailure defines model for FleetHostFailure.

type FleetLiveness

type FleetLiveness struct {
	NeverProbed int64 `json:"never_probed"`
	Reachable   int64 `json:"reachable"`
	Unknown     int64 `json:"unknown"`
	Unreachable int64 `json:"unreachable"`
}

FleetLiveness defines model for FleetLiveness.

type FleetRecentChanges

type FleetRecentChanges struct {
	Items []FleetTransaction `json:"items"`
}

FleetRecentChanges defines model for FleetRecentChanges.

type FleetRuleFailure

type FleetRuleFailure struct {
	FailingHostCount int64  `json:"failing_host_count"`
	RuleId           string `json:"rule_id"`
}

FleetRuleFailure defines model for FleetRuleFailure.

type FleetScanQueue

type FleetScanQueue struct {
	Queued  int64 `json:"queued"`
	Running int64 `json:"running"`
}

FleetScanQueue defines model for FleetScanQueue.

type FleetTopFailingHosts

type FleetTopFailingHosts struct {
	Items []FleetHostFailure `json:"items"`
}

FleetTopFailingHosts defines model for FleetTopFailingHosts.

type FleetTopFailingRules

type FleetTopFailingRules struct {
	Items []FleetRuleFailure `json:"items"`
}

FleetTopFailingRules defines model for FleetTopFailingRules.

type FleetTransaction

type FleetTransaction struct {
	ChangeKind FleetTransactionChangeKind `json:"change_kind"`
	HostId     openapi_types.UUID         `json:"host_id"`
	Id         openapi_types.UUID         `json:"id"`
	OccurredAt time.Time                  `json:"occurred_at"`
	RuleId     string                     `json:"rule_id"`
	Severity   *string                    `json:"severity,omitempty"`
	Status     FleetTransactionStatus     `json:"status"`
}

FleetTransaction defines model for FleetTransaction.

type FleetTransactionChangeKind

type FleetTransactionChangeKind string

FleetTransactionChangeKind defines model for FleetTransaction.ChangeKind.

const (
	FirstSeen       FleetTransactionChangeKind = "first_seen"
	SeverityChanged FleetTransactionChangeKind = "severity_changed"
	StateChanged    FleetTransactionChangeKind = "state_changed"
)

Defines values for FleetTransactionChangeKind.

func (FleetTransactionChangeKind) Valid

func (e FleetTransactionChangeKind) Valid() bool

Valid indicates whether the value is a known member of the FleetTransactionChangeKind enum.

type FleetTransactionStatus

type FleetTransactionStatus string

FleetTransactionStatus defines model for FleetTransaction.Status.

const (
	FleetTransactionStatusError   FleetTransactionStatus = "error"
	FleetTransactionStatusFail    FleetTransactionStatus = "fail"
	FleetTransactionStatusPass    FleetTransactionStatus = "pass"
	FleetTransactionStatusSkipped FleetTransactionStatus = "skipped"
)

Defines values for FleetTransactionStatus.

func (FleetTransactionStatus) Valid

func (e FleetTransactionStatus) Valid() bool

Valid indicates whether the value is a known member of the FleetTransactionStatus enum.

type Forbidden

type Forbidden = ErrorEnvelope

Forbidden defines model for Forbidden.

type FreshnessEntry added in v0.6.0

type FreshnessEntry struct {
	AttemptAt  time.Time `json:"attempt_at"`
	ObservedAt time.Time `json:"observed_at"`

	// Reason Present only on stale entries: why the category was not re-observed this run
	Reason *FreshnessEntryReason `json:"reason,omitempty"`
	Status FreshnessEntryStatus  `json:"status"`
}

FreshnessEntry Per-category collection freshness. status=ok when the category was observed on the most recent run; status=stale when the run did not observe it and the last-known-good value was carried forward (observed_at then points at the last successful observation). On a stale entry, reason records WHY it was not re-observed: denied (a fixable sudo/permission refusal), failed (transport or command failure), or timeout. Spec system-host-discovery / system-os-intelligence.

type FreshnessEntryReason added in v0.6.0

type FreshnessEntryReason string

FreshnessEntryReason Present only on stale entries: why the category was not re-observed this run

const (
	FreshnessEntryReasonDenied  FreshnessEntryReason = "denied"
	FreshnessEntryReasonFailed  FreshnessEntryReason = "failed"
	FreshnessEntryReasonTimeout FreshnessEntryReason = "timeout"
)

Defines values for FreshnessEntryReason.

func (FreshnessEntryReason) Valid added in v0.6.0

func (e FreshnessEntryReason) Valid() bool

Valid indicates whether the value is a known member of the FreshnessEntryReason enum.

type FreshnessEntryStatus added in v0.6.0

type FreshnessEntryStatus string

FreshnessEntryStatus defines model for FreshnessEntry.Status.

const (
	FreshnessEntryStatusOk    FreshnessEntryStatus = "ok"
	FreshnessEntryStatusStale FreshnessEntryStatus = "stale"
)

Defines values for FreshnessEntryStatus.

func (FreshnessEntryStatus) Valid added in v0.6.0

func (e FreshnessEntryStatus) Valid() bool

Valid indicates whether the value is a known member of the FreshnessEntryStatus enum.

type GenerateReportRequest

type GenerateReportRequest struct {
	// Framework Scope the report to this framework lens (framework_refs key).
	Framework *string `json:"framework,omitempty"`

	// GroupId Scope the report to this group's member hosts.
	GroupId *openapi_types.UUID `json:"group_id,omitempty"`

	// Kind The report kind; defaults to executive. attestation produces
	// the Framework Attestation (CSV/OSCAL bulk faces over the latest
	// completed scan per in-scope host); exception produces the
	// Exception Register; remediation produces the Remediation
	// Activity log over a look-back period.
	Kind *GenerateReportRequestKind `json:"kind,omitempty"`

	// PeriodDays Look-back window in days for time-windowed kinds (remediation):
	// the report covers requests filed in the last period_days.
	// Defaults to 30; ignored by point-in-time kinds.
	PeriodDays *int `json:"period_days,omitempty"`
}

GenerateReportRequest Optional kind + scope for the report. An empty body (or empty object) generates the all-hosts, all-frameworks executive summary.

type GenerateReportRequestKind

type GenerateReportRequestKind string

GenerateReportRequestKind The report kind; defaults to executive. attestation produces the Framework Attestation (CSV/OSCAL bulk faces over the latest completed scan per in-scope host); exception produces the Exception Register; remediation produces the Remediation Activity log over a look-back period.

const (
	GenerateReportRequestKindAttestation GenerateReportRequestKind = "attestation"
	GenerateReportRequestKindException   GenerateReportRequestKind = "exception"
	GenerateReportRequestKindExecutive   GenerateReportRequestKind = "executive"
	GenerateReportRequestKindRemediation GenerateReportRequestKind = "remediation"
)

Defines values for GenerateReportRequestKind.

func (GenerateReportRequestKind) Valid

func (e GenerateReportRequestKind) Valid() bool

Valid indicates whether the value is a known member of the GenerateReportRequestKind enum.

type GetActivityParams

type GetActivityParams struct {
	Source   *GetActivityParamsSource   `form:"source,omitempty" json:"source,omitempty"`
	Severity *GetActivityParamsSeverity `form:"severity,omitempty" json:"severity,omitempty"`
	HostId   *openapi_types.UUID        `form:"host_id,omitempty" json:"host_id,omitempty"`
	Since    *time.Time                 `form:"since,omitempty" json:"since,omitempty"`
	Until    *time.Time                 `form:"until,omitempty" json:"until,omitempty"`
	Cursor   *string                    `form:"cursor,omitempty" json:"cursor,omitempty"`
	Limit    *int                       `form:"limit,omitempty" json:"limit,omitempty"`
}

GetActivityParams defines parameters for GetActivity.

type GetActivityParamsSeverity

type GetActivityParamsSeverity string

GetActivityParamsSeverity defines parameters for GetActivity.

const (
	GetActivityParamsSeverityCritical GetActivityParamsSeverity = "critical"
	GetActivityParamsSeverityHigh     GetActivityParamsSeverity = "high"
	GetActivityParamsSeverityInfo     GetActivityParamsSeverity = "info"
	GetActivityParamsSeverityLow      GetActivityParamsSeverity = "low"
	GetActivityParamsSeverityMedium   GetActivityParamsSeverity = "medium"
)

Defines values for GetActivityParamsSeverity.

func (GetActivityParamsSeverity) Valid

func (e GetActivityParamsSeverity) Valid() bool

Valid indicates whether the value is a known member of the GetActivityParamsSeverity enum.

type GetActivityParamsSource

type GetActivityParamsSource string

GetActivityParamsSource defines parameters for GetActivity.

const (
	GetActivityParamsSourceAlert        GetActivityParamsSource = "alert"
	GetActivityParamsSourceAudit        GetActivityParamsSource = "audit"
	GetActivityParamsSourceIntelligence GetActivityParamsSource = "intelligence"
	GetActivityParamsSourceMonitoring   GetActivityParamsSource = "monitoring"
	GetActivityParamsSourceTransaction  GetActivityParamsSource = "transaction"
)

Defines values for GetActivityParamsSource.

func (GetActivityParamsSource) Valid

func (e GetActivityParamsSource) Valid() bool

Valid indicates whether the value is a known member of the GetActivityParamsSource enum.

type GetAlertsParams

type GetAlertsParams struct {
	State    *GetAlertsParamsState    `form:"state,omitempty" json:"state,omitempty"`
	HostId   *openapi_types.UUID      `form:"host_id,omitempty" json:"host_id,omitempty"`
	Severity *GetAlertsParamsSeverity `form:"severity,omitempty" json:"severity,omitempty"`
	Since    *time.Time               `form:"since,omitempty" json:"since,omitempty"`
	Until    *time.Time               `form:"until,omitempty" json:"until,omitempty"`
	Cursor   *string                  `form:"cursor,omitempty" json:"cursor,omitempty"`
	Limit    *int                     `form:"limit,omitempty" json:"limit,omitempty"`
}

GetAlertsParams defines parameters for GetAlerts.

type GetAlertsParamsSeverity

type GetAlertsParamsSeverity string

GetAlertsParamsSeverity defines parameters for GetAlerts.

const (
	GetAlertsParamsSeverityCritical GetAlertsParamsSeverity = "critical"
	GetAlertsParamsSeverityHigh     GetAlertsParamsSeverity = "high"
	GetAlertsParamsSeverityInfo     GetAlertsParamsSeverity = "info"
	GetAlertsParamsSeverityLow      GetAlertsParamsSeverity = "low"
	GetAlertsParamsSeverityMedium   GetAlertsParamsSeverity = "medium"
)

Defines values for GetAlertsParamsSeverity.

func (GetAlertsParamsSeverity) Valid

func (e GetAlertsParamsSeverity) Valid() bool

Valid indicates whether the value is a known member of the GetAlertsParamsSeverity enum.

type GetAlertsParamsState

type GetAlertsParamsState string

GetAlertsParamsState defines parameters for GetAlerts.

const (
	Acknowledged GetAlertsParamsState = "acknowledged"
	Active       GetAlertsParamsState = "active"
	Dismissed    GetAlertsParamsState = "dismissed"
	Resolved     GetAlertsParamsState = "resolved"
	Silenced     GetAlertsParamsState = "silenced"
)

Defines values for GetAlertsParamsState.

func (GetAlertsParamsState) Valid

func (e GetAlertsParamsState) Valid() bool

Valid indicates whether the value is a known member of the GetAlertsParamsState enum.

type GetAuditEventsExportParams

type GetAuditEventsExportParams struct {
	// Format Output format. Defaults to csv.
	Format        *GetAuditEventsExportParamsFormat `form:"format,omitempty" json:"format,omitempty"`
	Action        *string                           `form:"action,omitempty" json:"action,omitempty"`
	CorrelationId *string                           `form:"correlation_id,omitempty" json:"correlation_id,omitempty"`
	ActorType     *string                           `form:"actor_type,omitempty" json:"actor_type,omitempty"`
	ResourceType  *string                           `form:"resource_type,omitempty" json:"resource_type,omitempty"`
	ResourceId    *string                           `form:"resource_id,omitempty" json:"resource_id,omitempty"`
	Since         *time.Time                        `form:"since,omitempty" json:"since,omitempty"`
	Until         *time.Time                        `form:"until,omitempty" json:"until,omitempty"`
}

GetAuditEventsExportParams defines parameters for GetAuditEventsExport.

type GetAuditEventsExportParamsFormat

type GetAuditEventsExportParamsFormat string

GetAuditEventsExportParamsFormat defines parameters for GetAuditEventsExport.

const (
	GetAuditEventsExportParamsFormatCsv  GetAuditEventsExportParamsFormat = "csv"
	GetAuditEventsExportParamsFormatJson GetAuditEventsExportParamsFormat = "json"
)

Defines values for GetAuditEventsExportParamsFormat.

func (GetAuditEventsExportParamsFormat) Valid

Valid indicates whether the value is a known member of the GetAuditEventsExportParamsFormat enum.

type GetAuditEventsParams

type GetAuditEventsParams struct {
	Action        *string `form:"action,omitempty" json:"action,omitempty"`
	CorrelationId *string `form:"correlation_id,omitempty" json:"correlation_id,omitempty"`
	ActorType     *string `form:"actor_type,omitempty" json:"actor_type,omitempty"`

	// ResourceType Filter to events whose resource_type matches (e.g. "host"). Pair with resource_id for a single resource's audit trail.
	ResourceType *string `form:"resource_type,omitempty" json:"resource_type,omitempty"`

	// ResourceId Filter to events whose resource_id matches (e.g. a host UUID). Typically paired with resource_type.
	ResourceId *string    `form:"resource_id,omitempty" json:"resource_id,omitempty"`
	Since      *time.Time `form:"since,omitempty" json:"since,omitempty"`
	Until      *time.Time `form:"until,omitempty" json:"until,omitempty"`
	Cursor     *string    `form:"cursor,omitempty" json:"cursor,omitempty"`
	Limit      *int       `form:"limit,omitempty" json:"limit,omitempty"`
}

GetAuditEventsParams defines parameters for GetAuditEvents.

type GetAuthSSOCallbackParams

type GetAuthSSOCallbackParams struct {
	Code  *string `form:"code,omitempty" json:"code,omitempty"`
	State *string `form:"state,omitempty" json:"state,omitempty"`
	Error *string `form:"error,omitempty" json:"error,omitempty"`
}

GetAuthSSOCallbackParams defines parameters for GetAuthSSOCallback.

type GetAuthSSOLoginParams

type GetAuthSSOLoginParams struct {
	ReturnTo *string `form:"return_to,omitempty" json:"return_to,omitempty"`
}

GetAuthSSOLoginParams defines parameters for GetAuthSSOLogin.

type GetComplianceExceptionsParams

type GetComplianceExceptionsParams struct {
	Status *GetComplianceExceptionsParamsStatus `form:"status,omitempty" json:"status,omitempty"`
	Limit  *int                                 `form:"limit,omitempty" json:"limit,omitempty"`
}

GetComplianceExceptionsParams defines parameters for GetComplianceExceptions.

type GetComplianceExceptionsParamsStatus

type GetComplianceExceptionsParamsStatus string

GetComplianceExceptionsParamsStatus defines parameters for GetComplianceExceptions.

const (
	GetComplianceExceptionsParamsStatusApproved  GetComplianceExceptionsParamsStatus = "approved"
	GetComplianceExceptionsParamsStatusExpired   GetComplianceExceptionsParamsStatus = "expired"
	GetComplianceExceptionsParamsStatusRejected  GetComplianceExceptionsParamsStatus = "rejected"
	GetComplianceExceptionsParamsStatusRequested GetComplianceExceptionsParamsStatus = "requested"
	GetComplianceExceptionsParamsStatusRevoked   GetComplianceExceptionsParamsStatus = "revoked"
)

Defines values for GetComplianceExceptionsParamsStatus.

func (GetComplianceExceptionsParamsStatus) Valid

Valid indicates whether the value is a known member of the GetComplianceExceptionsParamsStatus enum.

type GetComplianceFrameworksParams added in v0.5.0

type GetComplianceFrameworksParams struct {
	// All When true, return every corpus family, ignoring the enabled-frameworks allowlist.
	All *bool `form:"all,omitempty" json:"all,omitempty"`
}

GetComplianceFrameworksParams defines parameters for GetComplianceFrameworks.

type GetFleetComplianceTrendParams

type GetFleetComplianceTrendParams struct {
	// Days Trailing window in days; clamped into [1, 90]
	Days *int `form:"days,omitempty" json:"days,omitempty"`
}

GetFleetComplianceTrendParams defines parameters for GetFleetComplianceTrend.

type GetFleetRecentChangesParams

type GetFleetRecentChangesParams struct {
	// Framework Filter to transactions whose framework_refs contains this key (v1.1.0).
	Framework *string `form:"framework,omitempty" json:"framework,omitempty"`

	// Since Filter to transactions strictly newer than this RFC3339 timestamp
	Since *time.Time `form:"since,omitempty" json:"since,omitempty"`
	Limit *int       `form:"limit,omitempty" json:"limit,omitempty"`
}

GetFleetRecentChangesParams defines parameters for GetFleetRecentChanges.

type GetFleetScoreParams

type GetFleetScoreParams struct {
	// Framework Filter to host_rule_state rows whose framework_refs contains this key (v1.1.0).
	Framework *string `form:"framework,omitempty" json:"framework,omitempty"`
}

GetFleetScoreParams defines parameters for GetFleetScore.

type GetFleetTopFailingHostsParams

type GetFleetTopFailingHostsParams struct {
	// Framework Filter to host_rule_state rows whose framework_refs contains this key (v1.1.0).
	Framework *string `form:"framework,omitempty" json:"framework,omitempty"`
	Limit     *int    `form:"limit,omitempty" json:"limit,omitempty"`
}

GetFleetTopFailingHostsParams defines parameters for GetFleetTopFailingHosts.

type GetFleetTopFailingRulesParams

type GetFleetTopFailingRulesParams struct {
	// Framework Filter to host_rule_state rows whose framework_refs contains this key (v1.1.0).
	Framework *string `form:"framework,omitempty" json:"framework,omitempty"`
	Limit     *int    `form:"limit,omitempty" json:"limit,omitempty"`
}

GetFleetTopFailingRulesParams defines parameters for GetFleetTopFailingRules.

type GetHostByIDParams

type GetHostByIDParams struct {
	// Framework Filter compliance_summary to host_rule_state rows whose framework_refs contains this key (v1.2.0). Liveness is unaffected.
	Framework *string `form:"framework,omitempty" json:"framework,omitempty"`
}

GetHostByIDParams defines parameters for GetHostByID.

type GetHostComplianceParams

type GetHostComplianceParams struct {
	// Framework Filter to rows whose framework_refs contains this key and project its control ids; summary and categories are recomputed under the filter.
	Framework *string `form:"framework,omitempty" json:"framework,omitempty"`
}

GetHostComplianceParams defines parameters for GetHostCompliance.

type GetHostComplianceTrendParams

type GetHostComplianceTrendParams struct {
	// Days Trailing window in days; clamped into [1, 90]
	Days *int `form:"days,omitempty" json:"days,omitempty"`
}

GetHostComplianceTrendParams defines parameters for GetHostComplianceTrend.

type GetHostExceptionsParams

type GetHostExceptionsParams struct {
	History *bool `form:"history,omitempty" json:"history,omitempty"`
}

GetHostExceptionsParams defines parameters for GetHostExceptions.

type GetHostFailedRulesParams

type GetHostFailedRulesParams struct {
	// Limit Max rules returned. Clamped to [1, 100]; default 10.
	Limit *int `form:"limit,omitempty" json:"limit,omitempty"`

	// Framework Filter to rows whose framework_refs contains this key and project its control ids.
	Framework *string `form:"framework,omitempty" json:"framework,omitempty"`
}

GetHostFailedRulesParams defines parameters for GetHostFailedRules.

type GetHostMonitoringHistoryParams

type GetHostMonitoringHistoryParams struct {
	Limit *int `form:"limit,omitempty" json:"limit,omitempty"`
}

GetHostMonitoringHistoryParams defines parameters for GetHostMonitoringHistory.

type GetHostsParams

type GetHostsParams struct {
	Environment *string `form:"environment,omitempty" json:"environment,omitempty"`
	Tag         *string `form:"tag,omitempty" json:"tag,omitempty"`

	// Framework Lens each host card's compliance_summary through a framework family (e.g. "stig") or a specific corpus key; omit for All rules.
	Framework *string `form:"framework,omitempty" json:"framework,omitempty"`
}

GetHostsParams defines parameters for GetHosts.

type GetIntelligenceEventsParams

type GetIntelligenceEventsParams struct {
	HostId    *openapi_types.UUID                  `form:"host_id,omitempty" json:"host_id,omitempty"`
	EventCode *string                              `form:"event_code,omitempty" json:"event_code,omitempty"`
	Severity  *GetIntelligenceEventsParamsSeverity `form:"severity,omitempty" json:"severity,omitempty"`
	Since     *time.Time                           `form:"since,omitempty" json:"since,omitempty"`
	Until     *time.Time                           `form:"until,omitempty" json:"until,omitempty"`
	Cursor    *string                              `form:"cursor,omitempty" json:"cursor,omitempty"`
	Limit     *int                                 `form:"limit,omitempty" json:"limit,omitempty"`
}

GetIntelligenceEventsParams defines parameters for GetIntelligenceEvents.

type GetIntelligenceEventsParamsSeverity

type GetIntelligenceEventsParamsSeverity string

GetIntelligenceEventsParamsSeverity defines parameters for GetIntelligenceEvents.

Defines values for GetIntelligenceEventsParamsSeverity.

func (GetIntelligenceEventsParamsSeverity) Valid

Valid indicates whether the value is a known member of the GetIntelligenceEventsParamsSeverity enum.

type GetNotificationFeedParams

type GetNotificationFeedParams struct {
	// Unread When true, return only unread notifications.
	Unread *bool `form:"unread,omitempty" json:"unread,omitempty"`

	// Limit Max items to return (default 50).
	Limit *int `form:"limit,omitempty" json:"limit,omitempty"`
}

GetNotificationFeedParams defines parameters for GetNotificationFeed.

type GetReportExportParams

type GetReportExportParams struct {
	// Format The face to render. Defaults to pdf.
	Format *GetReportExportParamsFormat `form:"format,omitempty" json:"format,omitempty"`
}

GetReportExportParams defines parameters for GetReportExport.

type GetReportExportParamsFormat

type GetReportExportParamsFormat string

GetReportExportParamsFormat defines parameters for GetReportExport.

const (
	GetReportExportParamsFormatCsv      GetReportExportParamsFormat = "csv"
	GetReportExportParamsFormatJson     GetReportExportParamsFormat = "json"
	GetReportExportParamsFormatOscalSar GetReportExportParamsFormat = "oscal_sar"
	GetReportExportParamsFormatPdf      GetReportExportParamsFormat = "pdf"
)

Defines values for GetReportExportParamsFormat.

func (GetReportExportParamsFormat) Valid

Valid indicates whether the value is a known member of the GetReportExportParamsFormat enum.

type GetScansParams

type GetScansParams struct {
	HostId openapi_types.UUID `form:"host_id" json:"host_id"`
	Limit  *int               `form:"limit,omitempty" json:"limit,omitempty"`

	// Cursor queued_at of the last row already seen (RFC3339); omit to start at the newest
	Cursor *time.Time `form:"cursor,omitempty" json:"cursor,omitempty"`
}

GetScansParams defines parameters for GetScans.

type Group

type Group struct {
	// Color Design-token color key (e.g. info)
	Color       string             `json:"color"`
	CreatedAt   time.Time          `json:"created_at"`
	Id          openapi_types.UUID `json:"id"`
	Kind        GroupKind          `json:"kind"`
	Maintenance bool               `json:"maintenance"`

	// MatchFamily OS family an auto group matches on (empty for manual groups)
	MatchFamily *string         `json:"match_family,omitempty"`
	Membership  GroupMembership `json:"membership"`
	Name        string          `json:"name"`

	// Subtype Free-form sub-classifier (may be empty)
	Subtype string `json:"subtype"`

	// TargetFramework Compliance target framework family a member host is held to (empty for none). Only a site group may carry one.
	TargetFramework *string   `json:"target_framework,omitempty"`
	UpdatedAt       time.Time `json:"updated_at"`
}

Group defines model for Group.

type GroupCreate

type GroupCreate struct {
	Color *string         `json:"color,omitempty"`
	Kind  GroupCreateKind `json:"kind"`

	// MatchFamily Required for auto membership; must be empty for manual
	MatchFamily *string               `json:"match_family,omitempty"`
	Membership  GroupCreateMembership `json:"membership"`
	Name        string                `json:"name"`
	Subtype     *string               `json:"subtype,omitempty"`
}

GroupCreate defines model for GroupCreate.

type GroupCreateKind

type GroupCreateKind string

GroupCreateKind defines model for GroupCreate.Kind.

const (
	GroupCreateKindOsCategory GroupCreateKind = "os_category"
	GroupCreateKindSite       GroupCreateKind = "site"
)

Defines values for GroupCreateKind.

func (GroupCreateKind) Valid

func (e GroupCreateKind) Valid() bool

Valid indicates whether the value is a known member of the GroupCreateKind enum.

type GroupCreateMembership

type GroupCreateMembership string

GroupCreateMembership defines model for GroupCreate.Membership.

const (
	GroupCreateMembershipAuto   GroupCreateMembership = "auto"
	GroupCreateMembershipManual GroupCreateMembership = "manual"
)

Defines values for GroupCreateMembership.

func (GroupCreateMembership) Valid

func (e GroupCreateMembership) Valid() bool

Valid indicates whether the value is a known member of the GroupCreateMembership enum.

type GroupKind

type GroupKind string

GroupKind defines model for Group.Kind.

const (
	GroupKindOsCategory GroupKind = "os_category"
	GroupKindSite       GroupKind = "site"
)

Defines values for GroupKind.

func (GroupKind) Valid

func (e GroupKind) Valid() bool

Valid indicates whether the value is a known member of the GroupKind enum.

type GroupListResponse

type GroupListResponse struct {
	Groups  []GroupWithRollup `json:"groups"`
	Summary GroupSummary      `json:"summary"`
}

GroupListResponse defines model for GroupListResponse.

type GroupMaintenanceRequest

type GroupMaintenanceRequest struct {
	On bool `json:"on"`
}

GroupMaintenanceRequest defines model for GroupMaintenanceRequest.

type GroupMember

type GroupMember struct {
	HostId   openapi_types.UUID `json:"host_id"`
	Hostname string             `json:"hostname"`

	// Status Host monitoring band (online, down, unknown, ...)
	Status string `json:"status"`
}

GroupMember defines model for GroupMember.

type GroupMemberRequest

type GroupMemberRequest struct {
	HostId openapi_types.UUID `json:"host_id"`
}

GroupMemberRequest defines model for GroupMemberRequest.

type GroupMembership

type GroupMembership string

GroupMembership defines model for Group.Membership.

const (
	GroupMembershipAuto   GroupMembership = "auto"
	GroupMembershipManual GroupMembership = "manual"
)

Defines values for GroupMembership.

func (GroupMembership) Valid

func (e GroupMembership) Valid() bool

Valid indicates whether the value is a known member of the GroupMembership enum.

type GroupRollup

type GroupRollup struct {
	CriticalHosts int            `json:"critical_hosts"`
	Down          int            `json:"down"`
	Hosts         int            `json:"hosts"`
	Members       []GroupMember  `json:"members"`
	Online        int            `json:"online"`
	Score         AggregateScore `json:"score"`
}

GroupRollup defines model for GroupRollup.

type GroupSummary

type GroupSummary struct {
	Groups           int            `json:"groups"`
	HostsMaintenance int            `json:"hosts_maintenance"`
	OsCategories     int            `json:"os_categories"`
	Score            AggregateScore `json:"score"`
	Sites            int            `json:"sites"`
	Ungrouped        int            `json:"ungrouped"`
}

GroupSummary defines model for GroupSummary.

type GroupTargetRequest added in v0.5.0

type GroupTargetRequest struct {
	// TargetFramework Compliance target family id, or empty to clear the target.
	TargetFramework string `json:"target_framework"`
}

GroupTargetRequest defines model for GroupTargetRequest.

type GroupUpdate

type GroupUpdate struct {
	Color   *string `json:"color,omitempty"`
	Name    string  `json:"name"`
	Subtype *string `json:"subtype,omitempty"`
}

GroupUpdate defines model for GroupUpdate.

type GroupWithRollup

type GroupWithRollup struct {
	// Color Design-token color key (e.g. info)
	Color       string              `json:"color"`
	CreatedAt   time.Time           `json:"created_at"`
	Id          openapi_types.UUID  `json:"id"`
	Kind        GroupWithRollupKind `json:"kind"`
	Maintenance bool                `json:"maintenance"`

	// MatchFamily OS family an auto group matches on (empty for manual groups)
	MatchFamily *string                   `json:"match_family,omitempty"`
	Membership  GroupWithRollupMembership `json:"membership"`
	Name        string                    `json:"name"`
	Rollup      GroupRollup               `json:"rollup"`

	// Subtype Free-form sub-classifier (may be empty)
	Subtype string `json:"subtype"`

	// TargetFramework Compliance target framework family a member host is held to (empty for none). Only a site group may carry one.
	TargetFramework *string   `json:"target_framework,omitempty"`
	UpdatedAt       time.Time `json:"updated_at"`
}

GroupWithRollup defines model for GroupWithRollup.

type GroupWithRollupKind

type GroupWithRollupKind string

GroupWithRollupKind defines model for GroupWithRollup.Kind.

const (
	OsCategory GroupWithRollupKind = "os_category"
	Site       GroupWithRollupKind = "site"
)

Defines values for GroupWithRollupKind.

func (GroupWithRollupKind) Valid

func (e GroupWithRollupKind) Valid() bool

Valid indicates whether the value is a known member of the GroupWithRollupKind enum.

type GroupWithRollupMembership

type GroupWithRollupMembership string

GroupWithRollupMembership defines model for GroupWithRollup.Membership.

const (
	Auto   GroupWithRollupMembership = "auto"
	Manual GroupWithRollupMembership = "manual"
)

Defines values for GroupWithRollupMembership.

func (GroupWithRollupMembership) Valid

func (e GroupWithRollupMembership) Valid() bool

Valid indicates whether the value is a known member of the GroupWithRollupMembership enum.

type HealthResponse

type HealthResponse struct {
	DbConnected bool                 `json:"db_connected"`
	Status      HealthResponseStatus `json:"status"`
	Version     string               `json:"version"`
}

HealthResponse defines model for HealthResponse.

type HealthResponseStatus

type HealthResponseStatus string

HealthResponseStatus defines model for HealthResponse.Status.

const (
	HealthResponseStatusDegraded HealthResponseStatus = "degraded"
	HealthResponseStatusHealthy  HealthResponseStatus = "healthy"
)

Defines values for HealthResponseStatus.

func (HealthResponseStatus) Valid

func (e HealthResponseStatus) Valid() bool

Valid indicates whether the value is a known member of the HealthResponseStatus enum.

type HostComplianceCategory

type HostComplianceCategory struct {
	// Category Kensa catalog category; uncategorized when the catalog lacks the rule.
	Category string `json:"category"`
	Failing  int64  `json:"failing"`
	Passing  int64  `json:"passing"`

	// ScorePct Passing over passing plus failing within this category, to one decimal, computed server side. NULL when the category produced no verdict. Sent rather than derived so the browser holds no compliance arithmetic (system-compliance-scoring C-14).
	ScorePct *float64 `json:"score_pct"`
	Total    int64    `json:"total"`
}

HostComplianceCategory defines model for HostComplianceCategory.

type HostComplianceFramework

type HostComplianceFramework struct {
	Envelope ScoreEnvelope `json:"envelope"`

	// Failing Rows mapped to this framework with current_status fail.
	Failing     int    `json:"failing"`
	FrameworkId string `json:"framework_id"`

	// Label Display label for framework_id, taken from Kensa's framework vocabulary ("NIST SP 800-171 Rev 2", "CIS (RHEL 9)"). An id Kensa does not know is returned as it is. "All rules" on the overall entry, whose framework_id is "all".
	Label string `json:"label"`

	// Passing Rows mapped to this framework with current_status pass.
	Passing int `json:"passing"`

	// RuleCount Number of host_rule_state rows mapped to this framework.
	RuleCount int64 `json:"rule_count"`

	// ScorePct Passing over passing plus failing, to one decimal. NULL when this framework's rules produced no verdict. Not over rule_count, which counts rules that were skipped or errored. Powers the per-lens score on the View-as chips.
	ScorePct *float32 `json:"score_pct"`
}

HostComplianceFramework defines model for HostComplianceFramework.

type HostComplianceFrameworksResponse

type HostComplianceFrameworksResponse struct {
	Frameworks []HostComplianceFramework `json:"frameworks"`
	Overall    HostComplianceFramework   `json:"overall"`
}

HostComplianceFrameworksResponse defines model for HostComplianceFrameworksResponse.

type HostComplianceLensResponse

type HostComplianceLensResponse struct {
	Categories  []HostComplianceCategory  `json:"categories"`
	Rules       []HostComplianceRule      `json:"rules"`
	ScanContext HostScanContext           `json:"scan_context"`
	Summary     HostComplianceLensSummary `json:"summary"`
}

HostComplianceLensResponse defines model for HostComplianceLensResponse.

type HostComplianceLensSummary

type HostComplianceLensSummary struct {
	// CoveragePct Non-null if and only if coverage_status is available.
	CoveragePct *float64 `json:"coverage_pct"`

	// CoverageStatus Whether the share of in-scope rules that produced a verdict can be stated, and when it cannot, why.
	CoverageStatus HostComplianceLensSummaryCoverageStatus `json:"coverage_status"`
	Envelope       ScoreEnvelope                           `json:"envelope"`
	Error          int64                                   `json:"error"`
	Failing        int64                                   `json:"failing"`
	Passing        int64                                   `json:"passing"`

	// ScorePct Passing over passing plus failing, to one decimal. NULL when no rule produced a verdict, which is a different fact from every evaluated rule failing (that is 0).
	ScorePct *float64 `json:"score_pct"`
	Skipped  int64    `json:"skipped"`
	Total    int64    `json:"total"`
}

HostComplianceLensSummary defines model for HostComplianceLensSummary.

type HostComplianceLensSummaryCoverageStatus added in v0.8.0

type HostComplianceLensSummaryCoverageStatus string

HostComplianceLensSummaryCoverageStatus Whether the share of in-scope rules that produced a verdict can be stated, and when it cannot, why.

const (
	HostComplianceLensSummaryCoverageStatusAvailable                    HostComplianceLensSummaryCoverageStatus = "available"
	HostComplianceLensSummaryCoverageStatusUnavailableNoOutcomes        HostComplianceLensSummaryCoverageStatus = "unavailable_no_outcomes"
	HostComplianceLensSummaryCoverageStatusUnavailableUnclassifiedSkips HostComplianceLensSummaryCoverageStatus = "unavailable_unclassified_skips"
)

Defines values for HostComplianceLensSummaryCoverageStatus.

func (HostComplianceLensSummaryCoverageStatus) Valid added in v0.8.0

Valid indicates whether the value is a known member of the HostComplianceLensSummaryCoverageStatus enum.

type HostComplianceRule

type HostComplianceRule struct {
	// Category Catalog category; uncategorized when unknown.
	Category string `json:"category"`

	// ControlIds Control ids for the requested framework; empty unless ?framework= is given.
	ControlIds []string `json:"control_ids"`

	// Description First sentence of the catalog description; empty when the catalog lacks the rule. Catalog text only, never stored check output.
	Description   string    `json:"description"`
	LastCheckedAt time.Time `json:"last_checked_at"`
	RuleId        string    `json:"rule_id"`

	// Severity Stored severity; empty when the scan recorded none.
	Severity string `json:"severity"`

	// Status current_status of the rule on this host (pass, fail, skipped, error).
	Status string `json:"status"`

	// Title Catalog title; falls back to rule_id when the catalog lacks the rule.
	Title string `json:"title"`
}

HostComplianceRule defines model for HostComplianceRule.

type HostComplianceSchedule

type HostComplianceSchedule struct {
	ComplianceState HostComplianceScheduleComplianceState `json:"compliance_state"`

	// HostMaintenance Per-host maintenance flag on the schedule row
	HostMaintenance bool `json:"host_maintenance"`

	// IntervalMinutes Current per-state interval; 0 when unseeded
	IntervalMinutes int `json:"interval_minutes"`

	// NextScanAt Null when the host has no schedule row yet
	NextScanAt *time.Time `json:"next_scan_at,omitempty"`

	// SchedulerEnabled The scan config enabled flag
	SchedulerEnabled bool `json:"scheduler_enabled"`

	// SchedulerPaused True when the scheduler dispatches nothing fleet-wide (disabled or global maintenance)
	SchedulerPaused bool `json:"scheduler_paused"`
}

HostComplianceSchedule defines model for HostComplianceSchedule.

type HostComplianceScheduleComplianceState

type HostComplianceScheduleComplianceState string

HostComplianceScheduleComplianceState defines model for HostComplianceSchedule.ComplianceState.

const (
	HostComplianceScheduleComplianceStateCompliant       HostComplianceScheduleComplianceState = "compliant"
	HostComplianceScheduleComplianceStateCritical        HostComplianceScheduleComplianceState = "critical"
	HostComplianceScheduleComplianceStateMostlyCompliant HostComplianceScheduleComplianceState = "mostly_compliant"
	HostComplianceScheduleComplianceStateNonCompliant    HostComplianceScheduleComplianceState = "non_compliant"
	HostComplianceScheduleComplianceStatePartial         HostComplianceScheduleComplianceState = "partial"
	HostComplianceScheduleComplianceStateUnknown         HostComplianceScheduleComplianceState = "unknown"
)

Defines values for HostComplianceScheduleComplianceState.

func (HostComplianceScheduleComplianceState) Valid

Valid indicates whether the value is a known member of the HostComplianceScheduleComplianceState enum.

type HostComplianceSummary

type HostComplianceSummary struct {
	// CoveragePct Non-null if and only if coverage_status is available.
	CoveragePct *float64 `json:"coverage_pct"`

	// CoverageStatus Whether coverage can be stated for this host, and if not, why.
	CoverageStatus HostComplianceSummaryCoverageStatus `json:"coverage_status"`
	Envelope       ScoreEnvelope                       `json:"envelope"`
	Error          int64                               `json:"error"`
	Failing        int64                               `json:"failing"`
	Passing        int64                               `json:"passing"`

	// ScorePct Passing over passing plus failing, to one decimal. NULL when no rule produced a verdict. This is the PRIMARY single-host score, and it is computed server side: the host detail page used to derive passing/total in the browser, so a host whose rules all skipped displayed 0% instead of no score.
	ScorePct *float64 `json:"score_pct"`
	Skipped  int64    `json:"skipped"`
	Total    int64    `json:"total"`
}

HostComplianceSummary defines model for HostComplianceSummary.

type HostComplianceSummaryCoverageStatus added in v0.8.0

type HostComplianceSummaryCoverageStatus string

HostComplianceSummaryCoverageStatus Whether coverage can be stated for this host, and if not, why.

const (
	HostComplianceSummaryCoverageStatusAvailable                    HostComplianceSummaryCoverageStatus = "available"
	HostComplianceSummaryCoverageStatusUnavailableNoOutcomes        HostComplianceSummaryCoverageStatus = "unavailable_no_outcomes"
	HostComplianceSummaryCoverageStatusUnavailableUnclassifiedSkips HostComplianceSummaryCoverageStatus = "unavailable_unclassified_skips"
)

Defines values for HostComplianceSummaryCoverageStatus.

func (HostComplianceSummaryCoverageStatus) Valid added in v0.8.0

Valid indicates whether the value is a known member of the HostComplianceSummaryCoverageStatus enum.

type HostComplianceTrend

type HostComplianceTrend struct {
	// Days One entry per day with a snapshot, oldest first
	Days []struct {
		Date     openapi_types.Date `json:"date"`
		Envelope ScoreEnvelope      `json:"envelope"`
		Failing  int                `json:"failing"`

		// FormulaStatus identified when the day's snapshot used the current formula; legacy_unknown when it predates it, in which case the score is preserved as stored and is NOT comparable with an identified one. mixed cannot occur on a host point: a snapshot is one host on one date under one lens and holds a single formula.
		FormulaStatus HostComplianceTrendDaysFormulaStatus `json:"formula_status"`

		// FormulaVersion 2 when formula_status is identified, otherwise null.
		FormulaVersion *int `json:"formula_version"`
		Passing        int  `json:"passing"`

		// ScorePct Passing over passing plus failing, to one decimal. NULL when that day's rules produced no verdict. The day still appears, with its counts, so the absence is explained rather than shown as a gap.
		ScorePct *float32 `json:"score_pct"`
		Total    int      `json:"total"`
	} `json:"days"`
}

HostComplianceTrend defines model for HostComplianceTrend.

type HostComplianceTrendDaysFormulaStatus added in v0.8.0

type HostComplianceTrendDaysFormulaStatus string

HostComplianceTrendDaysFormulaStatus identified when the day's snapshot used the current formula; legacy_unknown when it predates it, in which case the score is preserved as stored and is NOT comparable with an identified one. mixed cannot occur on a host point: a snapshot is one host on one date under one lens and holds a single formula.

const (
	HostComplianceTrendDaysFormulaStatusIdentified    HostComplianceTrendDaysFormulaStatus = "identified"
	HostComplianceTrendDaysFormulaStatusLegacyUnknown HostComplianceTrendDaysFormulaStatus = "legacy_unknown"
	HostComplianceTrendDaysFormulaStatusMixed         HostComplianceTrendDaysFormulaStatus = "mixed"
)

Defines values for HostComplianceTrendDaysFormulaStatus.

func (HostComplianceTrendDaysFormulaStatus) Valid added in v0.8.0

Valid indicates whether the value is a known member of the HostComplianceTrendDaysFormulaStatus enum.

type HostCreateRequest

type HostCreateRequest struct {
	Description *string             `json:"description,omitempty"`
	DisplayName *string             `json:"display_name,omitempty"`
	Environment *string             `json:"environment,omitempty"`
	GroupId     *openapi_types.UUID `json:"group_id,omitempty"`
	Hostname    string              `json:"hostname"`
	IpAddress   string              `json:"ip_address"`
	Port        *int                `json:"port,omitempty"`
	Tags        *[]string           `json:"tags,omitempty"`
	Username    *string             `json:"username,omitempty"`
}

HostCreateRequest defines model for HostCreateRequest.

type HostDetailResponse

type HostDetailResponse struct {
	ComplianceSummary HostComplianceSummary `json:"compliance_summary"`
	Host              HostResponse          `json:"host"`
	LastScanAt        *time.Time            `json:"last_scan_at,omitempty"`

	// Liveness Null when no liveness probe has ever run against this host.
	Liveness  *HostLiveness                `json:"liveness,omitempty"`
	ScanState *HostDetailResponseScanState `json:"scan_state,omitempty"`
}

HostDetailResponse defines model for HostDetailResponse.

type HostDetailResponseScanState added in v0.3.0

type HostDetailResponseScanState string

HostDetailResponseScanState defines model for HostDetailResponse.ScanState.

const (
	HostDetailResponseScanStateQueued  HostDetailResponseScanState = "queued"
	HostDetailResponseScanStateRunning HostDetailResponseScanState = "running"
)

Defines values for HostDetailResponseScanState.

func (HostDetailResponseScanState) Valid added in v0.3.0

Valid indicates whether the value is a known member of the HostDetailResponseScanState enum.

type HostFailedRule

type HostFailedRule struct {
	// Category Catalog category; empty when unknown.
	Category   string `json:"category"`
	CheckCount int    `json:"check_count"`

	// ControlIds Control ids for the requested framework; empty unless ?framework= is given.
	ControlIds    []string  `json:"control_ids"`
	LastCheckedAt time.Time `json:"last_checked_at"`
	RuleId        string    `json:"rule_id"`

	// Severity Stored severity; empty when the scan recorded none.
	Severity string `json:"severity"`

	// Title Catalog title; falls back to rule_id when the catalog lacks the rule.
	Title string `json:"title"`
}

HostFailedRule defines model for HostFailedRule.

type HostFailedRulesResponse

type HostFailedRulesResponse struct {
	Rules []HostFailedRule `json:"rules"`

	// TotalFailing Count of ALL failing rows for the host (post-framework-filter, pre-limit).
	TotalFailing int64 `json:"total_failing"`
}

HostFailedRulesResponse defines model for HostFailedRulesResponse.

type HostListComplianceSummary

type HostListComplianceSummary struct {
	// CoveragePct Non-null if and only if coverage_status is available.
	CoveragePct *float64 `json:"coverage_pct"`

	// CoverageStatus Whether coverage can be stated for this host, and if not, why.
	CoverageStatus HostListComplianceSummaryCoverageStatus `json:"coverage_status"`

	// CriticalFailing Rows with current_status=fail and critical severity (case-insensitive).
	CriticalFailing int64         `json:"critical_failing"`
	Envelope        ScoreEnvelope `json:"envelope"`
	Error           int64         `json:"error"`
	Failing         int64         `json:"failing"`
	Passing         int64         `json:"passing"`

	// ScorePct Passing over passing plus failing, to one decimal, computed server side. NULL when the host produced no verdict. Added so the hosts list stops deriving a compliance percentage in the browser, which produced a second formula the rest of the product could not agree with (system-compliance-scoring C-14).
	ScorePct *float64 `json:"score_pct"`
	Skipped  int64    `json:"skipped"`
	Total    int64    `json:"total"`
}

HostListComplianceSummary defines model for HostListComplianceSummary.

type HostListComplianceSummaryCoverageStatus added in v0.8.0

type HostListComplianceSummaryCoverageStatus string

HostListComplianceSummaryCoverageStatus Whether coverage can be stated for this host, and if not, why.

const (
	HostListComplianceSummaryCoverageStatusAvailable                    HostListComplianceSummaryCoverageStatus = "available"
	HostListComplianceSummaryCoverageStatusUnavailableNoOutcomes        HostListComplianceSummaryCoverageStatus = "unavailable_no_outcomes"
	HostListComplianceSummaryCoverageStatusUnavailableUnclassifiedSkips HostListComplianceSummaryCoverageStatus = "unavailable_unclassified_skips"
)

Defines values for HostListComplianceSummaryCoverageStatus.

func (HostListComplianceSummaryCoverageStatus) Valid added in v0.8.0

Valid indicates whether the value is a known member of the HostListComplianceSummaryCoverageStatus enum.

type HostListItem

type HostListItem struct {
	Architecture  *string `json:"architecture,omitempty"`
	CheckPriority *int    `json:"check_priority,omitempty"`

	// ComplianceSummary Null when the host has no rows in its current corpus. That is not the same as never scanned: a completed scan that produced no outcome writes no rule state either, and the two are indistinguishable from this field alone.
	ComplianceSummary *HostListComplianceSummary `json:"compliance_summary,omitempty"`
	CreatedAt         *time.Time                 `json:"created_at,omitempty"`
	CreatedBy         *openapi_types.UUID        `json:"created_by,omitempty"`
	Description       *string                    `json:"description,omitempty"`
	DisplayName       *string                    `json:"display_name,omitempty"`
	Environment       string                     `json:"environment"`
	GroupId           *openapi_types.UUID        `json:"group_id,omitempty"`
	Hostname          string                     `json:"hostname"`
	Id                openapi_types.UUID         `json:"id"`
	IpAddress         string                     `json:"ip_address"`
	LastScanAt        *time.Time                 `json:"last_scan_at,omitempty"`
	LatestScanId      *openapi_types.UUID        `json:"latest_scan_id,omitempty"`

	// Liveness Null when no liveness probe has ever run against this host.
	Liveness           *HostLiveness          `json:"liveness,omitempty"`
	MaintenanceMode    *bool                  `json:"maintenance_mode,omitempty"`
	OsDiscoveredAt     *time.Time             `json:"os_discovered_at,omitempty"`
	OsFamily           *string                `json:"os_family,omitempty"`
	OsVersion          *string                `json:"os_version,omitempty"`
	PlatformIdentifier *string                `json:"platform_identifier,omitempty"`
	Port               int                    `json:"port"`
	ScanState          *HostListItemScanState `json:"scan_state,omitempty"`
	Tags               *[]string              `json:"tags,omitempty"`
	UpdatedAt          *time.Time             `json:"updated_at,omitempty"`
	Username           *string                `json:"username,omitempty"`
}

HostListItem defines model for HostListItem.

type HostListItemScanState added in v0.3.0

type HostListItemScanState string

HostListItemScanState defines model for HostListItem.ScanState.

const (
	HostListItemScanStateQueued  HostListItemScanState = "queued"
	HostListItemScanStateRunning HostListItemScanState = "running"
)

Defines values for HostListItemScanState.

func (HostListItemScanState) Valid added in v0.3.0

func (e HostListItemScanState) Valid() bool

Valid indicates whether the value is a known member of the HostListItemScanState enum.

type HostListResponse

type HostListResponse struct {
	Hosts []HostListItem `json:"hosts"`
}

HostListResponse defines model for HostListResponse.

type HostLiveness

type HostLiveness struct {
	ConsecutiveFailures           *int                           `json:"consecutive_failures,omitempty"`
	LastErrorType                 *string                        `json:"last_error_type,omitempty"`
	LastProbeAt                   *time.Time                     `json:"last_probe_at,omitempty"`
	LastResponseMs                *int                           `json:"last_response_ms,omitempty"`
	LastStateChangeAt             *time.Time                     `json:"last_state_change_at,omitempty"`
	MonitoringState               *HostLivenessMonitoringState   `json:"monitoring_state,omitempty"`
	PingConsecutiveFailures       *int                           `json:"ping_consecutive_failures,omitempty"`
	PingConsecutiveSuccesses      *int                           `json:"ping_consecutive_successes,omitempty"`
	PrivilegeConsecutiveFailures  *int                           `json:"privilege_consecutive_failures,omitempty"`
	PrivilegeConsecutiveSuccesses *int                           `json:"privilege_consecutive_successes,omitempty"`
	ReachabilityStatus            HostLivenessReachabilityStatus `json:"reachability_status"`
	SshConsecutiveFailures        *int                           `json:"ssh_consecutive_failures,omitempty"`
	SshConsecutiveSuccesses       *int                           `json:"ssh_consecutive_successes,omitempty"`
}

HostLiveness defines model for HostLiveness.

type HostLivenessMonitoringState

type HostLivenessMonitoringState string

HostLivenessMonitoringState defines model for HostLiveness.MonitoringState.

const (
	HostLivenessMonitoringStateCritical    HostLivenessMonitoringState = "critical"
	HostLivenessMonitoringStateDegraded    HostLivenessMonitoringState = "degraded"
	HostLivenessMonitoringStateDown        HostLivenessMonitoringState = "down"
	HostLivenessMonitoringStateMaintenance HostLivenessMonitoringState = "maintenance"
	HostLivenessMonitoringStateOnline      HostLivenessMonitoringState = "online"
	HostLivenessMonitoringStateUnknown     HostLivenessMonitoringState = "unknown"
)

Defines values for HostLivenessMonitoringState.

func (HostLivenessMonitoringState) Valid

Valid indicates whether the value is a known member of the HostLivenessMonitoringState enum.

type HostLivenessReachabilityStatus

type HostLivenessReachabilityStatus string

HostLivenessReachabilityStatus defines model for HostLiveness.ReachabilityStatus.

const (
	HostLivenessReachabilityStatusReachable   HostLivenessReachabilityStatus = "reachable"
	HostLivenessReachabilityStatusUnknown     HostLivenessReachabilityStatus = "unknown"
	HostLivenessReachabilityStatusUnreachable HostLivenessReachabilityStatus = "unreachable"
)

Defines values for HostLivenessReachabilityStatus.

func (HostLivenessReachabilityStatus) Valid

Valid indicates whether the value is a known member of the HostLivenessReachabilityStatus enum.

type HostMaintenanceRequest

type HostMaintenanceRequest struct {
	// Enabled true = pause probes; false = resume
	Enabled bool `json:"enabled"`
}

HostMaintenanceRequest defines model for HostMaintenanceRequest.

type HostMonitoringHistoryEntry

type HostMonitoringHistoryEntry struct {
	CheckTime       time.Time                                 `json:"check_time"`
	ErrorMessage    *string                                   `json:"error_message,omitempty"`
	ErrorType       *string                                   `json:"error_type,omitempty"`
	FailedLayer     *HostMonitoringHistoryEntryFailedLayer    `json:"failed_layer,omitempty"`
	HostId          openapi_types.UUID                        `json:"host_id"`
	Id              int64                                     `json:"id"`
	MonitoringState HostMonitoringHistoryEntryMonitoringState `json:"monitoring_state"`
	PingOk          *bool                                     `json:"ping_ok,omitempty"`
	PreviousState   *HostMonitoringHistoryEntryPreviousState  `json:"previous_state,omitempty"`
	PrivilegeOk     *bool                                     `json:"privilege_ok,omitempty"`
	ResponseTimeMs  *int                                      `json:"response_time_ms,omitempty"`
	SshOk           *bool                                     `json:"ssh_ok,omitempty"`
}

HostMonitoringHistoryEntry defines model for HostMonitoringHistoryEntry.

type HostMonitoringHistoryEntryFailedLayer

type HostMonitoringHistoryEntryFailedLayer string

HostMonitoringHistoryEntryFailedLayer defines model for HostMonitoringHistoryEntry.FailedLayer.

Defines values for HostMonitoringHistoryEntryFailedLayer.

func (HostMonitoringHistoryEntryFailedLayer) Valid

Valid indicates whether the value is a known member of the HostMonitoringHistoryEntryFailedLayer enum.

type HostMonitoringHistoryEntryMonitoringState

type HostMonitoringHistoryEntryMonitoringState string

HostMonitoringHistoryEntryMonitoringState defines model for HostMonitoringHistoryEntry.MonitoringState.

const (
	HostMonitoringHistoryEntryMonitoringStateCritical    HostMonitoringHistoryEntryMonitoringState = "critical"
	HostMonitoringHistoryEntryMonitoringStateDegraded    HostMonitoringHistoryEntryMonitoringState = "degraded"
	HostMonitoringHistoryEntryMonitoringStateDown        HostMonitoringHistoryEntryMonitoringState = "down"
	HostMonitoringHistoryEntryMonitoringStateMaintenance HostMonitoringHistoryEntryMonitoringState = "maintenance"
	HostMonitoringHistoryEntryMonitoringStateOnline      HostMonitoringHistoryEntryMonitoringState = "online"
	HostMonitoringHistoryEntryMonitoringStateUnknown     HostMonitoringHistoryEntryMonitoringState = "unknown"
)

Defines values for HostMonitoringHistoryEntryMonitoringState.

func (HostMonitoringHistoryEntryMonitoringState) Valid

Valid indicates whether the value is a known member of the HostMonitoringHistoryEntryMonitoringState enum.

type HostMonitoringHistoryEntryPreviousState

type HostMonitoringHistoryEntryPreviousState string

HostMonitoringHistoryEntryPreviousState defines model for HostMonitoringHistoryEntry.PreviousState.

const (
	HostMonitoringHistoryEntryPreviousStateCritical    HostMonitoringHistoryEntryPreviousState = "critical"
	HostMonitoringHistoryEntryPreviousStateDegraded    HostMonitoringHistoryEntryPreviousState = "degraded"
	HostMonitoringHistoryEntryPreviousStateDown        HostMonitoringHistoryEntryPreviousState = "down"
	HostMonitoringHistoryEntryPreviousStateMaintenance HostMonitoringHistoryEntryPreviousState = "maintenance"
	HostMonitoringHistoryEntryPreviousStateOnline      HostMonitoringHistoryEntryPreviousState = "online"
	HostMonitoringHistoryEntryPreviousStateUnknown     HostMonitoringHistoryEntryPreviousState = "unknown"
)

Defines values for HostMonitoringHistoryEntryPreviousState.

func (HostMonitoringHistoryEntryPreviousState) Valid

Valid indicates whether the value is a known member of the HostMonitoringHistoryEntryPreviousState enum.

type HostMonitoringHistoryResponse

type HostMonitoringHistoryResponse struct {
	Entries []HostMonitoringHistoryEntry `json:"entries"`
	HostId  openapi_types.UUID           `json:"host_id"`
}

HostMonitoringHistoryResponse defines model for HostMonitoringHistoryResponse.

type HostResponse

type HostResponse struct {
	// Architecture e.g. x86_64, aarch64
	Architecture    *string             `json:"architecture,omitempty"`
	CheckPriority   *int                `json:"check_priority,omitempty"`
	CreatedAt       *time.Time          `json:"created_at,omitempty"`
	CreatedBy       *openapi_types.UUID `json:"created_by,omitempty"`
	Description     *string             `json:"description,omitempty"`
	DisplayName     *string             `json:"display_name,omitempty"`
	Environment     string              `json:"environment"`
	GroupId         *openapi_types.UUID `json:"group_id,omitempty"`
	Hostname        string              `json:"hostname"`
	Id              openapi_types.UUID  `json:"id"`
	IpAddress       string              `json:"ip_address"`
	MaintenanceMode *bool               `json:"maintenance_mode,omitempty"`
	OsDiscoveredAt  *time.Time          `json:"os_discovered_at,omitempty"`

	// OsFamily Distro ID from /etc/os-release (e.g. rhel, ubuntu, rocky, centos, almalinux, debian, opensuse-leap, sles); rollup family (rhel | debian | suse | alpine | arch | gentoo | other) ONLY when ID was empty; null pre-Discovery. Spec system-host-discovery v1.3.0 AC-22.
	OsFamily  *string `json:"os_family,omitempty"`
	OsVersion *string `json:"os_version,omitempty"`

	// PlatformIdentifier e.g. platform:el9
	PlatformIdentifier *string   `json:"platform_identifier,omitempty"`
	Port               int       `json:"port"`
	Tags               *[]string `json:"tags,omitempty"`

	// TargetFramework Host's own compliance target framework family (absent when unset/inheriting).
	TargetFramework *string    `json:"target_framework,omitempty"`
	UpdatedAt       *time.Time `json:"updated_at,omitempty"`
	Username        *string    `json:"username,omitempty"`
}

HostResponse defines model for HostResponse.

type HostScanContext

type HostScanContext struct {
	// DurationSeconds Wall-clock duration of the latest completed run (finished_at - started_at); null when never scanned or timestamps absent.
	DurationSeconds *int `json:"duration_seconds,omitempty"`

	// LastScanAt finished_at of the latest completed scan run; null when never scanned.
	LastScanAt *time.Time `json:"last_scan_at"`

	// PolicyVersion Policy version of the latest completed run; empty when never scanned.
	PolicyVersion string `json:"policy_version"`

	// ScanId id of the latest completed scan run; null when never scanned.
	ScanId *openapi_types.UUID `json:"scan_id"`

	// ScanState In-flight scan state for this host, independent of the latest COMPLETED run above. 'queued' = enqueued, awaiting a worker; 'running' = actively executing; null = no scan in flight. Drives the host-detail hero "Running"/"Queued" badge. Spec api-host-compliance AC-17.
	ScanState *HostScanContextScanState `json:"scan_state,omitempty"`
}

HostScanContext defines model for HostScanContext.

type HostScanContextScanState added in v0.3.0

type HostScanContextScanState string

HostScanContextScanState In-flight scan state for this host, independent of the latest COMPLETED run above. 'queued' = enqueued, awaiting a worker; 'running' = actively executing; null = no scan in flight. Drives the host-detail hero "Running"/"Queued" badge. Spec api-host-compliance AC-17.

const (
	HostScanContextScanStateQueued  HostScanContextScanState = "queued"
	HostScanContextScanStateRunning HostScanContextScanState = "running"
)

Defines values for HostScanContextScanState.

func (HostScanContextScanState) Valid added in v0.3.0

func (e HostScanContextScanState) Valid() bool

Valid indicates whether the value is a known member of the HostScanContextScanState enum.

type HostSystemInfo

type HostSystemInfo struct {
	ApparmorEnabled   *bool              `json:"apparmor_enabled,omitempty"`
	Architecture      *string            `json:"architecture,omitempty"`
	CategoryFreshness *CategoryFreshness `json:"category_freshness,omitempty"`
	CollectedAt       time.Time          `json:"collected_at"`
	DiskFreeGb        *int               `json:"disk_free_gb,omitempty"`
	DiskTotalGb       *int               `json:"disk_total_gb,omitempty"`
	DiskUsedGb        *int               `json:"disk_used_gb,omitempty"`

	// FirewallService firewalld | ufw | nftables | iptables | empty
	FirewallService *string            `json:"firewall_service,omitempty"`
	FirewallStatus  *string            `json:"firewall_status,omitempty"`
	Fqdn            *string            `json:"fqdn,omitempty"`
	HostId          openapi_types.UUID `json:"host_id"`
	Hostname        *string            `json:"hostname,omitempty"`
	KernelName      *string            `json:"kernel_name,omitempty"`
	KernelRelease   *string            `json:"kernel_release,omitempty"`
	KernelVersion   *string            `json:"kernel_version,omitempty"`
	MemAvailableMb  *int               `json:"mem_available_mb,omitempty"`
	MemTotalMb      *int               `json:"mem_total_mb,omitempty"`

	// OsFamily Distro ID from /etc/os-release (rhel, ubuntu, rocky, ...); rollup family (rhel/debian/suse/alpine/arch/gentoo/other) only when ID was empty. Spec system-host-discovery v1.3.0 AC-22.
	OsFamily           *string `json:"os_family,omitempty"`
	OsId               *string `json:"os_id,omitempty"`
	OsIdLike           *string `json:"os_id_like,omitempty"`
	OsName             *string `json:"os_name,omitempty"`
	OsPrettyName       *string `json:"os_pretty_name,omitempty"`
	OsVersion          *string `json:"os_version,omitempty"`
	OsVersionFull      *string `json:"os_version_full,omitempty"`
	PlatformIdentifier *string `json:"platform_identifier,omitempty"`

	// SelinuxStatus Enforcing | Permissive | Disabled | empty if not present
	SelinuxStatus *string `json:"selinux_status,omitempty"`
	SwapTotalMb   *int    `json:"swap_total_mb,omitempty"`
}

HostSystemInfo Result of a Discovery run. Mirrors the host_system_info table column-for-column. Spec system-host-discovery.

type HostTargetRequest added in v0.5.0

type HostTargetRequest struct {
	// TargetFramework Compliance target family id, or empty to clear the host's own target.
	TargetFramework string `json:"target_framework"`
}

HostTargetRequest defines model for HostTargetRequest.

type HostUpdateRequest

type HostUpdateRequest struct {
	Description *string             `json:"description,omitempty"`
	DisplayName *string             `json:"display_name,omitempty"`
	Environment *string             `json:"environment,omitempty"`
	GroupId     *openapi_types.UUID `json:"group_id,omitempty"`
	IpAddress   *string             `json:"ip_address,omitempty"`
	Port        *int                `json:"port,omitempty"`
	Tags        *[]string           `json:"tags,omitempty"`
	Username    *string             `json:"username,omitempty"`
}

HostUpdateRequest defines model for HostUpdateRequest.

type IntelligenceConfig

type IntelligenceConfig struct {
	// IntervalSec Per-host cadence the scheduler advances next_intelligence_at by after a successful RunCycle (300..86400). Default 3600 (1h)
	IntervalSec int `json:"interval_sec"`

	// MaintenanceGlobal When true, the scheduler loop ticks but RunCycles no hosts
	MaintenanceGlobal bool `json:"maintenance_global"`

	// RateLimit Max concurrent RunCycles per scheduler instance (1..200). Default 10
	RateLimit int `json:"rate_limit"`
}

IntelligenceConfig defines model for IntelligenceConfig.

type IntelligenceConfigResponse

type IntelligenceConfigResponse struct {
	Config   IntelligenceConfig `json:"config"`
	Defaults IntelligenceConfig `json:"defaults"`
}

IntelligenceConfigResponse defines model for IntelligenceConfigResponse.

type IntelligenceEvent

type IntelligenceEvent struct {
	CorrelationId *string                 `json:"correlation_id,omitempty"`
	Detail        *map[string]interface{} `json:"detail,omitempty"`
	DetectedAt    time.Time               `json:"detected_at"`

	// EventCode Closed taxonomy: e.g. system.package.updated
	EventCode  string                    `json:"event_code"`
	HostId     openapi_types.UUID        `json:"host_id"`
	Id         openapi_types.UUID        `json:"id"`
	OccurredAt time.Time                 `json:"occurred_at"`
	Severity   IntelligenceEventSeverity `json:"severity"`
}

IntelligenceEvent defines model for IntelligenceEvent.

type IntelligenceEventSeverity

type IntelligenceEventSeverity string

IntelligenceEventSeverity defines model for IntelligenceEvent.Severity.

const (
	IntelligenceEventSeverityCritical IntelligenceEventSeverity = "critical"
	IntelligenceEventSeverityHigh     IntelligenceEventSeverity = "high"
	IntelligenceEventSeverityInfo     IntelligenceEventSeverity = "info"
	IntelligenceEventSeverityLow      IntelligenceEventSeverity = "low"
	IntelligenceEventSeverityMedium   IntelligenceEventSeverity = "medium"
)

Defines values for IntelligenceEventSeverity.

func (IntelligenceEventSeverity) Valid

func (e IntelligenceEventSeverity) Valid() bool

Valid indicates whether the value is a known member of the IntelligenceEventSeverity enum.

type IntelligenceEventsPage

type IntelligenceEventsPage struct {
	Items      []IntelligenceEvent `json:"items"`
	NextCursor *string             `json:"next_cursor,omitempty"`
}

IntelligenceEventsPage defines model for IntelligenceEventsPage.

type IntelligenceState

type IntelligenceState struct {
	CategoryFreshness *CategoryFreshness `json:"category_freshness,omitempty"`
	CollectedAt       time.Time          `json:"collected_at"`
	HostId            openapi_types.UUID `json:"host_id"`

	// Snapshot Free-form host_intelligence_state.snapshot — mirrors collector.Snapshot
	Snapshot map[string]interface{} `json:"snapshot"`
}

IntelligenceState defines model for IntelligenceState.

type InvalidParamFormatError

type InvalidParamFormatError struct {
	ParamName string
	Err       error
}

func (*InvalidParamFormatError) Error

func (e *InvalidParamFormatError) Error() string

func (*InvalidParamFormatError) Unwrap

func (e *InvalidParamFormatError) Unwrap() error

type LicenseStateResponse

type LicenseStateResponse struct {
	ClockRollbackDetected *bool                      `json:"clock_rollback_detected,omitempty"`
	CustomerId            *string                    `json:"customer_id,omitempty"`
	ExpiresAt             *time.Time                 `json:"expires_at,omitempty"`
	Features              []string                   `json:"features"`
	InGracePeriod         *bool                      `json:"in_grace_period,omitempty"`
	Status                LicenseStateResponseStatus `json:"status"`
	Tier                  LicenseStateResponseTier   `json:"tier"`
	UsingPrevKey          *bool                      `json:"using_prev_key,omitempty"`
}

LicenseStateResponse defines model for LicenseStateResponse.

type LicenseStateResponseStatus

type LicenseStateResponseStatus string

LicenseStateResponseStatus defines model for LicenseStateResponse.Status.

const (
	LicenseStateResponseStatusActive    LicenseStateResponseStatus = "active"
	LicenseStateResponseStatusExpired   LicenseStateResponseStatus = "expired"
	LicenseStateResponseStatusGrace     LicenseStateResponseStatus = "grace"
	LicenseStateResponseStatusInvalid   LicenseStateResponseStatus = "invalid"
	LicenseStateResponseStatusNoLicense LicenseStateResponseStatus = "no_license"
)

Defines values for LicenseStateResponseStatus.

func (LicenseStateResponseStatus) Valid

func (e LicenseStateResponseStatus) Valid() bool

Valid indicates whether the value is a known member of the LicenseStateResponseStatus enum.

type LicenseStateResponseTier

type LicenseStateResponseTier string

LicenseStateResponseTier defines model for LicenseStateResponse.Tier.

const (
	Enterprise LicenseStateResponseTier = "enterprise"
	Free       LicenseStateResponseTier = "free"
)

Defines values for LicenseStateResponseTier.

func (LicenseStateResponseTier) Valid

func (e LicenseStateResponseTier) Valid() bool

Valid indicates whether the value is a known member of the LicenseStateResponseTier enum.

type LicenseVerifyRequest

type LicenseVerifyRequest struct {
	LicenseJwt string `json:"license_jwt"`
}

LicenseVerifyRequest defines model for LicenseVerifyRequest.

type LicenseVerifyResponse

type LicenseVerifyResponse struct {
	ExpiresAt    *time.Time `json:"expires_at,omitempty"`
	Features     *[]string  `json:"features,omitempty"`
	IsValid      bool       `json:"is_valid"`
	Tier         *string    `json:"tier,omitempty"`
	VerifyResult string     `json:"verify_result"`
	Warnings     *[]string  `json:"warnings,omitempty"`
}

LicenseVerifyResponse defines model for LicenseVerifyResponse.

type ListRemediationRequestsParams

type ListRemediationRequestsParams struct {
	Status *ListRemediationRequestsParamsStatus `form:"status,omitempty" json:"status,omitempty"`
	HostId *openapi_types.UUID                  `form:"host_id,omitempty" json:"host_id,omitempty"`
	RuleId *string                              `form:"rule_id,omitempty" json:"rule_id,omitempty"`
	Limit  *int                                 `form:"limit,omitempty" json:"limit,omitempty"`
}

ListRemediationRequestsParams defines parameters for ListRemediationRequests.

type ListRemediationRequestsParamsStatus

type ListRemediationRequestsParamsStatus string

ListRemediationRequestsParamsStatus defines parameters for ListRemediationRequests.

const (
	ListRemediationRequestsParamsStatusApproved         ListRemediationRequestsParamsStatus = "approved"
	ListRemediationRequestsParamsStatusDryRunComplete   ListRemediationRequestsParamsStatus = "dry_run_complete"
	ListRemediationRequestsParamsStatusExecuted         ListRemediationRequestsParamsStatus = "executed"
	ListRemediationRequestsParamsStatusExecuting        ListRemediationRequestsParamsStatus = "executing"
	ListRemediationRequestsParamsStatusFailed           ListRemediationRequestsParamsStatus = "failed"
	ListRemediationRequestsParamsStatusNotApplied       ListRemediationRequestsParamsStatus = "not_applied"
	ListRemediationRequestsParamsStatusPartiallyApplied ListRemediationRequestsParamsStatus = "partially_applied"
	ListRemediationRequestsParamsStatusPendingApproval  ListRemediationRequestsParamsStatus = "pending_approval"
	ListRemediationRequestsParamsStatusRejected         ListRemediationRequestsParamsStatus = "rejected"
	ListRemediationRequestsParamsStatusReverted         ListRemediationRequestsParamsStatus = "reverted"
	ListRemediationRequestsParamsStatusRolledBack       ListRemediationRequestsParamsStatus = "rolled_back"
	ListRemediationRequestsParamsStatusStaged           ListRemediationRequestsParamsStatus = "staged"
)

Defines values for ListRemediationRequestsParamsStatus.

func (ListRemediationRequestsParamsStatus) Valid

Valid indicates whether the value is a known member of the ListRemediationRequestsParamsStatus enum.

type MethodNotAllowed

type MethodNotAllowed = ErrorEnvelope

MethodNotAllowed defines model for MethodNotAllowed.

type MiddlewareFunc

type MiddlewareFunc func(http.Handler) http.Handler

type NotFound

type NotFound = ErrorEnvelope

NotFound defines model for NotFound.

type NotificationChannel

type NotificationChannel struct {
	CreatedAt time.Time `json:"created_at"`
	Enabled   bool      `json:"enabled"`

	// From Sender address (email channels)
	From *string            `json:"from,omitempty"`
	Id   openapi_types.UUID `json:"id"`
	Name string             `json:"name"`

	// SmtpEncryption SMTP transport security (email channels) - none|starttls|tls
	SmtpEncryption *string `json:"smtp_encryption,omitempty"`

	// SmtpInsecureSkipVerify Skip TLS cert verification for an internal relay with a self-signed/private-CA cert (email channels; STARTTLS/TLS only)
	SmtpInsecureSkipVerify *bool `json:"smtp_insecure_skip_verify,omitempty"`

	// SmtpPort SMTP port (email channels)
	SmtpPort *int `json:"smtp_port,omitempty"`

	// TagFilter Alert tags this channel matches; empty = every alert
	TagFilter map[string]string `json:"tag_filter"`

	// TargetHint Non-secret host (URL host or SMTP host)
	TargetHint string `json:"target_hint"`

	// To Recipient addresses (email channels)
	To        *[]string               `json:"to,omitempty"`
	Type      NotificationChannelType `json:"type"`
	UpdatedAt time.Time               `json:"updated_at"`

	// Username SMTP username (email; the password is never returned)
	Username *string `json:"username,omitempty"`
}

NotificationChannel A delivery channel. SECRETS are NEVER returned — the SMTP password, and the slack/webhook URL + token, are write-only. For email channels the NON-secret config is returned so the edit form can pre-fill: smtp_host (also target_hint), smtp_port, from, to, username.

type NotificationChannelCreate

type NotificationChannelCreate struct {
	Enabled *bool `json:"enabled,omitempty"`

	// From Envelope From address (email).
	From *string `json:"from,omitempty"`
	Name string  `json:"name"`

	// Password SMTP auth password (email). Stored encrypted.
	Password *string `json:"password,omitempty"`

	// SmtpEncryption Transport security for the SMTP connection (email). 'starttls' (default) connects plaintext then requires a STARTTLS upgrade; 'tls' uses implicit TLS from connect (SMTPS, e.g. port 465); 'none' is plaintext for a trusted local relay. Omitted defaults to starttls.
	SmtpEncryption *NotificationChannelCreateSmtpEncryption `json:"smtp_encryption,omitempty"`

	// SmtpHost SMTP relay host (email). Stored encrypted.
	SmtpHost *string `json:"smtp_host,omitempty"`

	// SmtpInsecureSkipVerify Skip TLS certificate verification for the SMTP handshake (email). For an internal relay with a self-signed or private-CA cert only; a MITM-exposing downgrade, inert under 'none'. Defaults false.
	SmtpInsecureSkipVerify *bool `json:"smtp_insecure_skip_verify,omitempty"`

	// SmtpPort SMTP relay port (email)
	SmtpPort  *int               `json:"smtp_port,omitempty"`
	TagFilter *map[string]string `json:"tag_filter,omitempty"`

	// To Recipient addresses (email).
	To *[]string `json:"to,omitempty"`

	// Token Optional bearer token for webhook auth. Stored encrypted.
	Token *string                       `json:"token,omitempty"`
	Type  NotificationChannelCreateType `json:"type"`

	// Url Target URL (https, public host) for slack/webhook. Stored encrypted.
	Url *string `json:"url,omitempty"`

	// Username SMTP auth username (email). Stored encrypted.
	Username *string `json:"username,omitempty"`
}

NotificationChannelCreate For slack/webhook supply url (https, public host). For email supply smtp_host/smtp_port/from/to (and username/password if the relay authenticates). All secrets are stored encrypted and never returned.

type NotificationChannelCreateSmtpEncryption added in v0.4.0

type NotificationChannelCreateSmtpEncryption string

NotificationChannelCreateSmtpEncryption Transport security for the SMTP connection (email). 'starttls' (default) connects plaintext then requires a STARTTLS upgrade; 'tls' uses implicit TLS from connect (SMTPS, e.g. port 465); 'none' is plaintext for a trusted local relay. Omitted defaults to starttls.

const (
	NotificationChannelCreateSmtpEncryptionNone     NotificationChannelCreateSmtpEncryption = "none"
	NotificationChannelCreateSmtpEncryptionStarttls NotificationChannelCreateSmtpEncryption = "starttls"
	NotificationChannelCreateSmtpEncryptionTls      NotificationChannelCreateSmtpEncryption = "tls"
)

Defines values for NotificationChannelCreateSmtpEncryption.

func (NotificationChannelCreateSmtpEncryption) Valid added in v0.4.0

Valid indicates whether the value is a known member of the NotificationChannelCreateSmtpEncryption enum.

type NotificationChannelCreateType

type NotificationChannelCreateType string

NotificationChannelCreateType defines model for NotificationChannelCreate.Type.

const (
	NotificationChannelCreateTypeEmail   NotificationChannelCreateType = "email"
	NotificationChannelCreateTypeSlack   NotificationChannelCreateType = "slack"
	NotificationChannelCreateTypeWebhook NotificationChannelCreateType = "webhook"
)

Defines values for NotificationChannelCreateType.

func (NotificationChannelCreateType) Valid

Valid indicates whether the value is a known member of the NotificationChannelCreateType enum.

type NotificationChannelList

type NotificationChannelList struct {
	Channels []NotificationChannel `json:"channels"`
}

NotificationChannelList defines model for NotificationChannelList.

type NotificationChannelType

type NotificationChannelType string

NotificationChannelType defines model for NotificationChannel.Type.

const (
	NotificationChannelTypeEmail   NotificationChannelType = "email"
	NotificationChannelTypeSlack   NotificationChannelType = "slack"
	NotificationChannelTypeWebhook NotificationChannelType = "webhook"
)

Defines values for NotificationChannelType.

func (NotificationChannelType) Valid

func (e NotificationChannelType) Valid() bool

Valid indicates whether the value is a known member of the NotificationChannelType enum.

type NotificationChannelUpdate

type NotificationChannelUpdate struct {
	Enabled                bool                                     `json:"enabled"`
	From                   *string                                  `json:"from,omitempty"`
	Name                   string                                   `json:"name"`
	Password               *string                                  `json:"password,omitempty"`
	SmtpEncryption         *NotificationChannelUpdateSmtpEncryption `json:"smtp_encryption,omitempty"`
	SmtpHost               *string                                  `json:"smtp_host,omitempty"`
	SmtpInsecureSkipVerify *bool                                    `json:"smtp_insecure_skip_verify,omitempty"`
	SmtpPort               *int                                     `json:"smtp_port,omitempty"`
	TagFilter              *map[string]string                       `json:"tag_filter,omitempty"`
	To                     *[]string                                `json:"to,omitempty"`
	Token                  *string                                  `json:"token,omitempty"`
	Url                    *string                                  `json:"url,omitempty"`
	Username               *string                                  `json:"username,omitempty"`
}

NotificationChannelUpdate Updates name/enabled/tag_filter. Supplying the secret config (url for slack/webhook, or smtp_host for email) replaces it; omitting it leaves the stored secret unchanged.

type NotificationChannelUpdateSmtpEncryption added in v0.4.0

type NotificationChannelUpdateSmtpEncryption string

NotificationChannelUpdateSmtpEncryption defines model for NotificationChannelUpdate.SmtpEncryption.

const (
	NotificationChannelUpdateSmtpEncryptionNone     NotificationChannelUpdateSmtpEncryption = "none"
	NotificationChannelUpdateSmtpEncryptionStarttls NotificationChannelUpdateSmtpEncryption = "starttls"
	NotificationChannelUpdateSmtpEncryptionTls      NotificationChannelUpdateSmtpEncryption = "tls"
)

Defines values for NotificationChannelUpdateSmtpEncryption.

func (NotificationChannelUpdateSmtpEncryption) Valid added in v0.4.0

Valid indicates whether the value is a known member of the NotificationChannelUpdateSmtpEncryption enum.

type NotificationFeed

type NotificationFeed struct {
	Items []NotificationFeedItem `json:"items"`

	// UnreadCount Count of the unread notifications (badge value)
	UnreadCount int `json:"unread_count"`
}

NotificationFeed defines model for NotificationFeed.

type NotificationFeedItem

type NotificationFeedItem struct {
	Body *string `json:"body,omitempty"`

	// HostId Present for host-scoped changes
	HostId *openapi_types.UUID `json:"host_id,omitempty"`
	Id     openapi_types.UUID  `json:"id"`

	// Kind Change/alert kind, e.g. host_unreachable or drift_major
	Kind string `json:"kind"`

	// Link Deep-link target for the notification
	Link       *string   `json:"link,omitempty"`
	OccurredAt time.Time `json:"occurred_at"`

	// Read True when the caller has read it
	Read     bool                         `json:"read"`
	Severity NotificationFeedItemSeverity `json:"severity"`
	Title    string                       `json:"title"`
}

NotificationFeedItem One in-app notification (the bell). Self-scoped to the caller.

type NotificationFeedItemSeverity

type NotificationFeedItemSeverity string

NotificationFeedItemSeverity defines model for NotificationFeedItem.Severity.

const (
	NotificationFeedItemSeverityCritical NotificationFeedItemSeverity = "critical"
	NotificationFeedItemSeverityHigh     NotificationFeedItemSeverity = "high"
	NotificationFeedItemSeverityInfo     NotificationFeedItemSeverity = "info"
	NotificationFeedItemSeverityLow      NotificationFeedItemSeverity = "low"
	NotificationFeedItemSeverityMedium   NotificationFeedItemSeverity = "medium"
)

Defines values for NotificationFeedItemSeverity.

func (NotificationFeedItemSeverity) Valid

Valid indicates whether the value is a known member of the NotificationFeedItemSeverity enum.

type NotificationReadResult

type NotificationReadResult struct {
	// MarkedRead Number of notifications marked read
	MarkedRead int `json:"marked_read"`
}

NotificationReadResult defines model for NotificationReadResult.

type OscalDocument

type OscalDocument map[string]interface{}

OscalDocument An OSCAL 1.0.6 Assessment Results document (JSON), as produced by Kensa's exporter. Opaque to OpenWatch — passed through verbatim.

type PatchAuthMeJSONRequestBody added in v0.4.0

type PatchAuthMeJSONRequestBody = AuthMeUpdateRequest

PatchAuthMeJSONRequestBody defines body for PatchAuthMe for application/json ContentType.

type PatchCredentialByIDJSONRequestBody

type PatchCredentialByIDJSONRequestBody = CredentialUpdateRequest

PatchCredentialByIDJSONRequestBody defines body for PatchCredentialByID for application/json ContentType.

type PatchGroupJSONRequestBody

type PatchGroupJSONRequestBody = GroupUpdate

PatchGroupJSONRequestBody defines body for PatchGroup for application/json ContentType.

type PatchHostByIDJSONRequestBody

type PatchHostByIDJSONRequestBody = HostUpdateRequest

PatchHostByIDJSONRequestBody defines body for PatchHostByID for application/json ContentType.

type PatchNotificationChannelJSONRequestBody

type PatchNotificationChannelJSONRequestBody = NotificationChannelUpdate

PatchNotificationChannelJSONRequestBody defines body for PatchNotificationChannel for application/json ContentType.

type PatchUsersMePreferencesJSONRequestBody

type PatchUsersMePreferencesJSONRequestBody = UserPreferences

PatchUsersMePreferencesJSONRequestBody defines body for PatchUsersMePreferences for application/json ContentType.

type PermissionEntry

type PermissionEntry struct {
	Category    string `json:"category"`
	Dangerous   bool   `json:"dangerous"`
	Description string `json:"description"`
	Id          string `json:"id"`
}

PermissionEntry defines model for PermissionEntry.

type PermissionsRegistryResponse

type PermissionsRegistryResponse struct {
	Categories  []CategoryEntry   `json:"categories"`
	Permissions []PermissionEntry `json:"permissions"`
	Roles       []RoleEntry       `json:"roles"`
}

PermissionsRegistryResponse defines model for PermissionsRegistryResponse.

type PoliciesReloadResponse

type PoliciesReloadResponse struct {
	Outcomes map[string]string `json:"outcomes"`
}

PoliciesReloadResponse defines model for PoliciesReloadResponse.

type PolicyDecisionResponse

type PolicyDecisionResponse struct {
	Detail        *map[string]interface{} `json:"detail,omitempty"`
	HumanMessage  *string                 `json:"human_message,omitempty"`
	Outcome       string                  `json:"outcome"`
	PolicyType    string                  `json:"policy_type"`
	PolicyVersion string                  `json:"policy_version"`
	Reason        string                  `json:"reason"`
}

PolicyDecisionResponse defines model for PolicyDecisionResponse.

type PostAPITokenJSONRequestBody

type PostAPITokenJSONRequestBody = ApiTokenCreateRequest

PostAPITokenJSONRequestBody defines body for PostAPIToken for application/json ContentType.

type PostAdminLicenseVerifyJSONRequestBody

type PostAdminLicenseVerifyJSONRequestBody = LicenseVerifyRequest

PostAdminLicenseVerifyJSONRequestBody defines body for PostAdminLicenseVerify for application/json ContentType.

type PostAlertAcknowledgeJSONRequestBody

type PostAlertAcknowledgeJSONRequestBody = AlertLifecycleRequest

PostAlertAcknowledgeJSONRequestBody defines body for PostAlertAcknowledge for application/json ContentType.

type PostAlertDismissJSONRequestBody

type PostAlertDismissJSONRequestBody = AlertLifecycleRequest

PostAlertDismissJSONRequestBody defines body for PostAlertDismiss for application/json ContentType.

type PostAlertResolveJSONRequestBody

type PostAlertResolveJSONRequestBody = AlertLifecycleRequest

PostAlertResolveJSONRequestBody defines body for PostAlertResolve for application/json ContentType.

type PostAlertSilenceJSONRequestBody

type PostAlertSilenceJSONRequestBody = AlertLifecycleRequest

PostAlertSilenceJSONRequestBody defines body for PostAlertSilence for application/json ContentType.

type PostAuthLoginJSONRequestBody

type PostAuthLoginJSONRequestBody = AuthLoginRequest

PostAuthLoginJSONRequestBody defines body for PostAuthLogin for application/json ContentType.

type PostAuthMFAVerifyJSONRequestBody

type PostAuthMFAVerifyJSONRequestBody = AuthMFAVerifyRequest

PostAuthMFAVerifyJSONRequestBody defines body for PostAuthMFAVerify for application/json ContentType.

type PostAuthPasswordChangeJSONRequestBody

type PostAuthPasswordChangeJSONRequestBody = AuthPasswordChangeRequest

PostAuthPasswordChangeJSONRequestBody defines body for PostAuthPasswordChange for application/json ContentType.

type PostAuthRefreshJSONRequestBody

type PostAuthRefreshJSONRequestBody = AuthRefreshRequest

PostAuthRefreshJSONRequestBody defines body for PostAuthRefresh for application/json ContentType.

type PostCredentialCloneJSONRequestBody

type PostCredentialCloneJSONRequestBody = CredentialCloneRequest

PostCredentialCloneJSONRequestBody defines body for PostCredentialClone for application/json ContentType.

type PostCredentialsJSONRequestBody

type PostCredentialsJSONRequestBody = CredentialCreateRequest

PostCredentialsJSONRequestBody defines body for PostCredentials for application/json ContentType.

type PostDiagnosticsEchoJSONRequestBody

type PostDiagnosticsEchoJSONRequestBody = EchoRequest

PostDiagnosticsEchoJSONRequestBody defines body for PostDiagnosticsEcho for application/json ContentType.

type PostDiagnosticsEchoParams

type PostDiagnosticsEchoParams struct {
	IdempotencyKey string  `json:"Idempotency-Key"`
	XCorrelationId *string `json:"X-Correlation-Id,omitempty"`
}

PostDiagnosticsEchoParams defines parameters for PostDiagnosticsEcho.

type PostDiagnosticsEvaluateAlertJSONRequestBody

type PostDiagnosticsEvaluateAlertJSONRequestBody = EvaluateAlertRequest

PostDiagnosticsEvaluateAlertJSONRequestBody defines body for PostDiagnosticsEvaluateAlert for application/json ContentType.

type PostDiagnosticsPremiumEchoJSONRequestBody

type PostDiagnosticsPremiumEchoJSONRequestBody = EchoRequest

PostDiagnosticsPremiumEchoJSONRequestBody defines body for PostDiagnosticsPremiumEcho for application/json ContentType.

type PostDiagnosticsPremiumEchoParams

type PostDiagnosticsPremiumEchoParams struct {
	IdempotencyKey string `json:"Idempotency-Key"`
}

PostDiagnosticsPremiumEchoParams defines parameters for PostDiagnosticsPremiumEcho.

type PostDiagnosticsRequireHostReadJSONRequestBody

type PostDiagnosticsRequireHostReadJSONRequestBody = EchoRequest

PostDiagnosticsRequireHostReadJSONRequestBody defines body for PostDiagnosticsRequireHostRead for application/json ContentType.

type PostDiagnosticsRequireHostReadParams

type PostDiagnosticsRequireHostReadParams struct {
	IdempotencyKey string `json:"Idempotency-Key"`
}

PostDiagnosticsRequireHostReadParams defines parameters for PostDiagnosticsRequireHostRead.

type PostDiagnosticsRequireHostWriteJSONRequestBody

type PostDiagnosticsRequireHostWriteJSONRequestBody = EchoRequest

PostDiagnosticsRequireHostWriteJSONRequestBody defines body for PostDiagnosticsRequireHostWrite for application/json ContentType.

type PostDiagnosticsRequireHostWriteParams

type PostDiagnosticsRequireHostWriteParams struct {
	IdempotencyKey string `json:"Idempotency-Key"`
}

PostDiagnosticsRequireHostWriteParams defines parameters for PostDiagnosticsRequireHostWrite.

type PostDiagnosticsRequireRemediationExecuteJSONRequestBody

type PostDiagnosticsRequireRemediationExecuteJSONRequestBody = EchoRequest

PostDiagnosticsRequireRemediationExecuteJSONRequestBody defines body for PostDiagnosticsRequireRemediationExecute for application/json ContentType.

type PostDiagnosticsRequireRemediationExecuteParams

type PostDiagnosticsRequireRemediationExecuteParams struct {
	IdempotencyKey string `json:"Idempotency-Key"`
}

PostDiagnosticsRequireRemediationExecuteParams defines parameters for PostDiagnosticsRequireRemediationExecute.

type PostExceptionApproveJSONRequestBody

type PostExceptionApproveJSONRequestBody = ExceptionReview

PostExceptionApproveJSONRequestBody defines body for PostExceptionApprove for application/json ContentType.

type PostExceptionRejectJSONRequestBody

type PostExceptionRejectJSONRequestBody = ExceptionReview

PostExceptionRejectJSONRequestBody defines body for PostExceptionReject for application/json ContentType.

type PostExceptionRevokeJSONRequestBody

type PostExceptionRevokeJSONRequestBody = ExceptionReview

PostExceptionRevokeJSONRequestBody defines body for PostExceptionRevoke for application/json ContentType.

type PostGroupJSONRequestBody

type PostGroupJSONRequestBody = GroupCreate

PostGroupJSONRequestBody defines body for PostGroup for application/json ContentType.

type PostGroupMaintenanceJSONRequestBody

type PostGroupMaintenanceJSONRequestBody = GroupMaintenanceRequest

PostGroupMaintenanceJSONRequestBody defines body for PostGroupMaintenance for application/json ContentType.

type PostGroupMemberJSONRequestBody

type PostGroupMemberJSONRequestBody = GroupMemberRequest

PostGroupMemberJSONRequestBody defines body for PostGroupMember for application/json ContentType.

type PostGroupTargetJSONRequestBody added in v0.5.0

type PostGroupTargetJSONRequestBody = GroupTargetRequest

PostGroupTargetJSONRequestBody defines body for PostGroupTarget for application/json ContentType.

type PostHostConnectivityCheckParams

type PostHostConnectivityCheckParams struct {
	IdempotencyKey string `json:"Idempotency-Key"`
}

PostHostConnectivityCheckParams defines parameters for PostHostConnectivityCheck.

type PostHostDiscoveryRunParams

type PostHostDiscoveryRunParams struct {
	IdempotencyKey string `json:"Idempotency-Key"`
}

PostHostDiscoveryRunParams defines parameters for PostHostDiscoveryRun.

type PostHostExceptionJSONRequestBody

type PostHostExceptionJSONRequestBody = ExceptionRequest

PostHostExceptionJSONRequestBody defines body for PostHostException for application/json ContentType.

type PostHostScanParams

type PostHostScanParams struct {
	IdempotencyKey string `json:"Idempotency-Key"`
}

PostHostScanParams defines parameters for PostHostScan.

type PostHostTargetJSONRequestBody added in v0.5.0

type PostHostTargetJSONRequestBody = HostTargetRequest

PostHostTargetJSONRequestBody defines body for PostHostTarget for application/json ContentType.

type PostHostsJSONRequestBody

type PostHostsJSONRequestBody = HostCreateRequest

PostHostsJSONRequestBody defines body for PostHosts for application/json ContentType.

type PostNotificationChannelJSONRequestBody

type PostNotificationChannelJSONRequestBody = NotificationChannelCreate

PostNotificationChannelJSONRequestBody defines body for PostNotificationChannel for application/json ContentType.

type PostReportGenerateJSONRequestBody

type PostReportGenerateJSONRequestBody = GenerateReportRequest

PostReportGenerateJSONRequestBody defines body for PostReportGenerate for application/json ContentType.

type PostRolesCreateJSONRequestBody

type PostRolesCreateJSONRequestBody = CustomRoleCreateRequest

PostRolesCreateJSONRequestBody defines body for PostRolesCreate for application/json ContentType.

type PostSSOProviderJSONRequestBody

type PostSSOProviderJSONRequestBody = SSOProviderCreateRequest

PostSSOProviderJSONRequestBody defines body for PostSSOProvider for application/json ContentType.

type PostUserResetPasswordJSONRequestBody

type PostUserResetPasswordJSONRequestBody = UserPasswordResetRequest

PostUserResetPasswordJSONRequestBody defines body for PostUserResetPassword for application/json ContentType.

type PostUserRolesAssignJSONRequestBody

type PostUserRolesAssignJSONRequestBody = UserRoleAssignRequest

PostUserRolesAssignJSONRequestBody defines body for PostUserRolesAssign for application/json ContentType.

type PostUserRolesUnassignJSONRequestBody

type PostUserRolesUnassignJSONRequestBody = UserRoleAssignRequest

PostUserRolesUnassignJSONRequestBody defines body for PostUserRolesUnassign for application/json ContentType.

type PostUsersJSONRequestBody

type PostUsersJSONRequestBody = UserCreateRequest

PostUsersJSONRequestBody defines body for PostUsers for application/json ContentType.

type ProjectedLift

type ProjectedLift struct {
	Cis  *float64 `json:"cis,omitempty"`
	Nist *float64 `json:"nist,omitempty"`
	Stig *float64 `json:"stig,omitempty"`
}

ProjectedLift Estimated per-framework compliance-score delta (percentage points) if the rule flips to pass. Best-effort; a field is null when that framework's data is unavailable for the host.

type PutAuthPolicyJSONRequestBody

type PutAuthPolicyJSONRequestBody = AuthPolicyUpdateRequest

PutAuthPolicyJSONRequestBody defines body for PutAuthPolicy for application/json ContentType.

type PutHostMaintenanceJSONRequestBody

type PutHostMaintenanceJSONRequestBody = HostMaintenanceRequest

PutHostMaintenanceJSONRequestBody defines body for PutHostMaintenance for application/json ContentType.

type PutSSOProviderJSONRequestBody

type PutSSOProviderJSONRequestBody = SSOProviderUpdateRequest

PutSSOProviderJSONRequestBody defines body for PutSSOProvider for application/json ContentType.

type PutSystemComplianceConfigJSONRequestBody added in v0.4.0

type PutSystemComplianceConfigJSONRequestBody = ComplianceConfig

PutSystemComplianceConfigJSONRequestBody defines body for PutSystemComplianceConfig for application/json ContentType.

type PutSystemConnectivityConfigJSONRequestBody

type PutSystemConnectivityConfigJSONRequestBody = ConnectivityConfig

PutSystemConnectivityConfigJSONRequestBody defines body for PutSystemConnectivityConfig for application/json ContentType.

type PutSystemDiscoveryConfigJSONRequestBody

type PutSystemDiscoveryConfigJSONRequestBody = DiscoveryConfig

PutSystemDiscoveryConfigJSONRequestBody defines body for PutSystemDiscoveryConfig for application/json ContentType.

type PutSystemIntelligenceConfigJSONRequestBody

type PutSystemIntelligenceConfigJSONRequestBody = IntelligenceConfig

PutSystemIntelligenceConfigJSONRequestBody defines body for PutSystemIntelligenceConfig for application/json ContentType.

type PutSystemScanConfigJSONRequestBody

type PutSystemScanConfigJSONRequestBody = ScanConfig

PutSystemScanConfigJSONRequestBody defines body for PutSystemScanConfig for application/json ContentType.

type PutSystemScanVariablesJSONRequestBody

type PutSystemScanVariablesJSONRequestBody = ScanVariableOverrides

PutSystemScanVariablesJSONRequestBody defines body for PutSystemScanVariables for application/json ContentType.

type RejectRemediationJSONRequestBody

type RejectRemediationJSONRequestBody = RemediationReview

RejectRemediationJSONRequestBody defines body for RejectRemediation for application/json ContentType.

type RemediationPhase added in v0.7.1

type RemediationPhase struct {
	// Capturable False when this phase's mechanism cannot record pre-state, which is
	// what makes a rule non-rollbackable.
	Capturable bool `json:"capturable"`

	// Detail Human-readable account of what this phase did, or why it did not.
	Detail    *string `json:"detail,omitempty"`
	Index     int     `json:"index"`
	Mechanism string  `json:"mechanism"`

	// Staged True when the change was written to the persist layer but the
	// running host has not converged, so a re-scan still reports the rule
	// failing until reboot.
	Staged bool `json:"staged"`

	// Stranded True for a non-capturable phase that succeeded before a later
	// failure. Rollback does NOT reverse it.
	Stranded bool `json:"stranded"`
	Success  bool `json:"success"`
}

RemediationPhase One Capture/Apply/Validate/Commit phase of a rule's transaction.

type RemediationPlan added in v0.7.1

type RemediationPlan struct {
	// Before What Kensa found on the host while planning, one entry per step.
	// Computed live and never stored, because a plan describes the host
	// as it is now.
	Before *[]struct {
		Index     int     `json:"index"`
		Mechanism string  `json:"mechanism"`
		Summary   *string `json:"summary,omitempty"`
	} `json:"before,omitempty"`
	CapturedAt *time.Time `json:"captured_at,omitempty"`

	// Checks The validators that would run after apply.
	Checks []struct {
		Name    string  `json:"name"`
		Summary *string `json:"summary,omitempty"`
	} `json:"checks"`

	// ControlChannelSensitive True when a step touches SSH, networking, PAM or firewall state.
	// Kensa arms a deadman timer before applying such a transaction, so
	// a fix that could lock you out reverts itself if you lose contact.
	ControlChannelSensitive bool                `json:"control_channel_sensitive"`
	EstimatedSeconds        *float32            `json:"estimated_seconds,omitempty"`
	PlanId                  *openapi_types.UUID `json:"plan_id,omitempty"`

	// ReversibleSteps How many steps Kensa actually captured pre-state for, counted from
	// the capture rather than from the rule's own claim about itself.
	ReversibleSteps int    `json:"reversible_steps"`
	RuleId          string `json:"rule_id"`

	// Steps The apply steps that would run, in order.
	Steps []RemediationPlanStep `json:"steps"`

	// Transactional False when the steps are not all-or-nothing.
	Transactional bool `json:"transactional"`

	// Undo How each applied step would be reversed. Rollback runs this in
	// reverse order.
	Undo []RemediationPlanStep `json:"undo"`

	// Warnings Kensa's own operator-facing notices about this plan.
	Warnings *[]string `json:"warnings,omitempty"`
}

RemediationPlan What remediating one rule on one host would do. Produced by Kensa without mutating the host.

type RemediationPlanStep added in v0.7.1

type RemediationPlanStep struct {
	// Capturable False when this step cannot be reversed.
	Capturable *bool  `json:"capturable,omitempty"`
	Index      int    `json:"index"`
	Mechanism  string `json:"mechanism"`

	// Summary Kensa's human-readable description of the action.
	Summary *string `json:"summary,omitempty"`
}

RemediationPlanStep defines model for RemediationPlanStep.

type RemediationPreState added in v0.7.1

type RemediationPreState struct {
	// Capturable False for phases whose mechanism cannot capture pre-state; `data` is then empty.
	Capturable bool                    `json:"capturable"`
	Data       *map[string]interface{} `json:"data,omitempty"`
	Index      int                     `json:"index"`
	Mechanism  string                  `json:"mechanism"`

	// Summary Kensa's one-line rendering of what was captured, from the handler
	// that captured it.
	//
	// Display text, not evidence. It carries no stability guarantee and
	// may change between Kensa releases, which is why the transaction
	// records the Kensa version that produced it. `data` remains the
	// authoritative capture. Elided by construction so no file body
	// appears, and a credential named inside a config line is redacted,
	// but it is not a secret scanner: treat it as operator-visible text.
	Summary *string `json:"summary,omitempty"`
}

RemediationPreState One phase's captured pre-change state.

`data` is mechanism-specific and is passed through from Kensa without interpretation. OpenWatch has no schema for it and deliberately does not decode it: each capturable handler defines its own layout, so reading it here would couple this contract to Kensa handler internals. Clients should treat it as opaque evidence unless they know the mechanism.

type RemediationRequest

type RemediationRequest struct {
	HostId openapi_types.UUID `json:"host_id"`

	// HostName Hostname, populated on list responses (empty on single-row lifecycle results)
	HostName *string            `json:"host_name,omitempty"`
	Id       openapi_types.UUID `json:"id"`

	// Mechanism Kensa remediation handler id (empty when unknown at request time)
	Mechanism *string `json:"mechanism,omitempty"`

	// ProjectedLift Estimated per-framework compliance-score delta (percentage points) if the rule flips to pass. Best-effort; a field is null when that framework's data is unavailable for the host.
	ProjectedLift  *ProjectedLift           `json:"projected_lift,omitempty"`
	RebootRequired *bool                    `json:"reboot_required,omitempty"`
	RequestedAt    time.Time                `json:"requested_at"`
	RequestedBy    openapi_types.UUID       `json:"requested_by"`
	ReviewNote     *string                  `json:"review_note,omitempty"`
	ReviewedAt     *time.Time               `json:"reviewed_at,omitempty"`
	ReviewedBy     *openapi_types.UUID      `json:"reviewed_by,omitempty"`
	RuleId         string                   `json:"rule_id"`
	ScanRunId      *openapi_types.UUID      `json:"scan_run_id,omitempty"`
	Status         RemediationRequestStatus `json:"status"`
	Transactional  *bool                    `json:"transactional,omitempty"`
}

RemediationRequest defines model for RemediationRequest.

type RemediationRequestCreate

type RemediationRequestCreate struct {
	HostId openapi_types.UUID `json:"host_id"`
	RuleId string             `json:"rule_id"`

	// ScanRunId Optional provenance - the scan run whose finding this remediates
	ScanRunId *openapi_types.UUID `json:"scan_run_id,omitempty"`
}

RemediationRequestCreate defines model for RemediationRequestCreate.

type RemediationRequestList

type RemediationRequestList struct {
	Requests []RemediationRequest `json:"requests"`
}

RemediationRequestList defines model for RemediationRequestList.

type RemediationRequestStatus

type RemediationRequestStatus string

RemediationRequestStatus defines model for RemediationRequest.Status.

const (
	RemediationRequestStatusApproved         RemediationRequestStatus = "approved"
	RemediationRequestStatusDryRunComplete   RemediationRequestStatus = "dry_run_complete"
	RemediationRequestStatusExecuted         RemediationRequestStatus = "executed"
	RemediationRequestStatusExecuting        RemediationRequestStatus = "executing"
	RemediationRequestStatusFailed           RemediationRequestStatus = "failed"
	RemediationRequestStatusNotApplied       RemediationRequestStatus = "not_applied"
	RemediationRequestStatusPartiallyApplied RemediationRequestStatus = "partially_applied"
	RemediationRequestStatusPendingApproval  RemediationRequestStatus = "pending_approval"
	RemediationRequestStatusRejected         RemediationRequestStatus = "rejected"
	RemediationRequestStatusReverted         RemediationRequestStatus = "reverted"
	RemediationRequestStatusRolledBack       RemediationRequestStatus = "rolled_back"
	RemediationRequestStatusStaged           RemediationRequestStatus = "staged"
)

Defines values for RemediationRequestStatus.

func (RemediationRequestStatus) Valid

func (e RemediationRequestStatus) Valid() bool

Valid indicates whether the value is a known member of the RemediationRequestStatus enum.

type RemediationReview

type RemediationReview struct {
	// Note Optional reviewer note
	Note *string `json:"note,omitempty"`
}

RemediationReview defines model for RemediationReview.

type RemediationStep

type RemediationStep struct {
	AppliedAt *time.Time         `json:"applied_at,omitempty"`
	DryRun    bool               `json:"dry_run"`
	Id        openapi_types.UUID `json:"id"`
	Mechanism *string            `json:"mechanism,omitempty"`

	// PhaseResult Terminal outcome of the rule's transaction. Widened past
	// committed/rolled_back/skipped by the v0.7.0 outcome vocabulary.
	PhaseResult *RemediationStepPhaseResult `json:"phase_result,omitempty"`

	// Phases The per-phase journal Kensa returned, in execution order. `detail`
	// is the engine's own account of what each phase did, and is the
	// answer to why a remediation failed.
	Phases *[]RemediationPhase `json:"phases,omitempty"`

	// PreState The state captured before any change, one entry per phase, in phase
	// order.
	PreState *[]RemediationPreState `json:"pre_state,omitempty"`
	RuleId   string                 `json:"rule_id"`
}

RemediationStep One rule's Kensa transaction. Note that a "step" here is a RULE, not a phase: the Capture/Apply/Validate/Commit phases are in `phases`, one level below.

type RemediationStepList

type RemediationStepList struct {
	Steps []RemediationStep `json:"steps"`
}

RemediationStepList defines model for RemediationStepList.

type RemediationStepPhaseResult

type RemediationStepPhaseResult string

RemediationStepPhaseResult Terminal outcome of the rule's transaction. Widened past committed/rolled_back/skipped by the v0.7.0 outcome vocabulary.

const (
	RemediationStepPhaseResultCommitted        RemediationStepPhaseResult = "committed"
	RemediationStepPhaseResultNotApplied       RemediationStepPhaseResult = "not_applied"
	RemediationStepPhaseResultPartiallyApplied RemediationStepPhaseResult = "partially_applied"
	RemediationStepPhaseResultRolledBack       RemediationStepPhaseResult = "rolled_back"
	RemediationStepPhaseResultSkipped          RemediationStepPhaseResult = "skipped"
	RemediationStepPhaseResultStaged           RemediationStepPhaseResult = "staged"
)

Defines values for RemediationStepPhaseResult.

func (RemediationStepPhaseResult) Valid

func (e RemediationStepPhaseResult) Valid() bool

Valid indicates whether the value is a known member of the RemediationStepPhaseResult enum.

type Report

type Report struct {
	// Content The rendered JSON posture document. For an executive summary:
	// score_pct, host_count, passing_rules, failing_rules,
	// critical_issues, top_failing_rules, coverage (hosts_total,
	// hosts_fresh, hosts_stale, hosts_unreachable), and provenance.
	//
	// score_pct is the equal-host mean of the in-scope hosts' scores,
	// to one decimal, null when no host produced a verdict. Null is not
	// zero: zero means every evaluated rule failed.
	//
	// provenance carries artifact_class and the frozen envelope. Its
	// ABSENCE identifies an artifact signed before 2026-09-03, which
	// instead carries compliance_pct: a pooled whole percent computed
	// over every rule outcome in scope. The two are not comparable and
	// a client must label a legacy artifact as such rather than
	// plotting it beside a current one. Nothing backfills provenance,
	// and a legacy artifact's bytes, content address and signature are
	// never rewritten. A current artifact never carries
	// compliance_pct.
	Content map[string]interface{} `json:"content"`

	// ContentSha256 The snapshot's content address: hex SHA-256 of the canonical
	// content (the json export face reproduces these exact bytes).
	ContentSha256 string             `json:"content_sha256"`
	CreatedAt     time.Time          `json:"created_at"`
	DataAsOf      time.Time          `json:"data_as_of"`
	Format        string             `json:"format"`
	GeneratedBy   string             `json:"generated_by"`
	Id            openapi_types.UUID `json:"id"`
	Kind          ReportKind         `json:"kind"`

	// Scope The structured slice of the fleet a report summarizes: an optional
	// group and/or framework lens. An empty object is the all-hosts,
	// all-frameworks scope. Echoed so a caller can see and reproduce
	// exactly what a report covers.
	Scope      ReportScope `json:"scope"`
	ScopeLabel string      `json:"scope_label"`

	// Signature Base64 Ed25519 signature over the content address, or absent
	// for an unsigned snapshot. Verify with the key from
	// GET /api/v1/reports/signing-key.
	Signature *string `json:"signature,omitempty"`

	// SigningKeyId Short correlation identifier of the key that produced the
	// signature: the first 8 bytes of SHA-256 over the public key.
	// It matches a report to a served key. It is NOT an authenticity
	// anchor; 64 bits is within reach of a collision search. Anchor
	// trust on the complete public key or its full SHA-256.
	SigningKeyId *string `json:"signing_key_id,omitempty"`
	Title        string  `json:"title"`
}

Report defines model for Report.

type ReportFramework

type ReportFramework struct {
	// Framework The framework_refs key (e.g. cis_rhel9).
	Framework string `json:"framework"`

	// Label Display label for the key, from Kensa's framework vocabulary. An id Kensa does not know is returned as it is.
	Label string `json:"label"`

	// RuleCount Distinct rules mapped to this framework across the fleet.
	RuleCount int `json:"rule_count"`
}

ReportFramework A framework lens present in the fleet, with its rule count.

type ReportFrameworksResponse

type ReportFrameworksResponse struct {
	Frameworks []ReportFramework `json:"frameworks"`
}

ReportFrameworksResponse defines model for ReportFrameworksResponse.

type ReportKind

type ReportKind string

ReportKind defines model for Report.Kind.

const (
	ReportKindAttestation ReportKind = "attestation"
	ReportKindException   ReportKind = "exception"
	ReportKindExecutive   ReportKind = "executive"
	ReportKindRemediation ReportKind = "remediation"
)

Defines values for ReportKind.

func (ReportKind) Valid

func (e ReportKind) Valid() bool

Valid indicates whether the value is a known member of the ReportKind enum.

type ReportListResponse

type ReportListResponse struct {
	Reports []Report `json:"reports"`
}

ReportListResponse defines model for ReportListResponse.

type ReportSchedule

type ReportSchedule struct {
	// ChannelId The email channel used for delivery.
	ChannelId openapi_types.UUID `json:"channel_id"`
	CreatedAt time.Time          `json:"created_at"`

	// DayOfMonth 1-28
	DayOfMonth *int `json:"day_of_month,omitempty"`
	Enabled    bool `json:"enabled"`

	// Framework Optional framework lens.
	Framework *string                 `json:"framework,omitempty"`
	Frequency ReportScheduleFrequency `json:"frequency"`

	// GroupId Optional group scope.
	GroupId *openapi_types.UUID `json:"group_id,omitempty"`

	// Hour Hour of day (UTC) to run (0-23).
	Hour       int                `json:"hour"`
	Id         openapi_types.UUID `json:"id"`
	Kind       ReportScheduleKind `json:"kind"`
	LastRunAt  *time.Time         `json:"last_run_at,omitempty"`
	LastStatus *string            `json:"last_status,omitempty"`
	Name       string             `json:"name"`
	NextRunAt  time.Time          `json:"next_run_at"`

	// PeriodDays Period window for the remediation kind.
	PeriodDays *int `json:"period_days,omitempty"`

	// Weekday 0=Sunday..6=Saturday
	Weekday *int `json:"weekday,omitempty"`
}

ReportSchedule defines model for ReportSchedule.

type ReportScheduleFrequency

type ReportScheduleFrequency string

ReportScheduleFrequency defines model for ReportSchedule.Frequency.

const (
	ReportScheduleFrequencyDaily   ReportScheduleFrequency = "daily"
	ReportScheduleFrequencyMonthly ReportScheduleFrequency = "monthly"
	ReportScheduleFrequencyWeekly  ReportScheduleFrequency = "weekly"
)

Defines values for ReportScheduleFrequency.

func (ReportScheduleFrequency) Valid

func (e ReportScheduleFrequency) Valid() bool

Valid indicates whether the value is a known member of the ReportScheduleFrequency enum.

type ReportScheduleKind

type ReportScheduleKind string

ReportScheduleKind defines model for ReportSchedule.Kind.

const (
	ReportScheduleKindAttestation ReportScheduleKind = "attestation"
	ReportScheduleKindException   ReportScheduleKind = "exception"
	ReportScheduleKindExecutive   ReportScheduleKind = "executive"
	ReportScheduleKindRemediation ReportScheduleKind = "remediation"
)

Defines values for ReportScheduleKind.

func (ReportScheduleKind) Valid

func (e ReportScheduleKind) Valid() bool

Valid indicates whether the value is a known member of the ReportScheduleKind enum.

type ReportScheduleList

type ReportScheduleList struct {
	Schedules []ReportSchedule `json:"schedules"`
}

ReportScheduleList defines model for ReportScheduleList.

type ReportScope

type ReportScope struct {
	// Framework When set, the framework lens (framework_refs key) the report is scoped to.
	Framework *string `json:"framework,omitempty"`

	// GroupId When set, the report is scoped to this group's member hosts.
	GroupId *openapi_types.UUID `json:"group_id,omitempty"`

	// GroupName The group's display name, frozen at generation time.
	GroupName *string `json:"group_name,omitempty"`
}

ReportScope The structured slice of the fleet a report summarizes: an optional group and/or framework lens. An empty object is the all-hosts, all-frameworks scope. Echoed so a caller can see and reproduce exactly what a report covers.

type ReportSigningKey

type ReportSigningKey struct {
	Algorithm ReportSigningKeyAlgorithm `json:"algorithm"`

	// Ephemeral True when the server runs a per-boot development key (no durable
	// key configured); such signatures do not verify across restarts.
	Ephemeral bool `json:"ephemeral"`

	// KeyId Short correlation identifier: the first 8 bytes of SHA-256 over
	// public_key, hex encoded, prefixed `ed25519-`. Use it to match a
	// report's signing_key_id to this key. It is NOT an authenticity
	// anchor; compare the complete public_key, or its full SHA-256,
	// against a copy obtained independently of this server.
	KeyId string `json:"key_id"`

	// PublicKey Base64-encoded Ed25519 public key, 32 bytes when decoded. This,
	// or its lowercase hex SHA-256, is the value to compare against an
	// independently trusted copy.
	PublicKey string `json:"public_key"`
}

ReportSigningKey The public key used to sign report snapshots, for offline verification of a report's signature over its content_sha256.

type ReportSigningKeyAlgorithm

type ReportSigningKeyAlgorithm string

ReportSigningKeyAlgorithm defines model for ReportSigningKey.Algorithm.

const (
	Ed25519 ReportSigningKeyAlgorithm = "ed25519"
)

Defines values for ReportSigningKeyAlgorithm.

func (ReportSigningKeyAlgorithm) Valid

func (e ReportSigningKeyAlgorithm) Valid() bool

Valid indicates whether the value is a known member of the ReportSigningKeyAlgorithm enum.

type RequestRemediationJSONRequestBody

type RequestRemediationJSONRequestBody = RemediationRequestCreate

RequestRemediationJSONRequestBody defines body for RequestRemediation for application/json ContentType.

type RequiredHeaderError

type RequiredHeaderError struct {
	ParamName string
	Err       error
}

func (*RequiredHeaderError) Error

func (e *RequiredHeaderError) Error() string

func (*RequiredHeaderError) Unwrap

func (e *RequiredHeaderError) Unwrap() error

type RequiredParamError

type RequiredParamError struct {
	ParamName string
}

func (*RequiredParamError) Error

func (e *RequiredParamError) Error() string

type RoleEntry

type RoleEntry struct {
	Description string   `json:"description"`
	Id          string   `json:"id"`
	IsBuiltIn   bool     `json:"is_built_in"`
	Permissions []string `json:"permissions"`
}

RoleEntry defines model for RoleEntry.

type RuleList

type RuleList struct {
	// FrameworkLabels Display label, from Kensa's framework vocabulary, for every framework id used as a framework_refs key in this response. An id Kensa does not know maps to itself.
	FrameworkLabels map[string]string `json:"framework_labels"`
	Rules           []RuleListItem    `json:"rules"`

	// Total total rules in the library
	Total int `json:"total"`
}

RuleList defines model for RuleList.

type RuleListItem

type RuleListItem struct {
	Category    string `json:"category"`
	Description string `json:"description"`

	// FrameworkRefs framework_id -> control ids (same shape as scan results)
	FrameworkRefs map[string][]string `json:"framework_refs"`
	Id            string              `json:"id"`

	// Remediation Host-independent remediation summary from the kensa read model (facts only; risk level is operator policy, owned by OpenWatch).
	Remediation RuleRemediation `json:"remediation"`

	// Severity critical | high | medium | low
	Severity string   `json:"severity"`
	Tags     []string `json:"tags"`
	Title    string   `json:"title"`

	// Transactional the rule's apply path is a capturable atomic transaction (the "atomic" signal)
	Transactional bool `json:"transactional"`
}

RuleListItem One normalized Kensa rule for the library browser.

type RuleRemediation

type RuleRemediation struct {
	// Available true when an automated (non-manual) remediation exists
	Available bool `json:"available"`

	// Mechanisms distinct remediation mechanisms across implementations (e.g. config_set, service_enabled)
	Mechanisms []string `json:"mechanisms"`

	// RebootBehavior kensa reboot signal: "boot-param" (staged boot change, pending reboot) or "none" (not a complete requires-reboot answer)
	RebootBehavior string `json:"reboot_behavior"`

	// RestartsServices services the remediation reloads or restarts
	RestartsServices []string `json:"restarts_services"`
}

RuleRemediation Host-independent remediation summary from the kensa read model (facts only; risk level is operator policy, owned by OpenWatch).

type SSOEnabledList

type SSOEnabledList struct {
	Providers []SSOEnabledProvider `json:"providers"`
}

SSOEnabledList defines model for SSOEnabledList.

type SSOEnabledProvider

type SSOEnabledProvider struct {
	Id   openapi_types.UUID `json:"id"`
	Name string             `json:"name"`
}

SSOEnabledProvider The minimal, non-secret shape rendered on the anonymous login page.

type SSOProvider

type SSOProvider struct {
	ClientId  string    `json:"client_id"`
	CreatedAt time.Time `json:"created_at"`

	// DefaultRole Role granted to users provisioned via this provider
	DefaultRole string             `json:"default_role"`
	Enabled     bool               `json:"enabled"`
	Id          openapi_types.UUID `json:"id"`

	// Issuer OIDC issuer URL
	Issuer string `json:"issuer"`
	Name   string `json:"name"`

	// Scopes Space-delimited OAuth scopes
	Scopes string `json:"scopes"`

	// Type Protocol (oidc)
	Type      string     `json:"type"`
	UpdatedAt *time.Time `json:"updated_at,omitempty"`
}

SSOProvider SSO provider metadata. The client secret is NEVER included.

type SSOProviderCreateRequest

type SSOProviderCreateRequest struct {
	ClientId string `json:"client_id"`

	// ClientSecret Stored encrypted; never returned
	ClientSecret string `json:"client_secret"`

	// DefaultRole Role for provisioned users (default viewer)
	DefaultRole *string `json:"default_role,omitempty"`
	Enabled     *bool   `json:"enabled,omitempty"`

	// Issuer OIDC issuer URL (https)
	Issuer string `json:"issuer"`
	Name   string `json:"name"`

	// Scopes Space-delimited; openid is always added
	Scopes *string `json:"scopes,omitempty"`
}

SSOProviderCreateRequest defines model for SSOProviderCreateRequest.

type SSOProviderList

type SSOProviderList struct {
	Providers []SSOProvider `json:"providers"`
}

SSOProviderList defines model for SSOProviderList.

type SSOProviderUpdateRequest

type SSOProviderUpdateRequest struct {
	ClientId string `json:"client_id"`

	// ClientSecret Optional; empty keeps the existing secret
	ClientSecret *string `json:"client_secret,omitempty"`
	DefaultRole  *string `json:"default_role,omitempty"`
	Enabled      *bool   `json:"enabled,omitempty"`
	Issuer       string  `json:"issuer"`
	Name         string  `json:"name"`
	Scopes       *string `json:"scopes,omitempty"`
}

SSOProviderUpdateRequest Omit client_secret (or send empty) to keep the stored secret.

type ScanCheckEvidence

type ScanCheckEvidence struct {
	Actual    *string `json:"actual,omitempty"`
	Command   *string `json:"command,omitempty"`
	ExitCode  int     `json:"exit_code"`
	Expected  *string `json:"expected,omitempty"`
	Method    string  `json:"method"`
	Stderr    *string `json:"stderr,omitempty"`
	Stdout    *string `json:"stdout,omitempty"`
	Truncated *bool   `json:"truncated,omitempty"`
}

ScanCheckEvidence One command's reproducible evidence (mirrors kensa CheckEvidence).

type ScanConfig

type ScanConfig struct {
	// CompliantMins Re-scan interval (minutes) for the compliant band (score 90 and above). Clamped into [5, 2880]
	CompliantMins int `json:"compliant_mins"`

	// CriticalMins Re-scan interval (minutes) for hosts in the critical band (score under 20 or any critical finding). Clamped into [5, 2880]
	CriticalMins int `json:"critical_mins"`

	// Enabled Master switch for the adaptive scheduler. When false the loop ticks but dispatches nothing. On-demand scans are unaffected
	Enabled bool `json:"enabled"`

	// MaintenanceGlobal When true the scheduler loop ticks but dispatches nothing (fleet-wide pause)
	MaintenanceGlobal bool `json:"maintenance_global"`

	// MostlyCompliantMins Re-scan interval (minutes) for the mostly_compliant band (score 70 to 89). Clamped into [5, 2880]
	MostlyCompliantMins int `json:"mostly_compliant_mins"`

	// NonCompliantMins Re-scan interval (minutes) for the non_compliant band (score 20 to 49). Clamped into [5, 2880]
	NonCompliantMins int `json:"non_compliant_mins"`

	// PartialMins Re-scan interval (minutes) for the partial band (score 50 to 69). Clamped into [5, 2880]
	PartialMins int `json:"partial_mins"`

	// RateLimit Max hosts dispatched per 60s scheduler tick. Clamped into [1, 100]
	RateLimit int `json:"rate_limit"`

	// UnknownMins Re-scan interval (minutes) for never-classified hosts. Clamped into [5, 2880]
	UnknownMins int `json:"unknown_mins"`
}

ScanConfig defines model for ScanConfig.

type ScanConfigResponse

type ScanConfigResponse struct {
	Config   ScanConfig `json:"config"`
	Defaults ScanConfig `json:"defaults"`
}

ScanConfigResponse defines model for ScanConfigResponse.

type ScanDetail

type ScanDetail struct {
	// FrameworkLabels Display label, from Kensa's framework vocabulary, for every framework id used as a framework_refs key in this response. An id Kensa does not know maps to itself.
	FrameworkLabels map[string]string `json:"framework_labels"`
	Results         []ScanRuleResult  `json:"results"`

	// Scan One scan_runs row — a scan's metadata and outcome counts.
	Scan ScanSummary `json:"scan"`
}

ScanDetail defines model for ScanDetail.

type ScanList

type ScanList struct {
	// NextCursor Pass as ?cursor= to fetch the next page; absent when exhausted
	NextCursor *time.Time    `json:"next_cursor,omitempty"`
	Scans      []ScanSummary `json:"scans"`
}

ScanList defines model for ScanList.

type ScanRuleEvidence

type ScanRuleEvidence struct {
	Checks []ScanCheckEvidence `json:"checks"`

	// Detail human-readable verdict context
	Detail string `json:"detail"`

	// Error present only when status is error
	Error         *string             `json:"error,omitempty"`
	FrameworkRefs map[string][]string `json:"framework_refs"`
	RuleId        string              `json:"rule_id"`
	Severity      string              `json:"severity"`
	SkipReason    *string             `json:"skip_reason,omitempty"`

	// Status pass | fail | skipped | error
	Status string `json:"status"`
}

ScanRuleEvidence One rule's full drill-down payload — the stored evidence unwrapped plus metadata.

type ScanRuleResult

type ScanRuleResult struct {
	// Category catalog category (falls back to "uncategorized")
	Category string `json:"category"`

	// Description one-line catalog description of what the rule checks; empty when uncatalogued
	Description *string `json:"description,omitempty"`

	// FrameworkRefs framework_id -> control ids
	FrameworkRefs map[string][]string `json:"framework_refs"`

	// HasEvidence true when this rule has stored check output to drill into
	HasEvidence bool   `json:"has_evidence"`
	RuleId      string `json:"rule_id"`

	// Severity critical | high | medium | low | "" when unset
	Severity   string  `json:"severity"`
	SkipReason *string `json:"skip_reason,omitempty"`

	// Status pass | fail | skipped | error
	Status string `json:"status"`

	// Title human rule title from the catalog (falls back to rule_id)
	Title string `json:"title"`
}

ScanRuleResult One rule's durable verdict for a scan. No inline check output.

type ScanRunQueued

type ScanRunQueued struct {
	QueuedAt time.Time `json:"queued_at"`

	// ScanId scan_runs.id == queue job id == transactions.scan_id
	ScanId openapi_types.UUID  `json:"scan_id"`
	Status ScanRunQueuedStatus `json:"status"`
}

ScanRunQueued defines model for ScanRunQueued.

type ScanRunQueuedStatus

type ScanRunQueuedStatus string

ScanRunQueuedStatus defines model for ScanRunQueued.Status.

const (
	ScanRunQueuedStatusQueued ScanRunQueuedStatus = "queued"
)

Defines values for ScanRunQueuedStatus.

func (ScanRunQueuedStatus) Valid

func (e ScanRunQueuedStatus) Valid() bool

Valid indicates whether the value is a known member of the ScanRunQueuedStatus enum.

type ScanSchedulePreview

type ScanSchedulePreview struct {
	// Buckets 24 entries, one per hour from now; due count of hosts whose next_scheduled_scan falls inside that hour
	Buckets []struct {
		DueCount int `json:"due_count"`

		// HourOffset Hours from now (0 = the coming hour)
		HourOffset int `json:"hour_offset"`
	} `json:"buckets"`

	// DueNow Hosts whose next_scheduled_scan has already passed (dispatch backlog)
	DueNow int `json:"due_now"`

	// NextScanAt Soonest next_scheduled_scan across non-maintenance hosts; null when no schedule rows exist
	NextScanAt *time.Time `json:"next_scan_at,omitempty"`

	// QueuedJobs scan_runs rows currently queued
	QueuedJobs int `json:"queued_jobs"`

	// RunningJobs scan_runs rows currently running
	RunningJobs int `json:"running_jobs"`
}

ScanSchedulePreview defines model for ScanSchedulePreview.

type ScanSummary

type ScanSummary struct {
	FinishedAt    *time.Time         `json:"finished_at,omitempty"`
	HostId        openapi_types.UUID `json:"host_id"`
	Hostname      *string            `json:"hostname,omitempty"`
	IpAddress     *string            `json:"ip_address,omitempty"`
	PolicyVersion string             `json:"policy_version"`
	QueuedAt      time.Time          `json:"queued_at"`
	RulesError    int                `json:"rules_error"`
	RulesFail     int                `json:"rules_fail"`
	RulesPass     int                `json:"rules_pass"`
	RulesSkipped  int                `json:"rules_skipped"`
	ScanId        openapi_types.UUID `json:"scan_id"`
	StartedAt     *time.Time         `json:"started_at,omitempty"`

	// Status queued | running | completed | failed
	Status string `json:"status"`

	// TriggerSource on_demand | scheduled
	TriggerSource string `json:"trigger_source"`
}

ScanSummary One scan_runs row — a scan's metadata and outcome counts.

type ScanVariableOverrides

type ScanVariableOverrides struct {
	// Overrides Variable name to override value. PUT replaces the full map
	Overrides map[string]string `json:"overrides"`
}

ScanVariableOverrides defines model for ScanVariableOverrides.

type ScanVariablesResponse

type ScanVariablesResponse struct {
	// Variables Corpus-used variables sorted by name
	Variables []struct {
		// AffectsRules Count of corpus rules referencing the variable
		AffectsRules int `json:"affects_rules"`

		// ConfigureMe The built-in value cannot be right for a real site (a placeholder, or no value at all), so the operator has to set it
		ConfigureMe bool `json:"configure_me"`

		// Default kensa built-in default in effect without an override
		Default    string `json:"default"`
		Name       string `json:"name"`
		Overridden bool   `json:"overridden"`

		// RuleIds The referencing rule ids, sorted
		RuleIds []string `json:"rule_ids"`

		// Value Effective value (override when set, else the default)
		Value string `json:"value"`
	} `json:"variables"`
}

ScanVariablesResponse defines model for ScanVariablesResponse.

type ScoreEnvelope added in v0.8.0

type ScoreEnvelope struct {
	// AggregationMethod none for a single host; equal_host_mean for an aggregate, where each host counts once whatever its rule count.
	AggregationMethod ScoreEnvelopeAggregationMethod `json:"aggregation_method"`

	// Corpora One entry per distinct corpus that contributed. Empty when unavailable.
	Corpora []struct {
		ContributorsScored int    `json:"contributors_scored"`
		CorpusDigest       string `json:"corpus_digest"`

		// CorpusVersion Null for a curated corpus, which has a digest and no version.
		CorpusVersion *string `json:"corpus_version"`
	} `json:"corpora"`

	// CorpusDigest Convenience field, non-null ONLY when corpus_identity_status is identified. See corpus_version.
	CorpusDigest *string `json:"corpus_digest"`

	// CorpusIdentityStatus Whether the rule corpus behind the score can be named. unavailable until the scan engine can report it; never inferred from the corpus installed now.
	CorpusIdentityStatus ScoreEnvelopeCorpusIdentityStatus `json:"corpus_identity_status"`

	// CorpusVersion Convenience field, non-null ONLY when corpus_identity_status is identified. One entry in corpora is not sufficient: partially_identified also has one, alongside contributors whose corpus could not be named, and reporting that one as THE corpus would name an identity for hosts that have none. The durable record is corpora.
	CorpusVersion *string `json:"corpus_version"`

	// EngineIdentityStatus Whether the engine behind the score can be named. partially_identified means some scored hosts named an engine and some did not, which is what a fleet part way through an upgrade looks like and what a bare version list reported as agreement.
	EngineIdentityStatus ScoreEnvelopeEngineIdentityStatus `json:"engine_identity_status"`

	// EngineVersion Convenience field, non-null ONLY when engine_identity_status is identified: one engine version, and every scored host accounted for by it. Null under partially_identified even though exactly one version appears in engines, because that version does not speak for the hosts that recorded none. The durable record is engines. It is COPIED from the scan runs, never taken from the process answering the request: in a rolling or split deployment the API, the rollup and the workers run different builds, so a process describing itself names an engine that never touched the host.
	EngineVersion *string `json:"engine_version"`

	// Engines One entry per engine version that produced contributing outcomes, with how many scored hosts it covers, sorted by version. Empty when none was recorded. The counts plus hosts_without_engine_identity always equal hosts_scored.
	Engines []struct {
		ContributorsScored int    `json:"contributors_scored"`
		EngineVersion      string `json:"engine_version"`
	} `json:"engines"`

	// FormulaVersion 2 for the current formula (passing over passing plus failing). Null on an aggregate whose contributors disagree, or that predates the formula.
	FormulaVersion *int `json:"formula_version"`

	// HostsWithoutCorpusIdentity Scored hosts whose corpus could not be named.
	HostsWithoutCorpusIdentity int `json:"hosts_without_corpus_identity"`

	// HostsWithoutEngineIdentity Scored hosts whose scan run recorded no engine version.
	HostsWithoutEngineIdentity int `json:"hosts_without_engine_identity"`

	// Lens The single framework family every host was scored against, OS-resolved per host. "all_rules" when no lens narrows the set. An aggregate never blends per-host lenses.
	Lens string `json:"lens"`
}

ScoreEnvelope defines model for ScoreEnvelope.

type ScoreEnvelopeAggregationMethod added in v0.8.0

type ScoreEnvelopeAggregationMethod string

ScoreEnvelopeAggregationMethod none for a single host; equal_host_mean for an aggregate, where each host counts once whatever its rule count.

const (
	EqualHostMean ScoreEnvelopeAggregationMethod = "equal_host_mean"
	None          ScoreEnvelopeAggregationMethod = "none"
)

Defines values for ScoreEnvelopeAggregationMethod.

func (ScoreEnvelopeAggregationMethod) Valid added in v0.8.0

Valid indicates whether the value is a known member of the ScoreEnvelopeAggregationMethod enum.

type ScoreEnvelopeCorpusIdentityStatus added in v0.8.0

type ScoreEnvelopeCorpusIdentityStatus string

ScoreEnvelopeCorpusIdentityStatus Whether the rule corpus behind the score can be named. unavailable until the scan engine can report it; never inferred from the corpus installed now.

const (
	ScoreEnvelopeCorpusIdentityStatusIdentified          ScoreEnvelopeCorpusIdentityStatus = "identified"
	ScoreEnvelopeCorpusIdentityStatusMixed               ScoreEnvelopeCorpusIdentityStatus = "mixed"
	ScoreEnvelopeCorpusIdentityStatusNotApplicable       ScoreEnvelopeCorpusIdentityStatus = "not_applicable"
	ScoreEnvelopeCorpusIdentityStatusPartiallyIdentified ScoreEnvelopeCorpusIdentityStatus = "partially_identified"
	ScoreEnvelopeCorpusIdentityStatusUnavailable         ScoreEnvelopeCorpusIdentityStatus = "unavailable"
)

Defines values for ScoreEnvelopeCorpusIdentityStatus.

func (ScoreEnvelopeCorpusIdentityStatus) Valid added in v0.8.0

Valid indicates whether the value is a known member of the ScoreEnvelopeCorpusIdentityStatus enum.

type ScoreEnvelopeEngineIdentityStatus added in v0.8.0

type ScoreEnvelopeEngineIdentityStatus string

ScoreEnvelopeEngineIdentityStatus Whether the engine behind the score can be named. partially_identified means some scored hosts named an engine and some did not, which is what a fleet part way through an upgrade looks like and what a bare version list reported as agreement.

const (
	ScoreEnvelopeEngineIdentityStatusIdentified          ScoreEnvelopeEngineIdentityStatus = "identified"
	ScoreEnvelopeEngineIdentityStatusMixed               ScoreEnvelopeEngineIdentityStatus = "mixed"
	ScoreEnvelopeEngineIdentityStatusPartiallyIdentified ScoreEnvelopeEngineIdentityStatus = "partially_identified"
	ScoreEnvelopeEngineIdentityStatusUnavailable         ScoreEnvelopeEngineIdentityStatus = "unavailable"
)

Defines values for ScoreEnvelopeEngineIdentityStatus.

func (ScoreEnvelopeEngineIdentityStatus) Valid added in v0.8.0

Valid indicates whether the value is a known member of the ScoreEnvelopeEngineIdentityStatus enum.

type ServerInterface

type ServerInterface interface {
	// Unified Activity feed (UNION over alerts + transactions + intelligence + audit + monitoring)
	// (GET /api/v1/activity)
	GetActivity(w http.ResponseWriter, r *http.Request, params GetActivityParams)
	// Dry-run validate a JWT license without installing it
	// (POST /api/v1/admin/license:verify)
	PostAdminLicenseVerify(w http.ResponseWriter, r *http.Request)
	// Reload signed policy files from the configured directory
	// (POST /api/v1/admin/policies:reload)
	PostAdminPoliciesReload(w http.ResponseWriter, r *http.Request)
	// List persisted alerts (paginated, filterable)
	// (GET /api/v1/alerts)
	GetAlerts(w http.ResponseWriter, r *http.Request, params GetAlertsParams)
	// Single alert by id
	// (GET /api/v1/alerts/{id})
	GetAlertByID(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Acknowledge an active alert
	// (POST /api/v1/alerts/{id}:acknowledge)
	PostAlertAcknowledge(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Dismiss an alert (terminal)
	// (POST /api/v1/alerts/{id}:dismiss)
	PostAlertDismiss(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Resolve an alert
	// (POST /api/v1/alerts/{id}:resolve)
	PostAlertResolve(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Silence an alert until a timestamp (or indefinitely)
	// (POST /api/v1/alerts/{id}:silence)
	PostAlertSilence(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// List audit events (cursor-paginated, newest first)
	// (GET /api/v1/audit/events)
	GetAuditEvents(w http.ResponseWriter, r *http.Request, params GetAuditEventsParams)
	// Export the filtered audit events as a downloadable CSV or JSON file
	// (GET /api/v1/audit/events/export)
	GetAuditEventsExport(w http.ResponseWriter, r *http.Request, params GetAuditEventsExportParams)
	// View the workspace authentication policy
	// (GET /api/v1/auth-policy)
	GetAuthPolicy(w http.ResponseWriter, r *http.Request)
	// Replace the workspace authentication policy
	// (PUT /api/v1/auth-policy)
	PutAuthPolicy(w http.ResponseWriter, r *http.Request)
	// Username/password login with optional TOTP
	// (POST /api/v1/auth/login)
	PostAuthLogin(w http.ResponseWriter, r *http.Request)
	// Revoke the calling session
	// (POST /api/v1/auth/logout)
	PostAuthLogout(w http.ResponseWriter, r *http.Request)
	// Return the calling identity
	// (GET /api/v1/auth/me)
	GetAuthMe(w http.ResponseWriter, r *http.Request)
	// Update the calling user's own profile
	// (PATCH /api/v1/auth/me)
	PatchAuthMe(w http.ResponseWriter, r *http.Request)
	// Effective permissions for the calling identity
	// (GET /api/v1/auth/me/permissions)
	GetAuthMePermissions(w http.ResponseWriter, r *http.Request)
	// Enroll the calling user in TOTP MFA
	// (POST /api/v1/auth/mfa:enroll)
	PostAuthMFAEnroll(w http.ResponseWriter, r *http.Request)
	// Confirm an enrolled MFA secret by verifying a generated OTP
	// (POST /api/v1/auth/mfa:verify)
	PostAuthMFAVerify(w http.ResponseWriter, r *http.Request)
	// Change the calling user's password
	// (POST /api/v1/auth/password:change)
	PostAuthPasswordChange(w http.ResponseWriter, r *http.Request)
	// Full RBAC registry (categories, permissions, built-in roles)
	// (GET /api/v1/auth/permissions:registry)
	GetAuthPermissionsRegistry(w http.ResponseWriter, r *http.Request)
	// Rotate the refresh token; mint a new access+refresh pair
	// (POST /api/v1/auth/refresh)
	PostAuthRefresh(w http.ResponseWriter, r *http.Request)
	// Rotate the refresh cookie and mint a new session (browser flow)
	// (POST /api/v1/auth/refresh-cookie)
	PostAuthRefreshCookie(w http.ResponseWriter, r *http.Request)
	// SSO redirect-back — exchanges the code, issues a session, redirects into the app
	// (GET /api/v1/auth/sso/{id}/callback)
	GetAuthSSOCallback(w http.ResponseWriter, r *http.Request, id openapi_types.UUID, params GetAuthSSOCallbackParams)
	// Begin SSO sign-in — redirects to the IdP authorization endpoint
	// (GET /api/v1/auth/sso/{id}/login)
	GetAuthSSOLogin(w http.ResponseWriter, r *http.Request, id openapi_types.UUID, params GetAuthSSOLoginParams)
	// What this deployment is entitled to use
	// (GET /api/v1/capabilities)
	GetCapabilities(w http.ResponseWriter, r *http.Request)
	// Fleet-wide compliance exception queue
	// (GET /api/v1/compliance/exceptions)
	GetComplianceExceptions(w http.ResponseWriter, r *http.Request, params GetComplianceExceptionsParams)
	// List the framework families present in the scanned corpus
	// (GET /api/v1/compliance/frameworks)
	GetComplianceFrameworks(w http.ResponseWriter, r *http.Request, params GetComplianceFrameworksParams)
	// List credentials (metadata only)
	// (GET /api/v1/credentials)
	GetCredentials(w http.ResponseWriter, r *http.Request)
	// Create a credential
	// (POST /api/v1/credentials)
	PostCredentials(w http.ResponseWriter, r *http.Request)
	// Soft-delete a credential
	// (DELETE /api/v1/credentials/{id})
	DeleteCredentialByID(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Fetch a credential's metadata
	// (GET /api/v1/credentials/{id})
	GetCredentialByID(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Update a credential in place
	// (PATCH /api/v1/credentials/{id})
	PatchCredentialByID(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Clone a credential into a new scope (system → host or host → host)
	// (POST /api/v1/credentials/{id}:clone)
	PostCredentialClone(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Echo the request message; exercises idempotency + audit
	// (POST /api/v1/diagnostics:echo)
	PostDiagnosticsEcho(w http.ResponseWriter, r *http.Request, params PostDiagnosticsEchoParams)
	// Stage-0 queue demo; enqueues a no-op job processed by the in-process worker
	// (POST /api/v1/diagnostics:enqueue-test-job)
	PostDiagnosticsEnqueueTestJob(w http.ResponseWriter, r *http.Request)
	// Stage-0 policy demo; evaluates the alert_thresholds policy
	// (POST /api/v1/diagnostics:evaluate-alert)
	PostDiagnosticsEvaluateAlert(w http.ResponseWriter, r *http.Request)
	// License-gated echo; requires premium_diagnostics feature
	// (POST /api/v1/diagnostics:premium-echo)
	PostDiagnosticsPremiumEcho(w http.ResponseWriter, r *http.Request, params PostDiagnosticsPremiumEchoParams)
	// Stage-0 RBAC demo; requires host:read permission
	// (POST /api/v1/diagnostics:require-host-read)
	PostDiagnosticsRequireHostRead(w http.ResponseWriter, r *http.Request, params PostDiagnosticsRequireHostReadParams)
	// Stage-0 RBAC demo; requires host:write permission
	// (POST /api/v1/diagnostics:require-host-write)
	PostDiagnosticsRequireHostWrite(w http.ResponseWriter, r *http.Request, params PostDiagnosticsRequireHostWriteParams)
	// Stage-0 RBAC+license demo; requires remediation:execute (RBAC) + premium_diagnostics (license)
	// (POST /api/v1/diagnostics:require-remediation-execute)
	PostDiagnosticsRequireRemediationExecute(w http.ResponseWriter, r *http.Request, params PostDiagnosticsRequireRemediationExecuteParams)
	// Approve a requested exception
	// (POST /api/v1/exceptions/{xid}:approve)
	PostExceptionApprove(w http.ResponseWriter, r *http.Request, xid openapi_types.UUID)
	// Reject a requested exception
	// (POST /api/v1/exceptions/{xid}:reject)
	PostExceptionReject(w http.ResponseWriter, r *http.Request, xid openapi_types.UUID)
	// Revoke an active exception before its expiry
	// (POST /api/v1/exceptions/{xid}:revoke)
	PostExceptionRevoke(w http.ResponseWriter, r *http.Request, xid openapi_types.UUID)
	// Fleet host counts per compliance state
	// (GET /api/v1/fleet/compliance/states)
	GetFleetComplianceStates(w http.ResponseWriter, r *http.Request)
	// Daily fleet compliance trend
	// (GET /api/v1/fleet/compliance/trend)
	GetFleetComplianceTrend(w http.ResponseWriter, r *http.Request, params GetFleetComplianceTrendParams)
	// 4-state connectivity breakdown (online/degraded/critical/down/never_probed)
	// (GET /api/v1/fleet/connectivity/breakdown)
	GetFleetConnectivityBreakdown(w http.ResponseWriter, r *http.Request)
	// Host counts by reachability status
	// (GET /api/v1/fleet/liveness)
	GetFleetLiveness(w http.ResponseWriter, r *http.Request)
	// Recent transactions (state changes), newest first
	// (GET /api/v1/fleet/recent-changes)
	GetFleetRecentChanges(w http.ResponseWriter, r *http.Request, params GetFleetRecentChangesParams)
	// Scan-queue depth split by lifecycle state
	// (GET /api/v1/fleet/scan-queue)
	GetFleetScanQueue(w http.ResponseWriter, r *http.Request)
	// Fleet-wide compliance score (equal-host mean)
	// (GET /api/v1/fleet/score)
	GetFleetScore(w http.ResponseWriter, r *http.Request, params GetFleetScoreParams)
	// Hosts with the most failing rules (descending)
	// (GET /api/v1/fleet/top-failing-hosts)
	GetFleetTopFailingHosts(w http.ResponseWriter, r *http.Request, params GetFleetTopFailingHostsParams)
	// Rules with the most failing hosts (descending)
	// (GET /api/v1/fleet/top-failing-rules)
	GetFleetTopFailingRules(w http.ResponseWriter, r *http.Request, params GetFleetTopFailingRulesParams)
	// Fleet group summary + every group with its rollup
	// (GET /api/v1/groups)
	GetGroups(w http.ResponseWriter, r *http.Request)
	// Create a group
	// (POST /api/v1/groups)
	PostGroup(w http.ResponseWriter, r *http.Request)
	// Delete a group
	// (DELETE /api/v1/groups/{id})
	DeleteGroup(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Update a group's display fields
	// (PATCH /api/v1/groups/{id})
	PatchGroup(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Add a host to a manual group
	// (POST /api/v1/groups/{id}/members)
	PostGroupMember(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Remove a host from a manual group
	// (DELETE /api/v1/groups/{id}/members/{host_id})
	DeleteGroupMember(w http.ResponseWriter, r *http.Request, id openapi_types.UUID, hostId openapi_types.UUID)
	// Toggle a group's maintenance flag
	// (POST /api/v1/groups/{id}:maintenance)
	PostGroupMaintenance(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Set or clear a site group's compliance target framework
	// (POST /api/v1/groups/{id}:target)
	PostGroupTarget(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Liveness + readiness probe (anonymous)
	// (GET /api/v1/health)
	GetHealth(w http.ResponseWriter, r *http.Request)
	// List hosts
	// (GET /api/v1/hosts)
	GetHosts(w http.ResponseWriter, r *http.Request, params GetHostsParams)
	// Create a host
	// (POST /api/v1/hosts)
	PostHosts(w http.ResponseWriter, r *http.Request)
	// Resolve the credential that will be used for a host
	// (POST /api/v1/hosts/{host_id}/credentials:resolve)
	PostHostCredentialsResolve(w http.ResponseWriter, r *http.Request, hostId openapi_types.UUID)
	// Pause/resume liveness probes for a single host
	// (PUT /api/v1/hosts/{host_id}/maintenance)
	PutHostMaintenance(w http.ResponseWriter, r *http.Request, hostId openapi_types.UUID)
	// Tail the host's monitoring-history rows (most recent first)
	// (GET /api/v1/hosts/{host_id}/monitoring/history)
	GetHostMonitoringHistory(w http.ResponseWriter, r *http.Request, hostId openapi_types.UUID, params GetHostMonitoringHistoryParams)
	// Soft-delete a host
	// (DELETE /api/v1/hosts/{id})
	DeleteHostByID(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Fetch a host with liveness + compliance enrichment
	// (GET /api/v1/hosts/{id})
	GetHostByID(w http.ResponseWriter, r *http.Request, id openapi_types.UUID, params GetHostByIDParams)
	// Update mutable host fields
	// (PATCH /api/v1/hosts/{id})
	PatchHostByID(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Per-host compliance lens (one scan, many framework views)
	// (GET /api/v1/hosts/{id}/compliance)
	GetHostCompliance(w http.ResponseWriter, r *http.Request, id openapi_types.UUID, params GetHostComplianceParams)
	// List a host's currently-failing compliance rules
	// (GET /api/v1/hosts/{id}/compliance/failed-rules)
	GetHostFailedRules(w http.ResponseWriter, r *http.Request, id openapi_types.UUID, params GetHostFailedRulesParams)
	// List the frameworks the host's rule state maps to
	// (GET /api/v1/hosts/{id}/compliance/frameworks)
	GetHostComplianceFrameworks(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// One host's adaptive-scan schedule (Auto-scan tile)
	// (GET /api/v1/hosts/{id}/compliance/schedule)
	GetHostComplianceSchedule(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Daily compliance posture trend for one host
	// (GET /api/v1/hosts/{id}/compliance/trend)
	GetHostComplianceTrend(w http.ResponseWriter, r *http.Request, id openapi_types.UUID, params GetHostComplianceTrendParams)
	// Synchronous on-demand reachability probe for a single host
	// (POST /api/v1/hosts/{id}/connectivity:check)
	PostHostConnectivityCheck(w http.ResponseWriter, r *http.Request, id openapi_types.UUID, params PostHostConnectivityCheckParams)
	// Synchronous on-demand OS fingerprint discovery for a single host
	// (POST /api/v1/hosts/{id}/discovery:run)
	PostHostDiscoveryRun(w http.ResponseWriter, r *http.Request, id openapi_types.UUID, params PostHostDiscoveryRunParams)
	// List a host's compliance exceptions
	// (GET /api/v1/hosts/{id}/exceptions)
	GetHostExceptions(w http.ResponseWriter, r *http.Request, id openapi_types.UUID, params GetHostExceptionsParams)
	// Request a compliance exception (rule waiver) on a host
	// (POST /api/v1/hosts/{id}/exceptions)
	PostHostException(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Enqueue an on-demand compliance scan for a single host
	// (POST /api/v1/hosts/{id}/scans)
	PostHostScan(w http.ResponseWriter, r *http.Request, id openapi_types.UUID, params PostHostScanParams)
	// Read the latest Discovery facts for one host
	// (GET /api/v1/hosts/{id}/system-info)
	GetHostSystemInfo(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Set or clear a host's compliance target framework
	// (POST /api/v1/hosts/{id}:target)
	PostHostTarget(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// List OS Intelligence change events
	// (GET /api/v1/intelligence/events)
	GetIntelligenceEvents(w http.ResponseWriter, r *http.Request, params GetIntelligenceEventsParams)
	// Last full Intelligence snapshot for one host
	// (GET /api/v1/intelligence/state/{host_id})
	GetIntelligenceState(w http.ResponseWriter, r *http.Request, hostId openapi_types.UUID)
	// Get the current license state (tier, status, features, expiry)
	// (GET /api/v1/license)
	GetLicense(w http.ResponseWriter, r *http.Request)
	// List notification channels (secrets redacted)
	// (GET /api/v1/notifications/channels)
	GetNotificationChannels(w http.ResponseWriter, r *http.Request)
	// Create a notification channel
	// (POST /api/v1/notifications/channels)
	PostNotificationChannel(w http.ResponseWriter, r *http.Request)
	// Delete a notification channel
	// (DELETE /api/v1/notifications/channels/{id})
	DeleteNotificationChannel(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Fetch a notification channel (secret redacted)
	// (GET /api/v1/notifications/channels/{id})
	GetNotificationChannel(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Update a notification channel
	// (PATCH /api/v1/notifications/channels/{id})
	PatchNotificationChannel(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Send a synthetic test alert through the channel
	// (POST /api/v1/notifications/channels/{id}:test)
	TestNotificationChannel(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// List the calling user's in-app notifications (the bell)
	// (GET /api/v1/notifications/feed)
	GetNotificationFeed(w http.ResponseWriter, r *http.Request, params GetNotificationFeedParams)
	// Mark one notification read (must belong to the caller)
	// (POST /api/v1/notifications/feed/{id}:read)
	PostNotificationFeedRead(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Mark all the calling user's notifications read
	// (POST /api/v1/notifications/feed:read-all)
	PostNotificationFeedReadAll(w http.ResponseWriter, r *http.Request)
	// List remediation requests (fleet or filtered)
	// (GET /api/v1/remediation/requests)
	ListRemediationRequests(w http.ResponseWriter, r *http.Request, params ListRemediationRequestsParams)
	// Request a remediation (fix) for a failing rule on a host
	// (POST /api/v1/remediation/requests)
	RequestRemediation(w http.ResponseWriter, r *http.Request)
	// Get a remediation request
	// (GET /api/v1/remediation/requests/{rid})
	GetRemediationRequest(w http.ResponseWriter, r *http.Request, rid openapi_types.UUID)
	// Preview what a remediation would do, without changing the host
	// (GET /api/v1/remediation/requests/{rid}/plan)
	GetRemediationPlan(w http.ResponseWriter, r *http.Request, rid openapi_types.UUID)
	// List a remediation request's transaction journal (steps)
	// (GET /api/v1/remediation/requests/{rid}/steps)
	ListRemediationSteps(w http.ResponseWriter, r *http.Request, rid openapi_types.UUID)
	// Approve a pending remediation request
	// (POST /api/v1/remediation/requests/{rid}:approve)
	ApproveRemediation(w http.ResponseWriter, r *http.Request, rid openapi_types.UUID)
	// Dry-run a remediation (preview)
	// (POST /api/v1/remediation/requests/{rid}:dry-run)
	DryRunRemediation(w http.ResponseWriter, r *http.Request, rid openapi_types.UUID)
	// Execute an approved single-rule remediation (free core)
	// (POST /api/v1/remediation/requests/{rid}:execute)
	ExecuteRemediation(w http.ResponseWriter, r *http.Request, rid openapi_types.UUID)
	// Reject a pending remediation request
	// (POST /api/v1/remediation/requests/{rid}:reject)
	RejectRemediation(w http.ResponseWriter, r *http.Request, rid openapi_types.UUID)
	// Roll back an executed remediation (free core)
	// (POST /api/v1/remediation/requests/{rid}:rollback)
	RollbackRemediation(w http.ResponseWriter, r *http.Request, rid openapi_types.UUID)
	// List generated reports (newest first)
	// (GET /api/v1/reports)
	GetReports(w http.ResponseWriter, r *http.Request)
	// List the framework lenses available across the fleet
	// (GET /api/v1/reports/frameworks)
	GetReportFrameworks(w http.ResponseWriter, r *http.Request)
	// List the report delivery schedules
	// (GET /api/v1/reports/schedules)
	GetReportSchedules(w http.ResponseWriter, r *http.Request)
	// Create a report delivery schedule
	// (POST /api/v1/reports/schedules)
	CreateReportSchedule(w http.ResponseWriter, r *http.Request)
	// Delete a report schedule
	// (DELETE /api/v1/reports/schedules/{id})
	DeleteReportSchedule(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Enable or disable a report schedule
	// (PATCH /api/v1/reports/schedules/{id})
	UpdateReportSchedule(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// The public key for verifying report signatures
	// (GET /api/v1/reports/signing-key)
	GetReportSigningKey(w http.ResponseWriter, r *http.Request)
	// Fetch one report (with its stored JSON posture)
	// (GET /api/v1/reports/{id})
	GetReportByID(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Download a rendered face of a report (PDF, JSON, CSV, or OSCAL SAR)
	// (GET /api/v1/reports/{id}/export)
	GetReportExport(w http.ResponseWriter, r *http.Request, id openapi_types.UUID, params GetReportExportParams)
	// Generate a Fleet Compliance Executive Summary
	// (POST /api/v1/reports:generate)
	PostReportGenerate(w http.ResponseWriter, r *http.Request)
	// List built-in roles
	// (GET /api/v1/roles)
	GetRoles(w http.ResponseWriter, r *http.Request)
	// Create a custom role
	// (POST /api/v1/roles:create)
	PostRolesCreate(w http.ResponseWriter, r *http.Request)
	// List the Kensa rule library (the full rule catalog)
	// (GET /api/v1/rules)
	GetRules(w http.ResponseWriter, r *http.Request)
	// List a host's compliance scans (newest first)
	// (GET /api/v1/scans)
	GetScans(w http.ResponseWriter, r *http.Request, params GetScansParams)
	// One scan's metadata + per-rule results (no inline evidence)
	// (GET /api/v1/scans/{id})
	GetScanByID(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// A whole scan as an OSCAL 1.0.6 Assessment Results document
	// (GET /api/v1/scans/{id}/oscal)
	GetScanOSCAL(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// One rule's full evidence for a scan (the drill-down payload)
	// (GET /api/v1/scans/{id}/rules/{ruleId}/evidence)
	GetScanRuleEvidence(w http.ResponseWriter, r *http.Request, id openapi_types.UUID, ruleId string)
	// One rule's outcome as an OSCAL 1.0.6 Assessment Results document
	// (GET /api/v1/scans/{id}/rules/{ruleId}/oscal)
	GetScanRuleOSCAL(w http.ResponseWriter, r *http.Request, id openapi_types.UUID, ruleId string)
	// List SSO providers (metadata only; client secret never returned)
	// (GET /api/v1/sso/providers)
	GetSSOProviders(w http.ResponseWriter, r *http.Request)
	// Create an SSO provider
	// (POST /api/v1/sso/providers)
	PostSSOProvider(w http.ResponseWriter, r *http.Request)
	// List enabled SSO providers for the sign-in picker (anonymous)
	// (GET /api/v1/sso/providers/enabled)
	GetSSOProvidersEnabled(w http.ResponseWriter, r *http.Request)
	// Delete an SSO provider (cascades its identities + states)
	// (DELETE /api/v1/sso/providers/{id})
	DeleteSSOProvider(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// View one SSO provider (metadata only)
	// (GET /api/v1/sso/providers/{id})
	GetSSOProvider(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Update an SSO provider (omit client_secret to keep the existing one)
	// (PUT /api/v1/sso/providers/{id})
	PutSSOProvider(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Read the org-wide compliance-display config (default lens)
	// (GET /api/v1/system/compliance/config)
	GetSystemComplianceConfig(w http.ResponseWriter, r *http.Request)
	// Set the default compliance lens (framework family, or empty for All rules)
	// (PUT /api/v1/system/compliance/config)
	PutSystemComplianceConfig(w http.ResponseWriter, r *http.Request)
	// Read the connectivity-monitor runtime config + baked-in defaults
	// (GET /api/v1/system/connectivity/config)
	GetSystemConnectivityConfig(w http.ResponseWriter, r *http.Request)
	// Update connectivity-monitor runtime config
	// (PUT /api/v1/system/connectivity/config)
	PutSystemConnectivityConfig(w http.ResponseWriter, r *http.Request)
	// Read the connectivity-monitor in-process metrics + maintenance flag
	// (GET /api/v1/system/connectivity/status)
	GetSystemConnectivityStatus(w http.ResponseWriter, r *http.Request)
	// Read the OS discovery scheduler runtime config + baked-in defaults
	// (GET /api/v1/system/discovery/config)
	GetSystemDiscoveryConfig(w http.ResponseWriter, r *http.Request)
	// Update OS discovery scheduler runtime config
	// (PUT /api/v1/system/discovery/config)
	PutSystemDiscoveryConfig(w http.ResponseWriter, r *http.Request)
	// Enqueue a host.discovery job for every host with NULL os_discovered_at
	// (POST /api/v1/system/discovery/sweep)
	PostSystemDiscoverySweep(w http.ResponseWriter, r *http.Request)
	// Read the OS Intelligence scheduler runtime config + baked-in defaults
	// (GET /api/v1/system/intelligence/config)
	GetSystemIntelligenceConfig(w http.ResponseWriter, r *http.Request)
	// Update OS Intelligence scheduler runtime config
	// (PUT /api/v1/system/intelligence/config)
	PutSystemIntelligenceConfig(w http.ResponseWriter, r *http.Request)
	// Read the adaptive compliance scan scheduler config + baked-in defaults
	// (GET /api/v1/system/scan/config)
	GetSystemScanConfig(w http.ResponseWriter, r *http.Request)
	// Update the adaptive compliance scan scheduler config
	// (PUT /api/v1/system/scan/config)
	PutSystemScanConfig(w http.ResponseWriter, r *http.Request)
	// 24h forward projection of the compliance scan schedule
	// (GET /api/v1/system/scan/schedule-preview)
	GetSystemScanSchedulePreview(w http.ResponseWriter, r *http.Request)
	// List the corpus-used kensa rule-template variables with defaults and overrides
	// (GET /api/v1/system/scan/variables)
	GetSystemScanVariables(w http.ResponseWriter, r *http.Request)
	// Replace the operator variable overrides
	// (PUT /api/v1/system/scan/variables)
	PutSystemScanVariables(w http.ResponseWriter, r *http.Request)
	// List API tokens (metadata only; secrets never returned)
	// (GET /api/v1/tokens)
	GetAPITokens(w http.ResponseWriter, r *http.Request)
	// Create an API token (the secret is returned once, here only)
	// (POST /api/v1/tokens)
	PostAPIToken(w http.ResponseWriter, r *http.Request)
	// Revoke an API token
	// (DELETE /api/v1/tokens/{id})
	DeleteAPIToken(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// List users
	// (GET /api/v1/users)
	GetUsers(w http.ResponseWriter, r *http.Request)
	// Create a user
	// (POST /api/v1/users)
	PostUsers(w http.ResponseWriter, r *http.Request)
	// Return the calling user's UI preferences
	// (GET /api/v1/users/me/preferences)
	GetUsersMePreferences(w http.ResponseWriter, r *http.Request)
	// Merge a partial update into the calling user's UI preferences
	// (PATCH /api/v1/users/me/preferences)
	PatchUsersMePreferences(w http.ResponseWriter, r *http.Request)
	// Soft-delete a user
	// (DELETE /api/v1/users/{id})
	DeleteUserByID(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Fetch a user
	// (GET /api/v1/users/{id})
	GetUserByID(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Assign a role to a user
	// (POST /api/v1/users/{id}/roles:assign)
	PostUserRolesAssign(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Remove a role from a user
	// (POST /api/v1/users/{id}/roles:unassign)
	PostUserRolesUnassign(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Disable a user account
	// (POST /api/v1/users/{id}:disable)
	PostUserDisable(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Re-enable a disabled user account
	// (POST /api/v1/users/{id}:enable)
	PostUserEnable(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Admin-reset a user's password (own or another's)
	// (POST /api/v1/users/{id}:reset-password)
	PostUserResetPassword(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)
	// Build/version metadata (anonymous)
	// (GET /api/v1/version)
	GetVersion(w http.ResponseWriter, r *http.Request)
}

ServerInterface represents all server handlers.

type ServerInterfaceWrapper

type ServerInterfaceWrapper struct {
	Handler            ServerInterface
	HandlerMiddlewares []MiddlewareFunc
	ErrorHandlerFunc   func(w http.ResponseWriter, r *http.Request, err error)
}

ServerInterfaceWrapper converts contexts to parameters.

func (*ServerInterfaceWrapper) ApproveRemediation

func (siw *ServerInterfaceWrapper) ApproveRemediation(w http.ResponseWriter, r *http.Request)

ApproveRemediation operation middleware

func (*ServerInterfaceWrapper) CreateReportSchedule

func (siw *ServerInterfaceWrapper) CreateReportSchedule(w http.ResponseWriter, r *http.Request)

CreateReportSchedule operation middleware

func (*ServerInterfaceWrapper) DeleteAPIToken

func (siw *ServerInterfaceWrapper) DeleteAPIToken(w http.ResponseWriter, r *http.Request)

DeleteAPIToken operation middleware

func (*ServerInterfaceWrapper) DeleteCredentialByID

func (siw *ServerInterfaceWrapper) DeleteCredentialByID(w http.ResponseWriter, r *http.Request)

DeleteCredentialByID operation middleware

func (*ServerInterfaceWrapper) DeleteGroup

func (siw *ServerInterfaceWrapper) DeleteGroup(w http.ResponseWriter, r *http.Request)

DeleteGroup operation middleware

func (*ServerInterfaceWrapper) DeleteGroupMember

func (siw *ServerInterfaceWrapper) DeleteGroupMember(w http.ResponseWriter, r *http.Request)

DeleteGroupMember operation middleware

func (*ServerInterfaceWrapper) DeleteHostByID

func (siw *ServerInterfaceWrapper) DeleteHostByID(w http.ResponseWriter, r *http.Request)

DeleteHostByID operation middleware

func (*ServerInterfaceWrapper) DeleteNotificationChannel

func (siw *ServerInterfaceWrapper) DeleteNotificationChannel(w http.ResponseWriter, r *http.Request)

DeleteNotificationChannel operation middleware

func (*ServerInterfaceWrapper) DeleteReportSchedule

func (siw *ServerInterfaceWrapper) DeleteReportSchedule(w http.ResponseWriter, r *http.Request)

DeleteReportSchedule operation middleware

func (*ServerInterfaceWrapper) DeleteSSOProvider

func (siw *ServerInterfaceWrapper) DeleteSSOProvider(w http.ResponseWriter, r *http.Request)

DeleteSSOProvider operation middleware

func (*ServerInterfaceWrapper) DeleteUserByID

func (siw *ServerInterfaceWrapper) DeleteUserByID(w http.ResponseWriter, r *http.Request)

DeleteUserByID operation middleware

func (*ServerInterfaceWrapper) DryRunRemediation

func (siw *ServerInterfaceWrapper) DryRunRemediation(w http.ResponseWriter, r *http.Request)

DryRunRemediation operation middleware

func (*ServerInterfaceWrapper) ExecuteRemediation

func (siw *ServerInterfaceWrapper) ExecuteRemediation(w http.ResponseWriter, r *http.Request)

ExecuteRemediation operation middleware

func (*ServerInterfaceWrapper) GetAPITokens

func (siw *ServerInterfaceWrapper) GetAPITokens(w http.ResponseWriter, r *http.Request)

GetAPITokens operation middleware

func (*ServerInterfaceWrapper) GetActivity

func (siw *ServerInterfaceWrapper) GetActivity(w http.ResponseWriter, r *http.Request)

GetActivity operation middleware

func (*ServerInterfaceWrapper) GetAlertByID

func (siw *ServerInterfaceWrapper) GetAlertByID(w http.ResponseWriter, r *http.Request)

GetAlertByID operation middleware

func (*ServerInterfaceWrapper) GetAlerts

func (siw *ServerInterfaceWrapper) GetAlerts(w http.ResponseWriter, r *http.Request)

GetAlerts operation middleware

func (*ServerInterfaceWrapper) GetAuditEvents

func (siw *ServerInterfaceWrapper) GetAuditEvents(w http.ResponseWriter, r *http.Request)

GetAuditEvents operation middleware

func (*ServerInterfaceWrapper) GetAuditEventsExport

func (siw *ServerInterfaceWrapper) GetAuditEventsExport(w http.ResponseWriter, r *http.Request)

GetAuditEventsExport operation middleware

func (*ServerInterfaceWrapper) GetAuthMe

func (siw *ServerInterfaceWrapper) GetAuthMe(w http.ResponseWriter, r *http.Request)

GetAuthMe operation middleware

func (*ServerInterfaceWrapper) GetAuthMePermissions

func (siw *ServerInterfaceWrapper) GetAuthMePermissions(w http.ResponseWriter, r *http.Request)

GetAuthMePermissions operation middleware

func (*ServerInterfaceWrapper) GetAuthPermissionsRegistry

func (siw *ServerInterfaceWrapper) GetAuthPermissionsRegistry(w http.ResponseWriter, r *http.Request)

GetAuthPermissionsRegistry operation middleware

func (*ServerInterfaceWrapper) GetAuthPolicy

func (siw *ServerInterfaceWrapper) GetAuthPolicy(w http.ResponseWriter, r *http.Request)

GetAuthPolicy operation middleware

func (*ServerInterfaceWrapper) GetAuthSSOCallback

func (siw *ServerInterfaceWrapper) GetAuthSSOCallback(w http.ResponseWriter, r *http.Request)

GetAuthSSOCallback operation middleware

func (*ServerInterfaceWrapper) GetAuthSSOLogin

func (siw *ServerInterfaceWrapper) GetAuthSSOLogin(w http.ResponseWriter, r *http.Request)

GetAuthSSOLogin operation middleware

func (*ServerInterfaceWrapper) GetCapabilities added in v0.7.0

func (siw *ServerInterfaceWrapper) GetCapabilities(w http.ResponseWriter, r *http.Request)

GetCapabilities operation middleware

func (*ServerInterfaceWrapper) GetComplianceExceptions

func (siw *ServerInterfaceWrapper) GetComplianceExceptions(w http.ResponseWriter, r *http.Request)

GetComplianceExceptions operation middleware

func (*ServerInterfaceWrapper) GetComplianceFrameworks added in v0.4.0

func (siw *ServerInterfaceWrapper) GetComplianceFrameworks(w http.ResponseWriter, r *http.Request)

GetComplianceFrameworks operation middleware

func (*ServerInterfaceWrapper) GetCredentialByID

func (siw *ServerInterfaceWrapper) GetCredentialByID(w http.ResponseWriter, r *http.Request)

GetCredentialByID operation middleware

func (*ServerInterfaceWrapper) GetCredentials

func (siw *ServerInterfaceWrapper) GetCredentials(w http.ResponseWriter, r *http.Request)

GetCredentials operation middleware

func (*ServerInterfaceWrapper) GetFleetComplianceStates

func (siw *ServerInterfaceWrapper) GetFleetComplianceStates(w http.ResponseWriter, r *http.Request)

GetFleetComplianceStates operation middleware

func (*ServerInterfaceWrapper) GetFleetComplianceTrend

func (siw *ServerInterfaceWrapper) GetFleetComplianceTrend(w http.ResponseWriter, r *http.Request)

GetFleetComplianceTrend operation middleware

func (*ServerInterfaceWrapper) GetFleetConnectivityBreakdown

func (siw *ServerInterfaceWrapper) GetFleetConnectivityBreakdown(w http.ResponseWriter, r *http.Request)

GetFleetConnectivityBreakdown operation middleware

func (*ServerInterfaceWrapper) GetFleetLiveness

func (siw *ServerInterfaceWrapper) GetFleetLiveness(w http.ResponseWriter, r *http.Request)

GetFleetLiveness operation middleware

func (*ServerInterfaceWrapper) GetFleetRecentChanges

func (siw *ServerInterfaceWrapper) GetFleetRecentChanges(w http.ResponseWriter, r *http.Request)

GetFleetRecentChanges operation middleware

func (*ServerInterfaceWrapper) GetFleetScanQueue

func (siw *ServerInterfaceWrapper) GetFleetScanQueue(w http.ResponseWriter, r *http.Request)

GetFleetScanQueue operation middleware

func (*ServerInterfaceWrapper) GetFleetScore

func (siw *ServerInterfaceWrapper) GetFleetScore(w http.ResponseWriter, r *http.Request)

GetFleetScore operation middleware

func (*ServerInterfaceWrapper) GetFleetTopFailingHosts

func (siw *ServerInterfaceWrapper) GetFleetTopFailingHosts(w http.ResponseWriter, r *http.Request)

GetFleetTopFailingHosts operation middleware

func (*ServerInterfaceWrapper) GetFleetTopFailingRules

func (siw *ServerInterfaceWrapper) GetFleetTopFailingRules(w http.ResponseWriter, r *http.Request)

GetFleetTopFailingRules operation middleware

func (*ServerInterfaceWrapper) GetGroups

func (siw *ServerInterfaceWrapper) GetGroups(w http.ResponseWriter, r *http.Request)

GetGroups operation middleware

func (*ServerInterfaceWrapper) GetHealth

func (siw *ServerInterfaceWrapper) GetHealth(w http.ResponseWriter, r *http.Request)

GetHealth operation middleware

func (*ServerInterfaceWrapper) GetHostByID

func (siw *ServerInterfaceWrapper) GetHostByID(w http.ResponseWriter, r *http.Request)

GetHostByID operation middleware

func (*ServerInterfaceWrapper) GetHostCompliance

func (siw *ServerInterfaceWrapper) GetHostCompliance(w http.ResponseWriter, r *http.Request)

GetHostCompliance operation middleware

func (*ServerInterfaceWrapper) GetHostComplianceFrameworks

func (siw *ServerInterfaceWrapper) GetHostComplianceFrameworks(w http.ResponseWriter, r *http.Request)

GetHostComplianceFrameworks operation middleware

func (*ServerInterfaceWrapper) GetHostComplianceSchedule

func (siw *ServerInterfaceWrapper) GetHostComplianceSchedule(w http.ResponseWriter, r *http.Request)

GetHostComplianceSchedule operation middleware

func (*ServerInterfaceWrapper) GetHostComplianceTrend

func (siw *ServerInterfaceWrapper) GetHostComplianceTrend(w http.ResponseWriter, r *http.Request)

GetHostComplianceTrend operation middleware

func (*ServerInterfaceWrapper) GetHostExceptions

func (siw *ServerInterfaceWrapper) GetHostExceptions(w http.ResponseWriter, r *http.Request)

GetHostExceptions operation middleware

func (*ServerInterfaceWrapper) GetHostFailedRules

func (siw *ServerInterfaceWrapper) GetHostFailedRules(w http.ResponseWriter, r *http.Request)

GetHostFailedRules operation middleware

func (*ServerInterfaceWrapper) GetHostMonitoringHistory

func (siw *ServerInterfaceWrapper) GetHostMonitoringHistory(w http.ResponseWriter, r *http.Request)

GetHostMonitoringHistory operation middleware

func (*ServerInterfaceWrapper) GetHostSystemInfo

func (siw *ServerInterfaceWrapper) GetHostSystemInfo(w http.ResponseWriter, r *http.Request)

GetHostSystemInfo operation middleware

func (*ServerInterfaceWrapper) GetHosts

func (siw *ServerInterfaceWrapper) GetHosts(w http.ResponseWriter, r *http.Request)

GetHosts operation middleware

func (*ServerInterfaceWrapper) GetIntelligenceEvents

func (siw *ServerInterfaceWrapper) GetIntelligenceEvents(w http.ResponseWriter, r *http.Request)

GetIntelligenceEvents operation middleware

func (*ServerInterfaceWrapper) GetIntelligenceState

func (siw *ServerInterfaceWrapper) GetIntelligenceState(w http.ResponseWriter, r *http.Request)

GetIntelligenceState operation middleware

func (*ServerInterfaceWrapper) GetLicense

func (siw *ServerInterfaceWrapper) GetLicense(w http.ResponseWriter, r *http.Request)

GetLicense operation middleware

func (*ServerInterfaceWrapper) GetNotificationChannel

func (siw *ServerInterfaceWrapper) GetNotificationChannel(w http.ResponseWriter, r *http.Request)

GetNotificationChannel operation middleware

func (*ServerInterfaceWrapper) GetNotificationChannels

func (siw *ServerInterfaceWrapper) GetNotificationChannels(w http.ResponseWriter, r *http.Request)

GetNotificationChannels operation middleware

func (*ServerInterfaceWrapper) GetNotificationFeed

func (siw *ServerInterfaceWrapper) GetNotificationFeed(w http.ResponseWriter, r *http.Request)

GetNotificationFeed operation middleware

func (*ServerInterfaceWrapper) GetRemediationPlan added in v0.7.1

func (siw *ServerInterfaceWrapper) GetRemediationPlan(w http.ResponseWriter, r *http.Request)

GetRemediationPlan operation middleware

func (*ServerInterfaceWrapper) GetRemediationRequest

func (siw *ServerInterfaceWrapper) GetRemediationRequest(w http.ResponseWriter, r *http.Request)

GetRemediationRequest operation middleware

func (*ServerInterfaceWrapper) GetReportByID

func (siw *ServerInterfaceWrapper) GetReportByID(w http.ResponseWriter, r *http.Request)

GetReportByID operation middleware

func (*ServerInterfaceWrapper) GetReportExport

func (siw *ServerInterfaceWrapper) GetReportExport(w http.ResponseWriter, r *http.Request)

GetReportExport operation middleware

func (*ServerInterfaceWrapper) GetReportFrameworks

func (siw *ServerInterfaceWrapper) GetReportFrameworks(w http.ResponseWriter, r *http.Request)

GetReportFrameworks operation middleware

func (*ServerInterfaceWrapper) GetReportSchedules

func (siw *ServerInterfaceWrapper) GetReportSchedules(w http.ResponseWriter, r *http.Request)

GetReportSchedules operation middleware

func (*ServerInterfaceWrapper) GetReportSigningKey

func (siw *ServerInterfaceWrapper) GetReportSigningKey(w http.ResponseWriter, r *http.Request)

GetReportSigningKey operation middleware

func (*ServerInterfaceWrapper) GetReports

func (siw *ServerInterfaceWrapper) GetReports(w http.ResponseWriter, r *http.Request)

GetReports operation middleware

func (*ServerInterfaceWrapper) GetRoles

func (siw *ServerInterfaceWrapper) GetRoles(w http.ResponseWriter, r *http.Request)

GetRoles operation middleware

func (*ServerInterfaceWrapper) GetRules

func (siw *ServerInterfaceWrapper) GetRules(w http.ResponseWriter, r *http.Request)

GetRules operation middleware

func (*ServerInterfaceWrapper) GetSSOProvider

func (siw *ServerInterfaceWrapper) GetSSOProvider(w http.ResponseWriter, r *http.Request)

GetSSOProvider operation middleware

func (*ServerInterfaceWrapper) GetSSOProviders

func (siw *ServerInterfaceWrapper) GetSSOProviders(w http.ResponseWriter, r *http.Request)

GetSSOProviders operation middleware

func (*ServerInterfaceWrapper) GetSSOProvidersEnabled

func (siw *ServerInterfaceWrapper) GetSSOProvidersEnabled(w http.ResponseWriter, r *http.Request)

GetSSOProvidersEnabled operation middleware

func (*ServerInterfaceWrapper) GetScanByID

func (siw *ServerInterfaceWrapper) GetScanByID(w http.ResponseWriter, r *http.Request)

GetScanByID operation middleware

func (*ServerInterfaceWrapper) GetScanOSCAL

func (siw *ServerInterfaceWrapper) GetScanOSCAL(w http.ResponseWriter, r *http.Request)

GetScanOSCAL operation middleware

func (*ServerInterfaceWrapper) GetScanRuleEvidence

func (siw *ServerInterfaceWrapper) GetScanRuleEvidence(w http.ResponseWriter, r *http.Request)

GetScanRuleEvidence operation middleware

func (*ServerInterfaceWrapper) GetScanRuleOSCAL

func (siw *ServerInterfaceWrapper) GetScanRuleOSCAL(w http.ResponseWriter, r *http.Request)

GetScanRuleOSCAL operation middleware

func (*ServerInterfaceWrapper) GetScans

func (siw *ServerInterfaceWrapper) GetScans(w http.ResponseWriter, r *http.Request)

GetScans operation middleware

func (*ServerInterfaceWrapper) GetSystemComplianceConfig added in v0.4.0

func (siw *ServerInterfaceWrapper) GetSystemComplianceConfig(w http.ResponseWriter, r *http.Request)

GetSystemComplianceConfig operation middleware

func (*ServerInterfaceWrapper) GetSystemConnectivityConfig

func (siw *ServerInterfaceWrapper) GetSystemConnectivityConfig(w http.ResponseWriter, r *http.Request)

GetSystemConnectivityConfig operation middleware

func (*ServerInterfaceWrapper) GetSystemConnectivityStatus

func (siw *ServerInterfaceWrapper) GetSystemConnectivityStatus(w http.ResponseWriter, r *http.Request)

GetSystemConnectivityStatus operation middleware

func (*ServerInterfaceWrapper) GetSystemDiscoveryConfig

func (siw *ServerInterfaceWrapper) GetSystemDiscoveryConfig(w http.ResponseWriter, r *http.Request)

GetSystemDiscoveryConfig operation middleware

func (*ServerInterfaceWrapper) GetSystemIntelligenceConfig

func (siw *ServerInterfaceWrapper) GetSystemIntelligenceConfig(w http.ResponseWriter, r *http.Request)

GetSystemIntelligenceConfig operation middleware

func (*ServerInterfaceWrapper) GetSystemScanConfig

func (siw *ServerInterfaceWrapper) GetSystemScanConfig(w http.ResponseWriter, r *http.Request)

GetSystemScanConfig operation middleware

func (*ServerInterfaceWrapper) GetSystemScanSchedulePreview

func (siw *ServerInterfaceWrapper) GetSystemScanSchedulePreview(w http.ResponseWriter, r *http.Request)

GetSystemScanSchedulePreview operation middleware

func (*ServerInterfaceWrapper) GetSystemScanVariables

func (siw *ServerInterfaceWrapper) GetSystemScanVariables(w http.ResponseWriter, r *http.Request)

GetSystemScanVariables operation middleware

func (*ServerInterfaceWrapper) GetUserByID

func (siw *ServerInterfaceWrapper) GetUserByID(w http.ResponseWriter, r *http.Request)

GetUserByID operation middleware

func (*ServerInterfaceWrapper) GetUsers

func (siw *ServerInterfaceWrapper) GetUsers(w http.ResponseWriter, r *http.Request)

GetUsers operation middleware

func (*ServerInterfaceWrapper) GetUsersMePreferences

func (siw *ServerInterfaceWrapper) GetUsersMePreferences(w http.ResponseWriter, r *http.Request)

GetUsersMePreferences operation middleware

func (*ServerInterfaceWrapper) GetVersion

func (siw *ServerInterfaceWrapper) GetVersion(w http.ResponseWriter, r *http.Request)

GetVersion operation middleware

func (*ServerInterfaceWrapper) ListRemediationRequests

func (siw *ServerInterfaceWrapper) ListRemediationRequests(w http.ResponseWriter, r *http.Request)

ListRemediationRequests operation middleware

func (*ServerInterfaceWrapper) ListRemediationSteps

func (siw *ServerInterfaceWrapper) ListRemediationSteps(w http.ResponseWriter, r *http.Request)

ListRemediationSteps operation middleware

func (*ServerInterfaceWrapper) PatchAuthMe added in v0.4.0

func (siw *ServerInterfaceWrapper) PatchAuthMe(w http.ResponseWriter, r *http.Request)

PatchAuthMe operation middleware

func (*ServerInterfaceWrapper) PatchCredentialByID

func (siw *ServerInterfaceWrapper) PatchCredentialByID(w http.ResponseWriter, r *http.Request)

PatchCredentialByID operation middleware

func (*ServerInterfaceWrapper) PatchGroup

func (siw *ServerInterfaceWrapper) PatchGroup(w http.ResponseWriter, r *http.Request)

PatchGroup operation middleware

func (*ServerInterfaceWrapper) PatchHostByID

func (siw *ServerInterfaceWrapper) PatchHostByID(w http.ResponseWriter, r *http.Request)

PatchHostByID operation middleware

func (*ServerInterfaceWrapper) PatchNotificationChannel

func (siw *ServerInterfaceWrapper) PatchNotificationChannel(w http.ResponseWriter, r *http.Request)

PatchNotificationChannel operation middleware

func (*ServerInterfaceWrapper) PatchUsersMePreferences

func (siw *ServerInterfaceWrapper) PatchUsersMePreferences(w http.ResponseWriter, r *http.Request)

PatchUsersMePreferences operation middleware

func (*ServerInterfaceWrapper) PostAPIToken

func (siw *ServerInterfaceWrapper) PostAPIToken(w http.ResponseWriter, r *http.Request)

PostAPIToken operation middleware

func (*ServerInterfaceWrapper) PostAdminLicenseVerify

func (siw *ServerInterfaceWrapper) PostAdminLicenseVerify(w http.ResponseWriter, r *http.Request)

PostAdminLicenseVerify operation middleware

func (*ServerInterfaceWrapper) PostAdminPoliciesReload

func (siw *ServerInterfaceWrapper) PostAdminPoliciesReload(w http.ResponseWriter, r *http.Request)

PostAdminPoliciesReload operation middleware

func (*ServerInterfaceWrapper) PostAlertAcknowledge

func (siw *ServerInterfaceWrapper) PostAlertAcknowledge(w http.ResponseWriter, r *http.Request)

PostAlertAcknowledge operation middleware

func (*ServerInterfaceWrapper) PostAlertDismiss

func (siw *ServerInterfaceWrapper) PostAlertDismiss(w http.ResponseWriter, r *http.Request)

PostAlertDismiss operation middleware

func (*ServerInterfaceWrapper) PostAlertResolve

func (siw *ServerInterfaceWrapper) PostAlertResolve(w http.ResponseWriter, r *http.Request)

PostAlertResolve operation middleware

func (*ServerInterfaceWrapper) PostAlertSilence

func (siw *ServerInterfaceWrapper) PostAlertSilence(w http.ResponseWriter, r *http.Request)

PostAlertSilence operation middleware

func (*ServerInterfaceWrapper) PostAuthLogin

func (siw *ServerInterfaceWrapper) PostAuthLogin(w http.ResponseWriter, r *http.Request)

PostAuthLogin operation middleware

func (*ServerInterfaceWrapper) PostAuthLogout

func (siw *ServerInterfaceWrapper) PostAuthLogout(w http.ResponseWriter, r *http.Request)

PostAuthLogout operation middleware

func (*ServerInterfaceWrapper) PostAuthMFAEnroll

func (siw *ServerInterfaceWrapper) PostAuthMFAEnroll(w http.ResponseWriter, r *http.Request)

PostAuthMFAEnroll operation middleware

func (*ServerInterfaceWrapper) PostAuthMFAVerify

func (siw *ServerInterfaceWrapper) PostAuthMFAVerify(w http.ResponseWriter, r *http.Request)

PostAuthMFAVerify operation middleware

func (*ServerInterfaceWrapper) PostAuthPasswordChange

func (siw *ServerInterfaceWrapper) PostAuthPasswordChange(w http.ResponseWriter, r *http.Request)

PostAuthPasswordChange operation middleware

func (*ServerInterfaceWrapper) PostAuthRefresh

func (siw *ServerInterfaceWrapper) PostAuthRefresh(w http.ResponseWriter, r *http.Request)

PostAuthRefresh operation middleware

func (*ServerInterfaceWrapper) PostAuthRefreshCookie

func (siw *ServerInterfaceWrapper) PostAuthRefreshCookie(w http.ResponseWriter, r *http.Request)

PostAuthRefreshCookie operation middleware

func (*ServerInterfaceWrapper) PostCredentialClone

func (siw *ServerInterfaceWrapper) PostCredentialClone(w http.ResponseWriter, r *http.Request)

PostCredentialClone operation middleware

func (*ServerInterfaceWrapper) PostCredentials

func (siw *ServerInterfaceWrapper) PostCredentials(w http.ResponseWriter, r *http.Request)

PostCredentials operation middleware

func (*ServerInterfaceWrapper) PostDiagnosticsEcho

func (siw *ServerInterfaceWrapper) PostDiagnosticsEcho(w http.ResponseWriter, r *http.Request)

PostDiagnosticsEcho operation middleware

func (*ServerInterfaceWrapper) PostDiagnosticsEnqueueTestJob

func (siw *ServerInterfaceWrapper) PostDiagnosticsEnqueueTestJob(w http.ResponseWriter, r *http.Request)

PostDiagnosticsEnqueueTestJob operation middleware

func (*ServerInterfaceWrapper) PostDiagnosticsEvaluateAlert

func (siw *ServerInterfaceWrapper) PostDiagnosticsEvaluateAlert(w http.ResponseWriter, r *http.Request)

PostDiagnosticsEvaluateAlert operation middleware

func (*ServerInterfaceWrapper) PostDiagnosticsPremiumEcho

func (siw *ServerInterfaceWrapper) PostDiagnosticsPremiumEcho(w http.ResponseWriter, r *http.Request)

PostDiagnosticsPremiumEcho operation middleware

func (*ServerInterfaceWrapper) PostDiagnosticsRequireHostRead

func (siw *ServerInterfaceWrapper) PostDiagnosticsRequireHostRead(w http.ResponseWriter, r *http.Request)

PostDiagnosticsRequireHostRead operation middleware

func (*ServerInterfaceWrapper) PostDiagnosticsRequireHostWrite

func (siw *ServerInterfaceWrapper) PostDiagnosticsRequireHostWrite(w http.ResponseWriter, r *http.Request)

PostDiagnosticsRequireHostWrite operation middleware

func (*ServerInterfaceWrapper) PostDiagnosticsRequireRemediationExecute

func (siw *ServerInterfaceWrapper) PostDiagnosticsRequireRemediationExecute(w http.ResponseWriter, r *http.Request)

PostDiagnosticsRequireRemediationExecute operation middleware

func (*ServerInterfaceWrapper) PostExceptionApprove

func (siw *ServerInterfaceWrapper) PostExceptionApprove(w http.ResponseWriter, r *http.Request)

PostExceptionApprove operation middleware

func (*ServerInterfaceWrapper) PostExceptionReject

func (siw *ServerInterfaceWrapper) PostExceptionReject(w http.ResponseWriter, r *http.Request)

PostExceptionReject operation middleware

func (*ServerInterfaceWrapper) PostExceptionRevoke

func (siw *ServerInterfaceWrapper) PostExceptionRevoke(w http.ResponseWriter, r *http.Request)

PostExceptionRevoke operation middleware

func (*ServerInterfaceWrapper) PostGroup

func (siw *ServerInterfaceWrapper) PostGroup(w http.ResponseWriter, r *http.Request)

PostGroup operation middleware

func (*ServerInterfaceWrapper) PostGroupMaintenance

func (siw *ServerInterfaceWrapper) PostGroupMaintenance(w http.ResponseWriter, r *http.Request)

PostGroupMaintenance operation middleware

func (*ServerInterfaceWrapper) PostGroupMember

func (siw *ServerInterfaceWrapper) PostGroupMember(w http.ResponseWriter, r *http.Request)

PostGroupMember operation middleware

func (*ServerInterfaceWrapper) PostGroupTarget added in v0.5.0

func (siw *ServerInterfaceWrapper) PostGroupTarget(w http.ResponseWriter, r *http.Request)

PostGroupTarget operation middleware

func (*ServerInterfaceWrapper) PostHostConnectivityCheck

func (siw *ServerInterfaceWrapper) PostHostConnectivityCheck(w http.ResponseWriter, r *http.Request)

PostHostConnectivityCheck operation middleware

func (*ServerInterfaceWrapper) PostHostCredentialsResolve

func (siw *ServerInterfaceWrapper) PostHostCredentialsResolve(w http.ResponseWriter, r *http.Request)

PostHostCredentialsResolve operation middleware

func (*ServerInterfaceWrapper) PostHostDiscoveryRun

func (siw *ServerInterfaceWrapper) PostHostDiscoveryRun(w http.ResponseWriter, r *http.Request)

PostHostDiscoveryRun operation middleware

func (*ServerInterfaceWrapper) PostHostException

func (siw *ServerInterfaceWrapper) PostHostException(w http.ResponseWriter, r *http.Request)

PostHostException operation middleware

func (*ServerInterfaceWrapper) PostHostScan

func (siw *ServerInterfaceWrapper) PostHostScan(w http.ResponseWriter, r *http.Request)

PostHostScan operation middleware

func (*ServerInterfaceWrapper) PostHostTarget added in v0.5.0

func (siw *ServerInterfaceWrapper) PostHostTarget(w http.ResponseWriter, r *http.Request)

PostHostTarget operation middleware

func (*ServerInterfaceWrapper) PostHosts

func (siw *ServerInterfaceWrapper) PostHosts(w http.ResponseWriter, r *http.Request)

PostHosts operation middleware

func (*ServerInterfaceWrapper) PostNotificationChannel

func (siw *ServerInterfaceWrapper) PostNotificationChannel(w http.ResponseWriter, r *http.Request)

PostNotificationChannel operation middleware

func (*ServerInterfaceWrapper) PostNotificationFeedRead

func (siw *ServerInterfaceWrapper) PostNotificationFeedRead(w http.ResponseWriter, r *http.Request)

PostNotificationFeedRead operation middleware

func (*ServerInterfaceWrapper) PostNotificationFeedReadAll

func (siw *ServerInterfaceWrapper) PostNotificationFeedReadAll(w http.ResponseWriter, r *http.Request)

PostNotificationFeedReadAll operation middleware

func (*ServerInterfaceWrapper) PostReportGenerate

func (siw *ServerInterfaceWrapper) PostReportGenerate(w http.ResponseWriter, r *http.Request)

PostReportGenerate operation middleware

func (*ServerInterfaceWrapper) PostRolesCreate

func (siw *ServerInterfaceWrapper) PostRolesCreate(w http.ResponseWriter, r *http.Request)

PostRolesCreate operation middleware

func (*ServerInterfaceWrapper) PostSSOProvider

func (siw *ServerInterfaceWrapper) PostSSOProvider(w http.ResponseWriter, r *http.Request)

PostSSOProvider operation middleware

func (*ServerInterfaceWrapper) PostSystemDiscoverySweep

func (siw *ServerInterfaceWrapper) PostSystemDiscoverySweep(w http.ResponseWriter, r *http.Request)

PostSystemDiscoverySweep operation middleware

func (*ServerInterfaceWrapper) PostUserDisable

func (siw *ServerInterfaceWrapper) PostUserDisable(w http.ResponseWriter, r *http.Request)

PostUserDisable operation middleware

func (*ServerInterfaceWrapper) PostUserEnable

func (siw *ServerInterfaceWrapper) PostUserEnable(w http.ResponseWriter, r *http.Request)

PostUserEnable operation middleware

func (*ServerInterfaceWrapper) PostUserResetPassword

func (siw *ServerInterfaceWrapper) PostUserResetPassword(w http.ResponseWriter, r *http.Request)

PostUserResetPassword operation middleware

func (*ServerInterfaceWrapper) PostUserRolesAssign

func (siw *ServerInterfaceWrapper) PostUserRolesAssign(w http.ResponseWriter, r *http.Request)

PostUserRolesAssign operation middleware

func (*ServerInterfaceWrapper) PostUserRolesUnassign

func (siw *ServerInterfaceWrapper) PostUserRolesUnassign(w http.ResponseWriter, r *http.Request)

PostUserRolesUnassign operation middleware

func (*ServerInterfaceWrapper) PostUsers

func (siw *ServerInterfaceWrapper) PostUsers(w http.ResponseWriter, r *http.Request)

PostUsers operation middleware

func (*ServerInterfaceWrapper) PutAuthPolicy

func (siw *ServerInterfaceWrapper) PutAuthPolicy(w http.ResponseWriter, r *http.Request)

PutAuthPolicy operation middleware

func (*ServerInterfaceWrapper) PutHostMaintenance

func (siw *ServerInterfaceWrapper) PutHostMaintenance(w http.ResponseWriter, r *http.Request)

PutHostMaintenance operation middleware

func (*ServerInterfaceWrapper) PutSSOProvider

func (siw *ServerInterfaceWrapper) PutSSOProvider(w http.ResponseWriter, r *http.Request)

PutSSOProvider operation middleware

func (*ServerInterfaceWrapper) PutSystemComplianceConfig added in v0.4.0

func (siw *ServerInterfaceWrapper) PutSystemComplianceConfig(w http.ResponseWriter, r *http.Request)

PutSystemComplianceConfig operation middleware

func (*ServerInterfaceWrapper) PutSystemConnectivityConfig

func (siw *ServerInterfaceWrapper) PutSystemConnectivityConfig(w http.ResponseWriter, r *http.Request)

PutSystemConnectivityConfig operation middleware

func (*ServerInterfaceWrapper) PutSystemDiscoveryConfig

func (siw *ServerInterfaceWrapper) PutSystemDiscoveryConfig(w http.ResponseWriter, r *http.Request)

PutSystemDiscoveryConfig operation middleware

func (*ServerInterfaceWrapper) PutSystemIntelligenceConfig

func (siw *ServerInterfaceWrapper) PutSystemIntelligenceConfig(w http.ResponseWriter, r *http.Request)

PutSystemIntelligenceConfig operation middleware

func (*ServerInterfaceWrapper) PutSystemScanConfig

func (siw *ServerInterfaceWrapper) PutSystemScanConfig(w http.ResponseWriter, r *http.Request)

PutSystemScanConfig operation middleware

func (*ServerInterfaceWrapper) PutSystemScanVariables

func (siw *ServerInterfaceWrapper) PutSystemScanVariables(w http.ResponseWriter, r *http.Request)

PutSystemScanVariables operation middleware

func (*ServerInterfaceWrapper) RejectRemediation

func (siw *ServerInterfaceWrapper) RejectRemediation(w http.ResponseWriter, r *http.Request)

RejectRemediation operation middleware

func (*ServerInterfaceWrapper) RequestRemediation

func (siw *ServerInterfaceWrapper) RequestRemediation(w http.ResponseWriter, r *http.Request)

RequestRemediation operation middleware

func (*ServerInterfaceWrapper) RollbackRemediation

func (siw *ServerInterfaceWrapper) RollbackRemediation(w http.ResponseWriter, r *http.Request)

RollbackRemediation operation middleware

func (*ServerInterfaceWrapper) TestNotificationChannel

func (siw *ServerInterfaceWrapper) TestNotificationChannel(w http.ResponseWriter, r *http.Request)

TestNotificationChannel operation middleware

func (*ServerInterfaceWrapper) UpdateReportSchedule

func (siw *ServerInterfaceWrapper) UpdateReportSchedule(w http.ResponseWriter, r *http.Request)

UpdateReportSchedule operation middleware

type ServiceUnavailable

type ServiceUnavailable = ErrorEnvelope

ServiceUnavailable defines model for ServiceUnavailable.

type TooManyValuesForParamError

type TooManyValuesForParamError struct {
	ParamName string
	Count     int
}

func (*TooManyValuesForParamError) Error

type UnescapedCookieParamError

type UnescapedCookieParamError struct {
	ParamName string
	Err       error
}

func (*UnescapedCookieParamError) Error

func (e *UnescapedCookieParamError) Error() string

func (*UnescapedCookieParamError) Unwrap

func (e *UnescapedCookieParamError) Unwrap() error

type Unimplemented

type Unimplemented struct{}

func (Unimplemented) ApproveRemediation

func (_ Unimplemented) ApproveRemediation(w http.ResponseWriter, r *http.Request, rid openapi_types.UUID)

Approve a pending remediation request (POST /api/v1/remediation/requests/{rid}:approve)

func (Unimplemented) CreateReportSchedule

func (_ Unimplemented) CreateReportSchedule(w http.ResponseWriter, r *http.Request)

Create a report delivery schedule (POST /api/v1/reports/schedules)

func (Unimplemented) DeleteAPIToken

func (_ Unimplemented) DeleteAPIToken(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Revoke an API token (DELETE /api/v1/tokens/{id})

func (Unimplemented) DeleteCredentialByID

func (_ Unimplemented) DeleteCredentialByID(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Soft-delete a credential (DELETE /api/v1/credentials/{id})

func (Unimplemented) DeleteGroup

func (_ Unimplemented) DeleteGroup(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Delete a group (DELETE /api/v1/groups/{id})

func (Unimplemented) DeleteGroupMember

func (_ Unimplemented) DeleteGroupMember(w http.ResponseWriter, r *http.Request, id openapi_types.UUID, hostId openapi_types.UUID)

Remove a host from a manual group (DELETE /api/v1/groups/{id}/members/{host_id})

func (Unimplemented) DeleteHostByID

func (_ Unimplemented) DeleteHostByID(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Soft-delete a host (DELETE /api/v1/hosts/{id})

func (Unimplemented) DeleteNotificationChannel

func (_ Unimplemented) DeleteNotificationChannel(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Delete a notification channel (DELETE /api/v1/notifications/channels/{id})

func (Unimplemented) DeleteReportSchedule

func (_ Unimplemented) DeleteReportSchedule(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Delete a report schedule (DELETE /api/v1/reports/schedules/{id})

func (Unimplemented) DeleteSSOProvider

func (_ Unimplemented) DeleteSSOProvider(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Delete an SSO provider (cascades its identities + states) (DELETE /api/v1/sso/providers/{id})

func (Unimplemented) DeleteUserByID

func (_ Unimplemented) DeleteUserByID(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Soft-delete a user (DELETE /api/v1/users/{id})

func (Unimplemented) DryRunRemediation

func (_ Unimplemented) DryRunRemediation(w http.ResponseWriter, r *http.Request, rid openapi_types.UUID)

Dry-run a remediation (preview) (POST /api/v1/remediation/requests/{rid}:dry-run)

func (Unimplemented) ExecuteRemediation

func (_ Unimplemented) ExecuteRemediation(w http.ResponseWriter, r *http.Request, rid openapi_types.UUID)

Execute an approved single-rule remediation (free core) (POST /api/v1/remediation/requests/{rid}:execute)

func (Unimplemented) GetAPITokens

func (_ Unimplemented) GetAPITokens(w http.ResponseWriter, r *http.Request)

List API tokens (metadata only; secrets never returned) (GET /api/v1/tokens)

func (Unimplemented) GetActivity

func (_ Unimplemented) GetActivity(w http.ResponseWriter, r *http.Request, params GetActivityParams)

Unified Activity feed (UNION over alerts + transactions + intelligence + audit + monitoring) (GET /api/v1/activity)

func (Unimplemented) GetAlertByID

func (_ Unimplemented) GetAlertByID(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Single alert by id (GET /api/v1/alerts/{id})

func (Unimplemented) GetAlerts

func (_ Unimplemented) GetAlerts(w http.ResponseWriter, r *http.Request, params GetAlertsParams)

List persisted alerts (paginated, filterable) (GET /api/v1/alerts)

func (Unimplemented) GetAuditEvents

func (_ Unimplemented) GetAuditEvents(w http.ResponseWriter, r *http.Request, params GetAuditEventsParams)

List audit events (cursor-paginated, newest first) (GET /api/v1/audit/events)

func (Unimplemented) GetAuditEventsExport

func (_ Unimplemented) GetAuditEventsExport(w http.ResponseWriter, r *http.Request, params GetAuditEventsExportParams)

Export the filtered audit events as a downloadable CSV or JSON file (GET /api/v1/audit/events/export)

func (Unimplemented) GetAuthMe

func (_ Unimplemented) GetAuthMe(w http.ResponseWriter, r *http.Request)

Return the calling identity (GET /api/v1/auth/me)

func (Unimplemented) GetAuthMePermissions

func (_ Unimplemented) GetAuthMePermissions(w http.ResponseWriter, r *http.Request)

Effective permissions for the calling identity (GET /api/v1/auth/me/permissions)

func (Unimplemented) GetAuthPermissionsRegistry

func (_ Unimplemented) GetAuthPermissionsRegistry(w http.ResponseWriter, r *http.Request)

Full RBAC registry (categories, permissions, built-in roles) (GET /api/v1/auth/permissions:registry)

func (Unimplemented) GetAuthPolicy

func (_ Unimplemented) GetAuthPolicy(w http.ResponseWriter, r *http.Request)

View the workspace authentication policy (GET /api/v1/auth-policy)

func (Unimplemented) GetAuthSSOCallback

func (_ Unimplemented) GetAuthSSOCallback(w http.ResponseWriter, r *http.Request, id openapi_types.UUID, params GetAuthSSOCallbackParams)

SSO redirect-back — exchanges the code, issues a session, redirects into the app (GET /api/v1/auth/sso/{id}/callback)

func (Unimplemented) GetAuthSSOLogin

Begin SSO sign-in — redirects to the IdP authorization endpoint (GET /api/v1/auth/sso/{id}/login)

func (Unimplemented) GetCapabilities added in v0.7.0

func (_ Unimplemented) GetCapabilities(w http.ResponseWriter, r *http.Request)

What this deployment is entitled to use (GET /api/v1/capabilities)

func (Unimplemented) GetComplianceExceptions

func (_ Unimplemented) GetComplianceExceptions(w http.ResponseWriter, r *http.Request, params GetComplianceExceptionsParams)

Fleet-wide compliance exception queue (GET /api/v1/compliance/exceptions)

func (Unimplemented) GetComplianceFrameworks added in v0.4.0

func (_ Unimplemented) GetComplianceFrameworks(w http.ResponseWriter, r *http.Request, params GetComplianceFrameworksParams)

List the framework families present in the scanned corpus (GET /api/v1/compliance/frameworks)

func (Unimplemented) GetCredentialByID

func (_ Unimplemented) GetCredentialByID(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Fetch a credential's metadata (GET /api/v1/credentials/{id})

func (Unimplemented) GetCredentials

func (_ Unimplemented) GetCredentials(w http.ResponseWriter, r *http.Request)

List credentials (metadata only) (GET /api/v1/credentials)

func (Unimplemented) GetFleetComplianceStates

func (_ Unimplemented) GetFleetComplianceStates(w http.ResponseWriter, r *http.Request)

Fleet host counts per compliance state (GET /api/v1/fleet/compliance/states)

func (Unimplemented) GetFleetComplianceTrend

func (_ Unimplemented) GetFleetComplianceTrend(w http.ResponseWriter, r *http.Request, params GetFleetComplianceTrendParams)

Daily fleet compliance trend (GET /api/v1/fleet/compliance/trend)

func (Unimplemented) GetFleetConnectivityBreakdown

func (_ Unimplemented) GetFleetConnectivityBreakdown(w http.ResponseWriter, r *http.Request)

4-state connectivity breakdown (online/degraded/critical/down/never_probed) (GET /api/v1/fleet/connectivity/breakdown)

func (Unimplemented) GetFleetLiveness

func (_ Unimplemented) GetFleetLiveness(w http.ResponseWriter, r *http.Request)

Host counts by reachability status (GET /api/v1/fleet/liveness)

func (Unimplemented) GetFleetRecentChanges

func (_ Unimplemented) GetFleetRecentChanges(w http.ResponseWriter, r *http.Request, params GetFleetRecentChangesParams)

Recent transactions (state changes), newest first (GET /api/v1/fleet/recent-changes)

func (Unimplemented) GetFleetScanQueue

func (_ Unimplemented) GetFleetScanQueue(w http.ResponseWriter, r *http.Request)

Scan-queue depth split by lifecycle state (GET /api/v1/fleet/scan-queue)

func (Unimplemented) GetFleetScore

func (_ Unimplemented) GetFleetScore(w http.ResponseWriter, r *http.Request, params GetFleetScoreParams)

Fleet-wide compliance score (equal-host mean) (GET /api/v1/fleet/score)

func (Unimplemented) GetFleetTopFailingHosts

func (_ Unimplemented) GetFleetTopFailingHosts(w http.ResponseWriter, r *http.Request, params GetFleetTopFailingHostsParams)

Hosts with the most failing rules (descending) (GET /api/v1/fleet/top-failing-hosts)

func (Unimplemented) GetFleetTopFailingRules

func (_ Unimplemented) GetFleetTopFailingRules(w http.ResponseWriter, r *http.Request, params GetFleetTopFailingRulesParams)

Rules with the most failing hosts (descending) (GET /api/v1/fleet/top-failing-rules)

func (Unimplemented) GetGroups

func (_ Unimplemented) GetGroups(w http.ResponseWriter, r *http.Request)

Fleet group summary + every group with its rollup (GET /api/v1/groups)

func (Unimplemented) GetHealth

func (_ Unimplemented) GetHealth(w http.ResponseWriter, r *http.Request)

Liveness + readiness probe (anonymous) (GET /api/v1/health)

func (Unimplemented) GetHostByID

Fetch a host with liveness + compliance enrichment (GET /api/v1/hosts/{id})

func (Unimplemented) GetHostCompliance

func (_ Unimplemented) GetHostCompliance(w http.ResponseWriter, r *http.Request, id openapi_types.UUID, params GetHostComplianceParams)

Per-host compliance lens (one scan, many framework views) (GET /api/v1/hosts/{id}/compliance)

func (Unimplemented) GetHostComplianceFrameworks

func (_ Unimplemented) GetHostComplianceFrameworks(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

List the frameworks the host's rule state maps to (GET /api/v1/hosts/{id}/compliance/frameworks)

func (Unimplemented) GetHostComplianceSchedule

func (_ Unimplemented) GetHostComplianceSchedule(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

One host's adaptive-scan schedule (Auto-scan tile) (GET /api/v1/hosts/{id}/compliance/schedule)

func (Unimplemented) GetHostComplianceTrend

func (_ Unimplemented) GetHostComplianceTrend(w http.ResponseWriter, r *http.Request, id openapi_types.UUID, params GetHostComplianceTrendParams)

Daily compliance posture trend for one host (GET /api/v1/hosts/{id}/compliance/trend)

func (Unimplemented) GetHostExceptions

func (_ Unimplemented) GetHostExceptions(w http.ResponseWriter, r *http.Request, id openapi_types.UUID, params GetHostExceptionsParams)

List a host's compliance exceptions (GET /api/v1/hosts/{id}/exceptions)

func (Unimplemented) GetHostFailedRules

func (_ Unimplemented) GetHostFailedRules(w http.ResponseWriter, r *http.Request, id openapi_types.UUID, params GetHostFailedRulesParams)

List a host's currently-failing compliance rules (GET /api/v1/hosts/{id}/compliance/failed-rules)

func (Unimplemented) GetHostMonitoringHistory

func (_ Unimplemented) GetHostMonitoringHistory(w http.ResponseWriter, r *http.Request, hostId openapi_types.UUID, params GetHostMonitoringHistoryParams)

Tail the host's monitoring-history rows (most recent first) (GET /api/v1/hosts/{host_id}/monitoring/history)

func (Unimplemented) GetHostSystemInfo

func (_ Unimplemented) GetHostSystemInfo(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Read the latest Discovery facts for one host (GET /api/v1/hosts/{id}/system-info)

func (Unimplemented) GetHosts

func (_ Unimplemented) GetHosts(w http.ResponseWriter, r *http.Request, params GetHostsParams)

List hosts (GET /api/v1/hosts)

func (Unimplemented) GetIntelligenceEvents

func (_ Unimplemented) GetIntelligenceEvents(w http.ResponseWriter, r *http.Request, params GetIntelligenceEventsParams)

List OS Intelligence change events (GET /api/v1/intelligence/events)

func (Unimplemented) GetIntelligenceState

func (_ Unimplemented) GetIntelligenceState(w http.ResponseWriter, r *http.Request, hostId openapi_types.UUID)

Last full Intelligence snapshot for one host (GET /api/v1/intelligence/state/{host_id})

func (Unimplemented) GetLicense

func (_ Unimplemented) GetLicense(w http.ResponseWriter, r *http.Request)

Get the current license state (tier, status, features, expiry) (GET /api/v1/license)

func (Unimplemented) GetNotificationChannel

func (_ Unimplemented) GetNotificationChannel(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Fetch a notification channel (secret redacted) (GET /api/v1/notifications/channels/{id})

func (Unimplemented) GetNotificationChannels

func (_ Unimplemented) GetNotificationChannels(w http.ResponseWriter, r *http.Request)

List notification channels (secrets redacted) (GET /api/v1/notifications/channels)

func (Unimplemented) GetNotificationFeed

func (_ Unimplemented) GetNotificationFeed(w http.ResponseWriter, r *http.Request, params GetNotificationFeedParams)

List the calling user's in-app notifications (the bell) (GET /api/v1/notifications/feed)

func (Unimplemented) GetRemediationPlan added in v0.7.1

func (_ Unimplemented) GetRemediationPlan(w http.ResponseWriter, r *http.Request, rid openapi_types.UUID)

Preview what a remediation would do, without changing the host (GET /api/v1/remediation/requests/{rid}/plan)

func (Unimplemented) GetRemediationRequest

func (_ Unimplemented) GetRemediationRequest(w http.ResponseWriter, r *http.Request, rid openapi_types.UUID)

Get a remediation request (GET /api/v1/remediation/requests/{rid})

func (Unimplemented) GetReportByID

func (_ Unimplemented) GetReportByID(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Fetch one report (with its stored JSON posture) (GET /api/v1/reports/{id})

func (Unimplemented) GetReportExport

Download a rendered face of a report (PDF, JSON, CSV, or OSCAL SAR) (GET /api/v1/reports/{id}/export)

func (Unimplemented) GetReportFrameworks

func (_ Unimplemented) GetReportFrameworks(w http.ResponseWriter, r *http.Request)

List the framework lenses available across the fleet (GET /api/v1/reports/frameworks)

func (Unimplemented) GetReportSchedules

func (_ Unimplemented) GetReportSchedules(w http.ResponseWriter, r *http.Request)

List the report delivery schedules (GET /api/v1/reports/schedules)

func (Unimplemented) GetReportSigningKey

func (_ Unimplemented) GetReportSigningKey(w http.ResponseWriter, r *http.Request)

The public key for verifying report signatures (GET /api/v1/reports/signing-key)

func (Unimplemented) GetReports

func (_ Unimplemented) GetReports(w http.ResponseWriter, r *http.Request)

List generated reports (newest first) (GET /api/v1/reports)

func (Unimplemented) GetRoles

func (_ Unimplemented) GetRoles(w http.ResponseWriter, r *http.Request)

List built-in roles (GET /api/v1/roles)

func (Unimplemented) GetRules

func (_ Unimplemented) GetRules(w http.ResponseWriter, r *http.Request)

List the Kensa rule library (the full rule catalog) (GET /api/v1/rules)

func (Unimplemented) GetSSOProvider

func (_ Unimplemented) GetSSOProvider(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

View one SSO provider (metadata only) (GET /api/v1/sso/providers/{id})

func (Unimplemented) GetSSOProviders

func (_ Unimplemented) GetSSOProviders(w http.ResponseWriter, r *http.Request)

List SSO providers (metadata only; client secret never returned) (GET /api/v1/sso/providers)

func (Unimplemented) GetSSOProvidersEnabled

func (_ Unimplemented) GetSSOProvidersEnabled(w http.ResponseWriter, r *http.Request)

List enabled SSO providers for the sign-in picker (anonymous) (GET /api/v1/sso/providers/enabled)

func (Unimplemented) GetScanByID

func (_ Unimplemented) GetScanByID(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

One scan's metadata + per-rule results (no inline evidence) (GET /api/v1/scans/{id})

func (Unimplemented) GetScanOSCAL

func (_ Unimplemented) GetScanOSCAL(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

A whole scan as an OSCAL 1.0.6 Assessment Results document (GET /api/v1/scans/{id}/oscal)

func (Unimplemented) GetScanRuleEvidence

func (_ Unimplemented) GetScanRuleEvidence(w http.ResponseWriter, r *http.Request, id openapi_types.UUID, ruleId string)

One rule's full evidence for a scan (the drill-down payload) (GET /api/v1/scans/{id}/rules/{ruleId}/evidence)

func (Unimplemented) GetScanRuleOSCAL

func (_ Unimplemented) GetScanRuleOSCAL(w http.ResponseWriter, r *http.Request, id openapi_types.UUID, ruleId string)

One rule's outcome as an OSCAL 1.0.6 Assessment Results document (GET /api/v1/scans/{id}/rules/{ruleId}/oscal)

func (Unimplemented) GetScans

func (_ Unimplemented) GetScans(w http.ResponseWriter, r *http.Request, params GetScansParams)

List a host's compliance scans (newest first) (GET /api/v1/scans)

func (Unimplemented) GetSystemComplianceConfig added in v0.4.0

func (_ Unimplemented) GetSystemComplianceConfig(w http.ResponseWriter, r *http.Request)

Read the org-wide compliance-display config (default lens) (GET /api/v1/system/compliance/config)

func (Unimplemented) GetSystemConnectivityConfig

func (_ Unimplemented) GetSystemConnectivityConfig(w http.ResponseWriter, r *http.Request)

Read the connectivity-monitor runtime config + baked-in defaults (GET /api/v1/system/connectivity/config)

func (Unimplemented) GetSystemConnectivityStatus

func (_ Unimplemented) GetSystemConnectivityStatus(w http.ResponseWriter, r *http.Request)

Read the connectivity-monitor in-process metrics + maintenance flag (GET /api/v1/system/connectivity/status)

func (Unimplemented) GetSystemDiscoveryConfig

func (_ Unimplemented) GetSystemDiscoveryConfig(w http.ResponseWriter, r *http.Request)

Read the OS discovery scheduler runtime config + baked-in defaults (GET /api/v1/system/discovery/config)

func (Unimplemented) GetSystemIntelligenceConfig

func (_ Unimplemented) GetSystemIntelligenceConfig(w http.ResponseWriter, r *http.Request)

Read the OS Intelligence scheduler runtime config + baked-in defaults (GET /api/v1/system/intelligence/config)

func (Unimplemented) GetSystemScanConfig

func (_ Unimplemented) GetSystemScanConfig(w http.ResponseWriter, r *http.Request)

Read the adaptive compliance scan scheduler config + baked-in defaults (GET /api/v1/system/scan/config)

func (Unimplemented) GetSystemScanSchedulePreview

func (_ Unimplemented) GetSystemScanSchedulePreview(w http.ResponseWriter, r *http.Request)

24h forward projection of the compliance scan schedule (GET /api/v1/system/scan/schedule-preview)

func (Unimplemented) GetSystemScanVariables

func (_ Unimplemented) GetSystemScanVariables(w http.ResponseWriter, r *http.Request)

List the corpus-used kensa rule-template variables with defaults and overrides (GET /api/v1/system/scan/variables)

func (Unimplemented) GetUserByID

func (_ Unimplemented) GetUserByID(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Fetch a user (GET /api/v1/users/{id})

func (Unimplemented) GetUsers

func (_ Unimplemented) GetUsers(w http.ResponseWriter, r *http.Request)

List users (GET /api/v1/users)

func (Unimplemented) GetUsersMePreferences

func (_ Unimplemented) GetUsersMePreferences(w http.ResponseWriter, r *http.Request)

Return the calling user's UI preferences (GET /api/v1/users/me/preferences)

func (Unimplemented) GetVersion

func (_ Unimplemented) GetVersion(w http.ResponseWriter, r *http.Request)

Build/version metadata (anonymous) (GET /api/v1/version)

func (Unimplemented) ListRemediationRequests

func (_ Unimplemented) ListRemediationRequests(w http.ResponseWriter, r *http.Request, params ListRemediationRequestsParams)

List remediation requests (fleet or filtered) (GET /api/v1/remediation/requests)

func (Unimplemented) ListRemediationSteps

func (_ Unimplemented) ListRemediationSteps(w http.ResponseWriter, r *http.Request, rid openapi_types.UUID)

List a remediation request's transaction journal (steps) (GET /api/v1/remediation/requests/{rid}/steps)

func (Unimplemented) PatchAuthMe added in v0.4.0

func (_ Unimplemented) PatchAuthMe(w http.ResponseWriter, r *http.Request)

Update the calling user's own profile (PATCH /api/v1/auth/me)

func (Unimplemented) PatchCredentialByID

func (_ Unimplemented) PatchCredentialByID(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Update a credential in place (PATCH /api/v1/credentials/{id})

func (Unimplemented) PatchGroup

Update a group's display fields (PATCH /api/v1/groups/{id})

func (Unimplemented) PatchHostByID

func (_ Unimplemented) PatchHostByID(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Update mutable host fields (PATCH /api/v1/hosts/{id})

func (Unimplemented) PatchNotificationChannel

func (_ Unimplemented) PatchNotificationChannel(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Update a notification channel (PATCH /api/v1/notifications/channels/{id})

func (Unimplemented) PatchUsersMePreferences

func (_ Unimplemented) PatchUsersMePreferences(w http.ResponseWriter, r *http.Request)

Merge a partial update into the calling user's UI preferences (PATCH /api/v1/users/me/preferences)

func (Unimplemented) PostAPIToken

func (_ Unimplemented) PostAPIToken(w http.ResponseWriter, r *http.Request)

Create an API token (the secret is returned once, here only) (POST /api/v1/tokens)

func (Unimplemented) PostAdminLicenseVerify

func (_ Unimplemented) PostAdminLicenseVerify(w http.ResponseWriter, r *http.Request)

Dry-run validate a JWT license without installing it (POST /api/v1/admin/license:verify)

func (Unimplemented) PostAdminPoliciesReload

func (_ Unimplemented) PostAdminPoliciesReload(w http.ResponseWriter, r *http.Request)

Reload signed policy files from the configured directory (POST /api/v1/admin/policies:reload)

func (Unimplemented) PostAlertAcknowledge

func (_ Unimplemented) PostAlertAcknowledge(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Acknowledge an active alert (POST /api/v1/alerts/{id}:acknowledge)

func (Unimplemented) PostAlertDismiss

func (_ Unimplemented) PostAlertDismiss(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Dismiss an alert (terminal) (POST /api/v1/alerts/{id}:dismiss)

func (Unimplemented) PostAlertResolve

func (_ Unimplemented) PostAlertResolve(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Resolve an alert (POST /api/v1/alerts/{id}:resolve)

func (Unimplemented) PostAlertSilence

func (_ Unimplemented) PostAlertSilence(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Silence an alert until a timestamp (or indefinitely) (POST /api/v1/alerts/{id}:silence)

func (Unimplemented) PostAuthLogin

func (_ Unimplemented) PostAuthLogin(w http.ResponseWriter, r *http.Request)

Username/password login with optional TOTP (POST /api/v1/auth/login)

func (Unimplemented) PostAuthLogout

func (_ Unimplemented) PostAuthLogout(w http.ResponseWriter, r *http.Request)

Revoke the calling session (POST /api/v1/auth/logout)

func (Unimplemented) PostAuthMFAEnroll

func (_ Unimplemented) PostAuthMFAEnroll(w http.ResponseWriter, r *http.Request)

Enroll the calling user in TOTP MFA (POST /api/v1/auth/mfa:enroll)

func (Unimplemented) PostAuthMFAVerify

func (_ Unimplemented) PostAuthMFAVerify(w http.ResponseWriter, r *http.Request)

Confirm an enrolled MFA secret by verifying a generated OTP (POST /api/v1/auth/mfa:verify)

func (Unimplemented) PostAuthPasswordChange

func (_ Unimplemented) PostAuthPasswordChange(w http.ResponseWriter, r *http.Request)

Change the calling user's password (POST /api/v1/auth/password:change)

func (Unimplemented) PostAuthRefresh

func (_ Unimplemented) PostAuthRefresh(w http.ResponseWriter, r *http.Request)

Rotate the refresh token; mint a new access+refresh pair (POST /api/v1/auth/refresh)

func (Unimplemented) PostAuthRefreshCookie

func (_ Unimplemented) PostAuthRefreshCookie(w http.ResponseWriter, r *http.Request)

Rotate the refresh cookie and mint a new session (browser flow) (POST /api/v1/auth/refresh-cookie)

func (Unimplemented) PostCredentialClone

func (_ Unimplemented) PostCredentialClone(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Clone a credential into a new scope (system → host or host → host) (POST /api/v1/credentials/{id}:clone)

func (Unimplemented) PostCredentials

func (_ Unimplemented) PostCredentials(w http.ResponseWriter, r *http.Request)

Create a credential (POST /api/v1/credentials)

func (Unimplemented) PostDiagnosticsEcho

func (_ Unimplemented) PostDiagnosticsEcho(w http.ResponseWriter, r *http.Request, params PostDiagnosticsEchoParams)

Echo the request message; exercises idempotency + audit (POST /api/v1/diagnostics:echo)

func (Unimplemented) PostDiagnosticsEnqueueTestJob

func (_ Unimplemented) PostDiagnosticsEnqueueTestJob(w http.ResponseWriter, r *http.Request)

Stage-0 queue demo; enqueues a no-op job processed by the in-process worker (POST /api/v1/diagnostics:enqueue-test-job)

func (Unimplemented) PostDiagnosticsEvaluateAlert

func (_ Unimplemented) PostDiagnosticsEvaluateAlert(w http.ResponseWriter, r *http.Request)

Stage-0 policy demo; evaluates the alert_thresholds policy (POST /api/v1/diagnostics:evaluate-alert)

func (Unimplemented) PostDiagnosticsPremiumEcho

func (_ Unimplemented) PostDiagnosticsPremiumEcho(w http.ResponseWriter, r *http.Request, params PostDiagnosticsPremiumEchoParams)

License-gated echo; requires premium_diagnostics feature (POST /api/v1/diagnostics:premium-echo)

func (Unimplemented) PostDiagnosticsRequireHostRead

func (_ Unimplemented) PostDiagnosticsRequireHostRead(w http.ResponseWriter, r *http.Request, params PostDiagnosticsRequireHostReadParams)

Stage-0 RBAC demo; requires host:read permission (POST /api/v1/diagnostics:require-host-read)

func (Unimplemented) PostDiagnosticsRequireHostWrite

func (_ Unimplemented) PostDiagnosticsRequireHostWrite(w http.ResponseWriter, r *http.Request, params PostDiagnosticsRequireHostWriteParams)

Stage-0 RBAC demo; requires host:write permission (POST /api/v1/diagnostics:require-host-write)

func (Unimplemented) PostDiagnosticsRequireRemediationExecute

func (_ Unimplemented) PostDiagnosticsRequireRemediationExecute(w http.ResponseWriter, r *http.Request, params PostDiagnosticsRequireRemediationExecuteParams)

Stage-0 RBAC+license demo; requires remediation:execute (RBAC) + premium_diagnostics (license) (POST /api/v1/diagnostics:require-remediation-execute)

func (Unimplemented) PostExceptionApprove

func (_ Unimplemented) PostExceptionApprove(w http.ResponseWriter, r *http.Request, xid openapi_types.UUID)

Approve a requested exception (POST /api/v1/exceptions/{xid}:approve)

func (Unimplemented) PostExceptionReject

func (_ Unimplemented) PostExceptionReject(w http.ResponseWriter, r *http.Request, xid openapi_types.UUID)

Reject a requested exception (POST /api/v1/exceptions/{xid}:reject)

func (Unimplemented) PostExceptionRevoke

func (_ Unimplemented) PostExceptionRevoke(w http.ResponseWriter, r *http.Request, xid openapi_types.UUID)

Revoke an active exception before its expiry (POST /api/v1/exceptions/{xid}:revoke)

func (Unimplemented) PostGroup

func (_ Unimplemented) PostGroup(w http.ResponseWriter, r *http.Request)

Create a group (POST /api/v1/groups)

func (Unimplemented) PostGroupMaintenance

func (_ Unimplemented) PostGroupMaintenance(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Toggle a group's maintenance flag (POST /api/v1/groups/{id}:maintenance)

func (Unimplemented) PostGroupMember

func (_ Unimplemented) PostGroupMember(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Add a host to a manual group (POST /api/v1/groups/{id}/members)

func (Unimplemented) PostGroupTarget added in v0.5.0

func (_ Unimplemented) PostGroupTarget(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Set or clear a site group's compliance target framework (POST /api/v1/groups/{id}:target)

func (Unimplemented) PostHostConnectivityCheck

func (_ Unimplemented) PostHostConnectivityCheck(w http.ResponseWriter, r *http.Request, id openapi_types.UUID, params PostHostConnectivityCheckParams)

Synchronous on-demand reachability probe for a single host (POST /api/v1/hosts/{id}/connectivity:check)

func (Unimplemented) PostHostCredentialsResolve

func (_ Unimplemented) PostHostCredentialsResolve(w http.ResponseWriter, r *http.Request, hostId openapi_types.UUID)

Resolve the credential that will be used for a host (POST /api/v1/hosts/{host_id}/credentials:resolve)

func (Unimplemented) PostHostDiscoveryRun

func (_ Unimplemented) PostHostDiscoveryRun(w http.ResponseWriter, r *http.Request, id openapi_types.UUID, params PostHostDiscoveryRunParams)

Synchronous on-demand OS fingerprint discovery for a single host (POST /api/v1/hosts/{id}/discovery:run)

func (Unimplemented) PostHostException

func (_ Unimplemented) PostHostException(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Request a compliance exception (rule waiver) on a host (POST /api/v1/hosts/{id}/exceptions)

func (Unimplemented) PostHostScan

Enqueue an on-demand compliance scan for a single host (POST /api/v1/hosts/{id}/scans)

func (Unimplemented) PostHostTarget added in v0.5.0

func (_ Unimplemented) PostHostTarget(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Set or clear a host's compliance target framework (POST /api/v1/hosts/{id}:target)

func (Unimplemented) PostHosts

func (_ Unimplemented) PostHosts(w http.ResponseWriter, r *http.Request)

Create a host (POST /api/v1/hosts)

func (Unimplemented) PostNotificationChannel

func (_ Unimplemented) PostNotificationChannel(w http.ResponseWriter, r *http.Request)

Create a notification channel (POST /api/v1/notifications/channels)

func (Unimplemented) PostNotificationFeedRead

func (_ Unimplemented) PostNotificationFeedRead(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Mark one notification read (must belong to the caller) (POST /api/v1/notifications/feed/{id}:read)

func (Unimplemented) PostNotificationFeedReadAll

func (_ Unimplemented) PostNotificationFeedReadAll(w http.ResponseWriter, r *http.Request)

Mark all the calling user's notifications read (POST /api/v1/notifications/feed:read-all)

func (Unimplemented) PostReportGenerate

func (_ Unimplemented) PostReportGenerate(w http.ResponseWriter, r *http.Request)

Generate a Fleet Compliance Executive Summary (POST /api/v1/reports:generate)

func (Unimplemented) PostRolesCreate

func (_ Unimplemented) PostRolesCreate(w http.ResponseWriter, r *http.Request)

Create a custom role (POST /api/v1/roles:create)

func (Unimplemented) PostSSOProvider

func (_ Unimplemented) PostSSOProvider(w http.ResponseWriter, r *http.Request)

Create an SSO provider (POST /api/v1/sso/providers)

func (Unimplemented) PostSystemDiscoverySweep

func (_ Unimplemented) PostSystemDiscoverySweep(w http.ResponseWriter, r *http.Request)

Enqueue a host.discovery job for every host with NULL os_discovered_at (POST /api/v1/system/discovery/sweep)

func (Unimplemented) PostUserDisable

func (_ Unimplemented) PostUserDisable(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Disable a user account (POST /api/v1/users/{id}:disable)

func (Unimplemented) PostUserEnable

func (_ Unimplemented) PostUserEnable(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Re-enable a disabled user account (POST /api/v1/users/{id}:enable)

func (Unimplemented) PostUserResetPassword

func (_ Unimplemented) PostUserResetPassword(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Admin-reset a user's password (own or another's) (POST /api/v1/users/{id}:reset-password)

func (Unimplemented) PostUserRolesAssign

func (_ Unimplemented) PostUserRolesAssign(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Assign a role to a user (POST /api/v1/users/{id}/roles:assign)

func (Unimplemented) PostUserRolesUnassign

func (_ Unimplemented) PostUserRolesUnassign(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Remove a role from a user (POST /api/v1/users/{id}/roles:unassign)

func (Unimplemented) PostUsers

func (_ Unimplemented) PostUsers(w http.ResponseWriter, r *http.Request)

Create a user (POST /api/v1/users)

func (Unimplemented) PutAuthPolicy

func (_ Unimplemented) PutAuthPolicy(w http.ResponseWriter, r *http.Request)

Replace the workspace authentication policy (PUT /api/v1/auth-policy)

func (Unimplemented) PutHostMaintenance

func (_ Unimplemented) PutHostMaintenance(w http.ResponseWriter, r *http.Request, hostId openapi_types.UUID)

Pause/resume liveness probes for a single host (PUT /api/v1/hosts/{host_id}/maintenance)

func (Unimplemented) PutSSOProvider

func (_ Unimplemented) PutSSOProvider(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Update an SSO provider (omit client_secret to keep the existing one) (PUT /api/v1/sso/providers/{id})

func (Unimplemented) PutSystemComplianceConfig added in v0.4.0

func (_ Unimplemented) PutSystemComplianceConfig(w http.ResponseWriter, r *http.Request)

Set the default compliance lens (framework family, or empty for All rules) (PUT /api/v1/system/compliance/config)

func (Unimplemented) PutSystemConnectivityConfig

func (_ Unimplemented) PutSystemConnectivityConfig(w http.ResponseWriter, r *http.Request)

Update connectivity-monitor runtime config (PUT /api/v1/system/connectivity/config)

func (Unimplemented) PutSystemDiscoveryConfig

func (_ Unimplemented) PutSystemDiscoveryConfig(w http.ResponseWriter, r *http.Request)

Update OS discovery scheduler runtime config (PUT /api/v1/system/discovery/config)

func (Unimplemented) PutSystemIntelligenceConfig

func (_ Unimplemented) PutSystemIntelligenceConfig(w http.ResponseWriter, r *http.Request)

Update OS Intelligence scheduler runtime config (PUT /api/v1/system/intelligence/config)

func (Unimplemented) PutSystemScanConfig

func (_ Unimplemented) PutSystemScanConfig(w http.ResponseWriter, r *http.Request)

Update the adaptive compliance scan scheduler config (PUT /api/v1/system/scan/config)

func (Unimplemented) PutSystemScanVariables

func (_ Unimplemented) PutSystemScanVariables(w http.ResponseWriter, r *http.Request)

Replace the operator variable overrides (PUT /api/v1/system/scan/variables)

func (Unimplemented) RejectRemediation

func (_ Unimplemented) RejectRemediation(w http.ResponseWriter, r *http.Request, rid openapi_types.UUID)

Reject a pending remediation request (POST /api/v1/remediation/requests/{rid}:reject)

func (Unimplemented) RequestRemediation

func (_ Unimplemented) RequestRemediation(w http.ResponseWriter, r *http.Request)

Request a remediation (fix) for a failing rule on a host (POST /api/v1/remediation/requests)

func (Unimplemented) RollbackRemediation

func (_ Unimplemented) RollbackRemediation(w http.ResponseWriter, r *http.Request, rid openapi_types.UUID)

Roll back an executed remediation (free core) (POST /api/v1/remediation/requests/{rid}:rollback)

func (Unimplemented) TestNotificationChannel

func (_ Unimplemented) TestNotificationChannel(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Send a synthetic test alert through the channel (POST /api/v1/notifications/channels/{id}:test)

func (Unimplemented) UpdateReportSchedule

func (_ Unimplemented) UpdateReportSchedule(w http.ResponseWriter, r *http.Request, id openapi_types.UUID)

Enable or disable a report schedule (PATCH /api/v1/reports/schedules/{id})

type UnmarshalingParamError

type UnmarshalingParamError struct {
	ParamName string
	Err       error
}

func (*UnmarshalingParamError) Error

func (e *UnmarshalingParamError) Error() string

func (*UnmarshalingParamError) Unwrap

func (e *UnmarshalingParamError) Unwrap() error

type UpdateReportScheduleJSONRequestBody

type UpdateReportScheduleJSONRequestBody = UpdateReportScheduleRequest

UpdateReportScheduleJSONRequestBody defines body for UpdateReportSchedule for application/json ContentType.

type UpdateReportScheduleRequest

type UpdateReportScheduleRequest struct {
	Enabled bool `json:"enabled"`
}

UpdateReportScheduleRequest defines model for UpdateReportScheduleRequest.

type UserCreateRequest

type UserCreateRequest struct {
	Email    string `json:"email"`
	Password string `json:"password"`
	Username string `json:"username"`
}

UserCreateRequest defines model for UserCreateRequest.

type UserPasswordResetRequest

type UserPasswordResetRequest struct {
	NewPassword string `json:"new_password"`
}

UserPasswordResetRequest defines model for UserPasswordResetRequest.

type UserPreferences

type UserPreferences struct {
	AccentColor      *UserPreferencesAccentColor      `json:"accent_color,omitempty"`
	DateFormat       *UserPreferencesDateFormat       `json:"date_format,omitempty"`
	Density          *UserPreferencesDensity          `json:"density,omitempty"`
	HostsViewDefault *UserPreferencesHostsViewDefault `json:"hosts_view_default,omitempty"`
	LandingPage      *UserPreferencesLandingPage      `json:"landing_page,omitempty"`
	ReduceMotion     *bool                            `json:"reduce_motion,omitempty"`
}

UserPreferences defines model for UserPreferences.

type UserPreferencesAccentColor

type UserPreferencesAccentColor string

UserPreferencesAccentColor defines model for UserPreferences.AccentColor.

const (
	UserPreferencesAccentColorBrand2 UserPreferencesAccentColor = "brand2"
	UserPreferencesAccentColorInfo   UserPreferencesAccentColor = "info"
	UserPreferencesAccentColorOk     UserPreferencesAccentColor = "ok"
)

Defines values for UserPreferencesAccentColor.

func (UserPreferencesAccentColor) Valid

func (e UserPreferencesAccentColor) Valid() bool

Valid indicates whether the value is a known member of the UserPreferencesAccentColor enum.

type UserPreferencesDateFormat

type UserPreferencesDateFormat string

UserPreferencesDateFormat defines model for UserPreferences.DateFormat.

const (
	Iso24  UserPreferencesDateFormat = "iso24"
	Long24 UserPreferencesDateFormat = "long24"
	Us12   UserPreferencesDateFormat = "us12"
)

Defines values for UserPreferencesDateFormat.

func (UserPreferencesDateFormat) Valid

func (e UserPreferencesDateFormat) Valid() bool

Valid indicates whether the value is a known member of the UserPreferencesDateFormat enum.

type UserPreferencesDensity

type UserPreferencesDensity string

UserPreferencesDensity defines model for UserPreferences.Density.

const (
	Comfortable UserPreferencesDensity = "comfortable"
	Compact     UserPreferencesDensity = "compact"
)

Defines values for UserPreferencesDensity.

func (UserPreferencesDensity) Valid

func (e UserPreferencesDensity) Valid() bool

Valid indicates whether the value is a known member of the UserPreferencesDensity enum.

type UserPreferencesHostsViewDefault

type UserPreferencesHostsViewDefault string

UserPreferencesHostsViewDefault defines model for UserPreferences.HostsViewDefault.

const (
	Cards UserPreferencesHostsViewDefault = "cards"
	Table UserPreferencesHostsViewDefault = "table"
)

Defines values for UserPreferencesHostsViewDefault.

func (UserPreferencesHostsViewDefault) Valid

Valid indicates whether the value is a known member of the UserPreferencesHostsViewDefault enum.

type UserPreferencesLandingPage

type UserPreferencesLandingPage string

UserPreferencesLandingPage defines model for UserPreferences.LandingPage.

const (
	Dashboard UserPreferencesLandingPage = "dashboard"
	Hosts     UserPreferencesLandingPage = "hosts"
	Reports   UserPreferencesLandingPage = "reports"
)

Defines values for UserPreferencesLandingPage.

func (UserPreferencesLandingPage) Valid

func (e UserPreferencesLandingPage) Valid() bool

Valid indicates whether the value is a known member of the UserPreferencesLandingPage enum.

type UserResponse

type UserResponse struct {
	CreatedAt *time.Time `json:"created_at,omitempty"`

	// DisabledAt Non-null when the account is disabled (cannot authenticate)
	DisabledAt           *time.Time         `json:"disabled_at,omitempty"`
	Email                string             `json:"email"`
	Id                   openapi_types.UUID `json:"id"`
	LastPasswordChangeAt *time.Time         `json:"last_password_change_at,omitempty"`

	// Roles Role IDs assigned to the user. Populated by the list endpoint (GET /users); other responses may omit it.
	Roles     *[]string  `json:"roles,omitempty"`
	UpdatedAt *time.Time `json:"updated_at,omitempty"`
	Username  string     `json:"username"`
}

UserResponse defines model for UserResponse.

type UserRoleAssignRequest

type UserRoleAssignRequest struct {
	RoleId string `json:"role_id"`
}

UserRoleAssignRequest defines model for UserRoleAssignRequest.

type UsersListResponse

type UsersListResponse struct {
	Users []UserResponse `json:"users"`
}

UsersListResponse defines model for UsersListResponse.

type VersionResponse

type VersionResponse struct {
	// BuildTime ISO-8601 build timestamp
	BuildTime string `json:"build_time"`

	// Commit Abbreviated git commit
	Commit string `json:"commit"`

	// Go Go toolchain version the binary was built with
	Go string `json:"go"`

	// Kensa Embedded Kensa engine module version (build info)
	Kensa string `json:"kensa"`

	// Openwatch OpenWatch semver (ldflags-injected)
	Openwatch string `json:"openwatch"`
}

VersionResponse defines model for VersionResponse.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL