server

package
v0.7.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 20, 2026 License: MIT Imports: 40 Imported by: 0

Documentation

Index

Constants

View Source
const (
	// HandFree means no connection may write to the session's terminal.
	HandFree = "free"
	// HandHeld means exactly one connection may write to it.
	HandHeld = "held"
	// HandRequested means the hand is held and another operator has asked for it.
	HandRequested = "requested"
)

Variables

View Source
var (
	// ErrHandHeld is returned instead of silently stealing the terminal from
	// another operator. The caller is expected to request control.
	ErrHandHeld = errors.New("another operator holds the terminal")
	// ErrNotHolder is returned to a connection that tried to write to, resize,
	// or release a terminal it does not hold.
	ErrNotHolder = errors.New("this connection does not hold the terminal")
	// ErrNoPendingRequest is returned when granting or declining a request that
	// has already expired, been withdrawn, or never existed.
	ErrNoPendingRequest = errors.New("no pending control request")
	// ErrTooManyObservers is returned once a session roster is full.
	ErrTooManyObservers = errors.New("observer limit reached")
	// ErrForceDisabled is returned when force takeover is requested but the
	// deployment has not opted into it.
	ErrForceDisabled = errors.New("force takeover is disabled")
	// ErrUnknownConnection is returned for a connID the registrar never saw, or
	// that disconnected between a roster read and this call.
	ErrUnknownConnection = errors.New("unknown connection")
	// ErrViewerRole is returned when a read-only connection attempts to take or
	// request the hand. The RPC dispatcher rejects viewers first; this is the
	// second, authoritative gate.
	ErrViewerRole = errors.New("permission denied: viewer role is read-only")
)
View Source
var DistAssets embed.FS

DistAssets embeds the production single-page application bundle. If empty (e.g. in test environments), the server provides a helpful fallback.

Functions

func DefaultConfigPath

func DefaultConfigPath() (string, error)

DefaultConfigPath resolves the default config file location.

func RunServe

func RunServe(arguments []string, _ io.Writer, diagnostics io.Writer) error

RunServe parses arguments and launches the Relayer Web Gateway.

func Serve

func Serve(ctx context.Context, opts Options) error

Serve initializes and runs the Relayer Web Gateway until context cancellation.

func StaticFileSystem

func StaticFileSystem() http.FileSystem

StaticFileSystem returns an http.FileSystem rooted at the embedded dist directory, stripping the "dist" prefix so that index.html is served at the root.

Types

type AgentCatalogEntry

type AgentCatalogEntry struct {
	ID                 string   `json:"id"`
	Name               string   `json:"name"`
	Description        string   `json:"description"`
	InstallStatus      string   `json:"installStatus"`
	Installed          bool     `json:"installed"`
	Adapter            string   `json:"adapter"`
	AdapterStatus      string   `json:"adapterStatus"`
	DefaultArgv        []string `json:"defaultArgv"`
	RequiresCustomArgv bool     `json:"requiresCustomArgv"`
	MinimumArguments   int      `json:"minimumArguments"`
	ArgumentPrefix     []string `json:"argumentPrefix"`
}

type AgentProfile

type AgentProfile struct {
	ID              string   `json:"id"`
	Name            string   `json:"name"`
	PresetID        string   `json:"presetID"`
	Cwd             string   `json:"cwd"`
	Backend         string   `json:"backend"`
	Adapter         string   `json:"adapter"`
	Argv            []string `json:"argv,omitempty"`
	ExecutableLabel string   `json:"executableLabel"`
	ArgumentCount   int      `json:"argumentCount"`
	Locked          bool     `json:"locked"`
	ReadOnlyReason  string   `json:"readOnlyReason,omitempty"`
	PreserveOnSave  bool     `json:"preserveOnSave"`
}

type AgentProfileInput

type AgentProfileInput struct {
	ID             string   `json:"id"`
	Name           string   `json:"name"`
	PresetID       string   `json:"presetID,omitempty"`
	Cwd            string   `json:"cwd,omitempty"`
	Backend        string   `json:"backend,omitempty"`
	Adapter        string   `json:"adapter,omitempty"`
	Argv           []string `json:"argv,omitempty"`
	PreserveOnSave bool     `json:"preserveOnSave,omitempty"`
}

type AgentProfilesView

type AgentProfilesView struct {
	ConfigPath      string              `json:"configPath"`
	Revision        string              `json:"revision"`
	Catalog         []AgentCatalogEntry `json:"catalog"`
	Profiles        []AgentProfile      `json:"profiles"`
	MinProfiles     int                 `json:"minProfiles"`
	MaxProfiles     int                 `json:"maxProfiles"`
	RestartRequired bool                `json:"restartRequired"`
	Editable        bool                `json:"editable"`
	ReadOnlyReason  string              `json:"readOnlyReason,omitempty"`
}

type AgentState

type AgentState struct {
	SessionID      string `json:"sessionID"`
	AgentID        string `json:"agentID"`
	Name           string `json:"name"`
	DisplayCommand string `json:"displayCommand"`
	Backend        string `json:"backend"`
	Adapter        string `json:"adapter"`
	Status         string `json:"status"`
	Output         string `json:"output"`
	Revision       uint64 `json:"revision"`
	Running        bool   `json:"running"`
	Attached       bool   `json:"attached"`
	ObserverCount  int    `json:"observerCount"`
	HolderIdentity string `json:"holderIdentity,omitempty"`
	InputFrozen    bool   `json:"inputFrozen"`
	Simulated      bool   `json:"simulated"`
	ExitCode       *int   `json:"exitCode,omitempty"`
}

type AppState

type AppState struct {
	RunID         string             `json:"runID"`
	RunStatus     string             `json:"runStatus"`
	StartedAt     string             `json:"startedAt,omitempty"`
	Policy        PolicyState        `json:"policy"`
	Audit         AuditState         `json:"audit"`
	Agents        []AgentState       `json:"agents"`
	PendingEvents []SupervisionEvent `json:"pendingEvents"`
	Notices       []string           `json:"notices"`
}

type AuditEntryView

type AuditEntryView struct {
	Sequence   uint64            `json:"sequence"`
	Timestamp  string            `json:"timestamp"`
	EntryID    string            `json:"entryID"`
	RunID      string            `json:"runID"`
	Kind       string            `json:"kind"`
	SessionID  string            `json:"sessionID,omitempty"`
	AgentID    string            `json:"agentID,omitempty"`
	Backend    string            `json:"backend,omitempty"`
	Adapter    string            `json:"adapter,omitempty"`
	EventType  string            `json:"eventType,omitempty"`
	Risk       string            `json:"risk,omitempty"`
	Rule       string            `json:"rule,omitempty"`
	Decision   string            `json:"decision,omitempty"`
	DecisionBy string            `json:"decisionBy,omitempty"`
	Operator   string            `json:"operator,omitempty"`
	Outcome    string            `json:"outcome,omitempty"`
	Reason     string            `json:"reason,omitempty"`
	Summary    string            `json:"summary,omitempty"`
	Sensitive  bool              `json:"sensitive"`
	Metadata   map[string]string `json:"metadata,omitempty"`
}

type AuditFilterInput

type AuditFilterInput struct {
	AgentID   string `json:"agentID,omitempty"`
	SessionID string `json:"sessionID,omitempty"`
	RunID     string `json:"runID,omitempty"`
	Kind      string `json:"kind,omitempty"`
	Limit     int    `json:"limit,omitempty"`
}

type AuditState

type AuditState struct {
	Enabled bool   `json:"enabled"`
	Mode    string `json:"mode"`
	Status  string `json:"status"`
	Path    string `json:"path,omitempty"`
}

type AuditSummaryView

type AuditSummaryView struct {
	Path           string         `json:"path"`
	TotalEntries   int            `json:"totalEntries"`
	RunsCount      int            `json:"runsCount"`
	SessionsCount  int            `json:"sessionsCount"`
	AgentCounts    map[string]int `json:"agentCounts"`
	KindCounts     map[string]int `json:"kindCounts"`
	DecisionsCount map[string]int `json:"decisionsCount"`
	ActorsCount    map[string]int `json:"actorsCount"`
	OutcomesCount  map[string]int `json:"outcomesCount"`
	SensitiveCount int            `json:"sensitiveCount"`
	FirstTimestamp string         `json:"firstTimestamp,omitempty"`
	LastTimestamp  string         `json:"lastTimestamp,omitempty"`
}

type AuditVerificationIssueView

type AuditVerificationIssueView struct {
	Line    int    `json:"line"`
	EntryID string `json:"entryID,omitempty"`
	Message string `json:"message"`
}

type AuditVerificationView

type AuditVerificationView struct {
	Path       string                       `json:"path"`
	TotalLines int                          `json:"totalLines"`
	TotalRuns  int                          `json:"totalRuns"`
	ValidLines int                          `json:"validLines"`
	Issues     []AuditVerificationIssueView `json:"issues"`
	Passed     bool                         `json:"passed"`
}

type AuthIdentity added in v0.6.0

type AuthIdentity struct {
	Identity string
	Role     UserRole
}

type Controller

type Controller struct {
	// contains filtered or unexported fields
}

Controller owns the headless supervisor runtime and provides thread-safe query and mutation methods mirroring the RelayerBridge interface.

func NewController

func NewController(configPath string, diagnostics io.Writer) (*Controller, error)

NewController creates an unstarted supervisor controller.

func (*Controller) Close

func (c *Controller) Close(ctx context.Context) error

Close gracefully stops the running supervisor and all agent processes.

func (*Controller) DeclineControl added in v0.7.0

func (c *Controller) DeclineControl(sessionID, connID, operator, toConnID string) (HandView, error)

DeclineControl refuses a pending request and leaves the hand where it is.

func (*Controller) DeleteRecording added in v0.7.0

func (c *Controller) DeleteRecording(id, operator string) error

DeleteRecording permanently removes a transcript. A recording still being written is refused by the store rather than deleted underneath its writer.

func (*Controller) ExportAuditReport

func (c *Controller) ExportAuditReport(format string) (string, error)

func (*Controller) ExportRecording added in v0.7.0

func (c *Controller) ExportRecording(id, operator string) (string, error)

ExportRecording returns a whole transcript as asciicast v2 text. Exporting is audited: it is the moment a transcript leaves the supervising host.

func (*Controller) ForceTakeControl added in v0.7.0

func (c *Controller) ForceTakeControl(sessionID, connID, operator string) (HandView, error)

ForceTakeControl seizes a held hand without the holder's consent. It is off by default: an operator typing into an agent's terminal can be interrupted mid-command, so the deployment must opt in.

func (*Controller) GetAgentProfiles

func (c *Controller) GetAgentProfiles() (AgentProfilesView, error)

func (*Controller) GetAuditEntries

func (c *Controller) GetAuditEntries(filter AuditFilterInput) ([]AuditEntryView, error)

func (*Controller) GetAuditSummary

func (c *Controller) GetAuditSummary() (AuditSummaryView, error)

func (*Controller) GetFullSettings

func (c *Controller) GetFullSettings() (FullSettingsView, error)

func (*Controller) GetRecording added in v0.7.0

func (c *Controller) GetRecording(id string) (RecordingView, error)

GetRecording returns one transcript's metadata.

func (*Controller) GetState

func (c *Controller) GetState() AppState

func (*Controller) GetTelemetrySnapshot

func (c *Controller) GetTelemetrySnapshot() TelemetrySnapshotView

func (*Controller) GrantControl added in v0.7.0

func (c *Controller) GrantControl(sessionID, connID, operator, toConnID string) (HandView, error)

GrantControl transfers the hand to a pending requester. Only the current holder may grant.

func (*Controller) HandFor added in v0.7.0

func (c *Controller) HandFor(sessionID string) HandView

HandFor returns the current write-lock snapshot for one session.

func (*Controller) HoldsHand added in v0.7.0

func (c *Controller) HoldsHand(sessionID, connID string) bool

HoldsHand reports whether a connection may currently write to a session. A session nobody has claimed is writable by any operator, which preserves the single-operator behavior of deployments that never use sharing.

func (*Controller) ListPresence added in v0.7.0

func (c *Controller) ListPresence(sessionID string) (PresenceView, error)

ListPresence returns the roster of one session without mutating anything.

func (*Controller) ListRecordings added in v0.7.0

func (c *Controller) ListRecordings(filter RecordingFilterInput) ([]RecordingView, error)

ListRecordings returns the stored transcripts, newest first.

func (*Controller) ObserveSession added in v0.7.0

func (c *Controller) ObserveSession(connID, sessionID string, observing bool) (PresenceView, error)

ObserveSession adds a connection to one session's roster. Observing is a read-only act: viewers may observe, and observing never implies the hand.

func (*Controller) ReadRecordingChunk added in v0.7.0

func (c *Controller) ReadRecordingChunk(id string, offset, limit int) (RecordingChunk, error)

ReadRecordingChunk returns one page of frames plus the header. A recording still being written is readable: the operator watching a session live is the one most likely to want the replay.

func (*Controller) RegisterPresence added in v0.7.0

func (c *Controller) RegisterPresence(connID, identity, role string)

RegisterPresence records a newly authenticated connection. It is called by the gateway immediately after the websocket is registered.

func (*Controller) ReleaseControl added in v0.7.0

func (c *Controller) ReleaseControl(sessionID, connID, operator string) (HandView, error)

ReleaseControl frees a hand held by this connection.

func (*Controller) ReleasePresence added in v0.7.0

func (c *Controller) ReleasePresence(connID string)

ReleasePresence removes a disconnected connection and frees any hand it held. The gateway must call this after releasing its own client lock: broadcasting while the gateway holds that lock deadlocks against the broadcast listener.

func (*Controller) RequestControl added in v0.7.0

func (c *Controller) RequestControl(sessionID, connID, operator string) (HandView, error)

RequestControl asks the current holder to hand over. A second request from the same connection refreshes the deadline rather than erroring, so a UI that retries is not punished.

func (*Controller) ResizeSession

func (c *Controller) ResizeSession(runID, sessionID string, columns, rows int, connID string) error

ResizeSession applies a terminal geometry change requested by the connection holding the hand. A resize from anyone else is a silent no-op: two observers with different window sizes must not fight over the PTY geometry and thrash the agent's rendering.

func (*Controller) RestartSession

func (c *Controller) RestartSession(runID, sessionID string) error

func (*Controller) RunPreflight

func (c *Controller) RunPreflight(ctx context.Context) (PreflightReport, error)

func (*Controller) SaveAgentProfiles

func (c *Controller) SaveAgentProfiles(runID string, req SaveAgentProfilesRequest) (AgentProfilesView, error)

func (*Controller) SaveAgentProfilesAndRestart

func (c *Controller) SaveAgentProfilesAndRestart(req SaveAgentProfilesAndRestartRequest) (LifecycleResult, error)

func (*Controller) SaveFullSettings

func (c *Controller) SaveFullSettings(runID string, req SaveFullSettingsRequest) (FullSettingsView, error)

func (*Controller) SendTerminalInput added in v0.6.0

func (c *Controller) SendTerminalInput(runID, sessionID string, data []byte, operator, connID string) error

SendTerminalInput delivers raw terminal input bytes directly to the session backend. Used by the web interactive terminal (full PTY mode) to stream keystrokes and signals.

The hand is checked before the write. The check and the write cannot share a single lock acquisition without holding c.mu across five seconds of I/O, so at most one already-in-flight keystroke may land just after a release. That window is documented in docs/sharing.md rather than papered over.

func (*Controller) SetInteractiveSession added in v0.6.0

func (c *Controller) SetInteractiveSession(runID, sessionID string, active bool, operator, connID string) error

SetInteractiveSession acquires or releases the session's write lock. It is the attach verb: taking the hand is what makes keystrokes routable.

Taking a hand another operator holds is refused rather than silently stolen; the caller is expected to request control instead.

func (*Controller) Start

func (c *Controller) Start(ctx context.Context) error

Start boots the supervisor runtime and begins event processing.

func (*Controller) StartSession

func (c *Controller) StartSession(runID, sessionID string) error

func (*Controller) StopRun

func (c *Controller) StopRun(runID string) (AppState, error)

func (*Controller) StopSession

func (c *Controller) StopSession(runID, sessionID string) error

func (*Controller) SubmitAutomaticDecision

func (c *Controller) SubmitAutomaticDecision(runID, sessionID, eventID, decision string) error

func (*Controller) SubmitDecision

func (c *Controller) SubmitDecision(runID, sessionID, eventID, value string) error

func (*Controller) SubmitDecisionWithOperator added in v0.6.0

func (c *Controller) SubmitDecisionWithOperator(runID, sessionID, eventID, value, operator string) error

func (*Controller) SubmitLine

func (c *Controller) SubmitLine(runID, sessionID, line string) error

func (*Controller) SubmitLineWithOperator added in v0.6.0

func (c *Controller) SubmitLineWithOperator(runID, sessionID, line, operator string) error

func (*Controller) Subscribe

func (c *Controller) Subscribe(listener func(event string, payload any)) func()

Subscribe registers an event listener called on each broadcast. Returns an unsubscribe function.

func (*Controller) TakeControl added in v0.7.0

func (c *Controller) TakeControl(sessionID, connID, operator string) (HandView, error)

TakeControl acquires a free hand. It deliberately refuses to steal a held one: the caller is told to request control instead.

func (*Controller) TestNotification

func (c *Controller) TestNotification() error

func (*Controller) VerifyAuditJournal

func (c *Controller) VerifyAuditJournal() (AuditVerificationView, error)

type DecisionBreakdown

type DecisionBreakdown struct {
	Allow     int64 `json:"allow"`
	Deny      int64 `json:"deny"`
	AutoAllow int64 `json:"autoAllow"`
	AutoDeny  int64 `json:"autoDeny"`
	Custom    int64 `json:"custom"`
}

type FullSettingsView

type FullSettingsView struct {
	AgentProfilesView
	Security      SecuritySettings     `json:"security"`
	Notifications NotificationSettings `json:"notifications"`
}

type HandView added in v0.7.0

type HandView struct {
	RunID             string `json:"runID"`
	SessionID         string `json:"sessionID"`
	State             string `json:"state"`
	HolderConnID      string `json:"holderConnID,omitempty"`
	HolderIdentity    string `json:"holderIdentity,omitempty"`
	RequesterConnID   string `json:"requesterConnID,omitempty"`
	RequesterIdentity string `json:"requesterIdentity,omitempty"`
	RequestExpiresAt  string `json:"requestExpiresAt,omitempty"`
	Since             string `json:"since,omitempty"`
}

HandView is a complete snapshot of one session's write lock.

type LatencyBucketView

type LatencyBucketView struct {
	Le    float64 `json:"le"`
	Label string  `json:"label"`
	Count uint64  `json:"count"`
}

type LifecycleResult

type LifecycleResult struct {
	Outcome  string            `json:"outcome"`
	State    AppState          `json:"state"`
	Profiles AgentProfilesView `json:"profiles"`
}

type NotificationEvent

type NotificationEvent struct {
	Title     string `json:"title"`
	Body      string `json:"body"`
	AgentName string `json:"agentName,omitempty"`
	SessionID string `json:"sessionID,omitempty"`
	EventID   string `json:"eventID,omitempty"`
	Kind      string `json:"kind"`
	Severity  string `json:"severity"`
	Reason    string `json:"reason,omitempty"`
	Timestamp string `json:"timestamp"`
}

NotificationEvent is broadcast to WebSocket clients when an operator alert fires.

type NotificationSettings

type NotificationSettings struct {
	Enabled     bool                         `json:"enabled"`
	Bell        bool                         `json:"bell"`
	Desktop     bool                         `json:"desktop"`
	MinSeverity string                       `json:"minSeverity"`
	Webhooks    []NotificationWebhookSetting `json:"webhooks"`
}

type NotificationWebhookSetting

type NotificationWebhookSetting struct {
	Name        string `json:"name"`
	URL         string `json:"url"`
	Format      string `json:"format"`
	MinSeverity string `json:"minSeverity"`
	Timeout     string `json:"timeout"`
}

type Options

type Options struct {
	Bind        string
	Port        int
	Token       string
	ViewerToken string
	ConfigPath  string
	StaticDir   string
	Diagnostics io.Writer
	OnReady     func(serverURL string, token string)
}

Options configures the headless Relayer web server.

type PolicyEvaluation

type PolicyEvaluation struct {
	Action         string `json:"action"`
	ProposedAction string `json:"proposedAction"`
	RuleName       string `json:"ruleName,omitempty"`
	Reason         string `json:"reason"`
	Automatic      bool   `json:"automatic"`
	DryRun         bool   `json:"dryRun"`
}

type PolicyState

type PolicyState struct {
	DefaultAction string `json:"defaultAction"`
	DryRun        bool   `json:"dryRun"`
}

type PreflightAgent

type PreflightAgent struct {
	Ordinal         int    `json:"ordinal"`
	Source          string `json:"source"`
	Command         string `json:"command"`
	Installation    string `json:"installation"`
	Adapter         string `json:"adapter,omitempty"`
	AdapterMaturity string `json:"adapterMaturity,omitempty"`
	Backend         string `json:"backend,omitempty"`
}

type PreflightAudit

type PreflightAudit struct {
	Enabled       bool   `json:"enabled"`
	Mode          string `json:"mode"`
	Location      string `json:"location"`
	MaxFileSizeMB int    `json:"maxFileSizeMB"`
	MaxFiles      int    `json:"maxFiles"`
}

type PreflightCheck

type PreflightCheck struct {
	ID          string `json:"id"`
	Scope       string `json:"scope"`
	Status      string `json:"status"`
	Summary     string `json:"summary"`
	Remediation string `json:"remediation,omitempty"`
}

type PreflightConfiguration

type PreflightConfiguration struct {
	Version         int  `json:"version"`
	Legacy          bool `json:"legacy"`
	AgentCount      int  `json:"agentCount"`
	PolicyRuleCount int  `json:"policyRuleCount"`
}

type PreflightPlatform

type PreflightPlatform struct {
	OS        string `json:"os"`
	Arch      string `json:"arch"`
	Supported bool   `json:"supported"`
}

type PreflightReport

type PreflightReport struct {
	SchemaVersion int                    `json:"schemaVersion"`
	Status        string                 `json:"status"`
	Platform      PreflightPlatform      `json:"platform"`
	Configuration PreflightConfiguration `json:"configuration"`
	Audit         PreflightAudit         `json:"audit"`
	Tools         []PreflightTool        `json:"tools"`
	Agents        []PreflightAgent       `json:"agents"`
	Checks        []PreflightCheck       `json:"checks"`
}

type PreflightTool

type PreflightTool struct {
	ProfileID    string `json:"profileID"`
	Installation string `json:"installation"`
}

type PresenceMember added in v0.7.0

type PresenceMember struct {
	ConnID         string `json:"connID"`
	Identity       string `json:"identity"`
	Role           string `json:"role"`
	Observing      bool   `json:"observing"`
	HoldsHand      bool   `json:"holdsHand"`
	RequestingHand bool   `json:"requestingHand"`
	Since          string `json:"since"`
}

PresenceMember is one connected client as the other clients of a session see it. Identity is not unique: the same operator may hold several connections, so ConnID is the addressable key everywhere the hand is concerned.

type PresenceView added in v0.7.0

type PresenceView struct {
	RunID         string           `json:"runID"`
	SessionID     string           `json:"sessionID"`
	Members       []PresenceMember `json:"members"`
	ObserverCount int              `json:"observerCount"`
}

PresenceView is a complete roster snapshot for one session. It is never a delta: a dropped broadcast must be self-healing at the next one.

type RecordingChunk added in v0.7.0

type RecordingChunk struct {
	ID         string               `json:"id"`
	Header     RecordingHeaderView  `json:"header"`
	Frames     []RecordingFrameView `json:"frames"`
	Offset     int                  `json:"offset"`
	NextOffset int                  `json:"nextOffset"`
	Complete   bool                 `json:"complete"`
}

RecordingChunk is one page of a transcript. Transcripts are paged rather than returned whole because a websocket frame large enough for a multi-megabyte cast would be dropped by the send queue instead of delivered.

type RecordingEvent added in v0.7.0

type RecordingEvent struct {
	Action    string        `json:"action"`
	Recording RecordingView `json:"recording"`
}

type RecordingFilterInput added in v0.7.0

type RecordingFilterInput struct {
	RunID     string `json:"runID,omitempty"`
	SessionID string `json:"sessionID,omitempty"`
	AgentID   string `json:"agentID,omitempty"`
	Limit     int    `json:"limit,omitempty"`
}

type RecordingFrameView added in v0.7.0

type RecordingFrameView struct {
	Time float64 `json:"time"`
	Kind string  `json:"kind"`
	Data string  `json:"data"`
}

type RecordingHeaderView added in v0.7.0

type RecordingHeaderView struct {
	Version   int    `json:"version"`
	Width     int    `json:"width"`
	Height    int    `json:"height"`
	Timestamp int64  `json:"timestamp,omitempty"`
	Title     string `json:"title,omitempty"`
}

type RecordingView added in v0.7.0

type RecordingView struct {
	ID              string  `json:"id"`
	RunID           string  `json:"runID"`
	SessionID       string  `json:"sessionID"`
	AgentID         string  `json:"agentID,omitempty"`
	Name            string  `json:"name,omitempty"`
	Backend         string  `json:"backend,omitempty"`
	Adapter         string  `json:"adapter,omitempty"`
	StartedAt       string  `json:"startedAt"`
	EndedAt         string  `json:"endedAt,omitempty"`
	DurationSeconds float64 `json:"durationSeconds"`
	Width           int     `json:"width"`
	Height          int     `json:"height"`
	Bytes           int64   `json:"bytes"`
	Frames          int     `json:"frames"`
	Truncated       bool    `json:"truncated"`
	DroppedFrames   int     `json:"droppedFrames"`
	InputRecorded   bool    `json:"inputRecorded"`
	Redacted        bool    `json:"redacted"`
	ExitCode        *int    `json:"exitCode,omitempty"`
	Active          bool    `json:"active"`
}

RecordingView is one session transcript as the web UI lists it. It carries no filesystem path: the store is addressed by id, and a path would tell a browser client where the supervising host keeps its files.

type SafeErrorEvent

type SafeErrorEvent struct {
	RunID     string `json:"runID"`
	Code      string `json:"code"`
	Message   string `json:"message"`
	SessionID string `json:"sessionID,omitempty"`
	Timestamp string `json:"timestamp"`
}

type SaveAgentProfilesAndRestartRequest

type SaveAgentProfilesAndRestartRequest struct {
	ExpectedRunID    string              `json:"expectedRunID,omitempty"`
	ExpectedRevision string              `json:"expectedRevision"`
	Profiles         []AgentProfileInput `json:"profiles"`
}

type SaveAgentProfilesRequest

type SaveAgentProfilesRequest struct {
	ExpectedRevision string              `json:"expectedRevision"`
	Profiles         []AgentProfileInput `json:"profiles"`
}

type SaveFullSettingsRequest

type SaveFullSettingsRequest struct {
	ExpectedRevision string                `json:"expectedRevision"`
	Profiles         []AgentProfileInput   `json:"profiles,omitempty"`
	Security         *SecuritySettings     `json:"security,omitempty"`
	Notifications    *NotificationSettings `json:"notifications,omitempty"`
}

type SecuritySettings

type SecuritySettings struct {
	Profile                     string `json:"profile"`
	DefaultAction               string `json:"defaultAction"`
	DryRun                      bool   `json:"dryRun"`
	BlockDestructive            bool   `json:"blockDestructive"`
	BlockExfiltration           bool   `json:"blockExfiltration"`
	BlockSensitivePaths         bool   `json:"blockSensitivePaths"`
	BlockOutsideWorkspace       bool   `json:"blockOutsideWorkspace"`
	WorkspaceRoot               string `json:"workspaceRoot"`
	RateLimitPerMinute          int    `json:"rateLimitPerMinute"`
	MaxConsecutiveAutoDecisions int    `json:"maxConsecutiveAutoDecisions"`
}

type SnapshotEvent

type SnapshotEvent struct {
	RunID          string `json:"runID"`
	SessionID      string `json:"sessionID"`
	Revision       uint64 `json:"revision"`
	Output         string `json:"output"`
	Status         string `json:"status"`
	Running        bool   `json:"running"`
	Attached       bool   `json:"attached"`
	ObserverCount  int    `json:"observerCount"`
	HolderIdentity string `json:"holderIdentity,omitempty"`
	InputFrozen    bool   `json:"inputFrozen"`
	ExitCode       *int   `json:"exitCode,omitempty"`
}

type StatusEvent

type StatusEvent struct {
	RunID     string `json:"runID"`
	Scope     string `json:"scope"`
	Status    string `json:"status"`
	SessionID string `json:"sessionID,omitempty"`
}

type SupervisionEvent

type SupervisionEvent struct {
	RunID          string           `json:"runID"`
	ID             string           `json:"id"`
	SessionID      string           `json:"sessionID"`
	AgentID        string           `json:"agentID"`
	Adapter        string           `json:"adapter"`
	Type           string           `json:"type"`
	Summary        string           `json:"summary"`
	Sensitive      bool             `json:"sensitive"`
	Risk           string           `json:"risk"`
	Timestamp      string           `json:"timestamp"`
	Evaluation     PolicyEvaluation `json:"evaluation"`
	DeliveryStatus string           `json:"deliveryStatus"`
	Decisions      []string         `json:"decisions"`
}

type TelemetrySnapshotView

type TelemetrySnapshotView struct {
	Timestamp            string              `json:"timestamp"`
	Enabled              bool                `json:"enabled"`
	PrometheusEnabled    bool                `json:"prometheusEnabled"`
	PrometheusAddress    string              `json:"prometheusAddress,omitempty"`
	OTLPEnabled          bool                `json:"otlpEnabled"`
	OTLPEndpoint         string              `json:"otlpEndpoint,omitempty"`
	SessionsActive       int64               `json:"sessionsActive"`
	EventsPending        int64               `json:"eventsPending"`
	SessionsTotal        int64               `json:"sessionsTotal"`
	EventsDetectedTotal  int64               `json:"eventsDetectedTotal"`
	EventsWithdrawnTotal int64               `json:"eventsWithdrawnTotal"`
	DecisionsTotal       int64               `json:"decisionsTotal"`
	DecisionsBreakdown   DecisionBreakdown   `json:"decisionsBreakdown"`
	OperatorInputsTotal  int64               `json:"operatorInputsTotal"`
	GuardrailsTotal      int64               `json:"guardrailsTotal"`
	GuardrailsBreakdown  map[string]int64    `json:"guardrailsBreakdown"`
	AverageReactionTime  float64             `json:"averageReactionTime"`
	DecisionDurations    []LatencyBucketView `json:"decisionDurations"`
}

type UserInfo added in v0.6.0

type UserInfo struct {
	Identity string `json:"identity"`
	ConnID   string `json:"connID"`
	Role     string `json:"role"`
	ReadOnly bool   `json:"readOnly"`
}

type UserRole added in v0.6.0

type UserRole string

UserRole defines the privilege level of an authenticated client.

const (
	RoleOperator UserRole = "operator"
	RoleViewer   UserRole = "viewer"
)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL