safety

package
v1.2.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 7, 2026 License: Apache-2.0 Imports: 18 Imported by: 0

Documentation

Overview

Package safety keeps Stampede from being pointed at systems the user does not own: target classification, ownership verification, load caps and a per-request host policy.

Index

Constants

View Source
const TXTPrefix = "stampede-verify="

TXTPrefix starts the DNS TXT verification record.

View Source
const WellKnownPath = "/.well-known/stampede-verify.txt"

WellKnownPath is where a verification token can be served.

Variables

View Source
var UnverifiedPublicCaps = Caps{MaxRate: 50, MaxVUs: 50, MaxDuration: 10 * time.Minute}

UnverifiedPublicCaps apply to public targets whose ownership has not been verified.

Functions

func CheckPlan

func CheckPlan(p *scenario.Plan, c Caps) error

CheckPlan returns an error describing every cap the plan exceeds.

func InstallSecret

func InstallSecret() ([]byte, error)

InstallSecret returns this machine's verification secret, creating it on first use under the user config directory.

func IsPrivateAddr

func IsPrivateAddr(a netip.Addr) bool

IsPrivateAddr reports whether an address is loopback, private, link-local or unique-local.

func IsPrivateHost

func IsPrivateHost(ctx context.Context, host string) (bool, error)

IsPrivateHost resolves host and reports whether every address it maps to is private. "localhost" and names under .localhost, .local, .internal and .test count as private without a lookup only if they resolve privately.

func Token

func Token(secret []byte, host string) string

Token derives the verification token for a host from a per-install secret, so the same machine always asks for the same token.

func Verify

func Verify(ctx context.Context, base *url.URL, token string) (string, error)

Verify checks DNS TXT records on the host (and on _stampede.<host>) and the well-known file for the token. It returns the method that succeeded.

Types

type Caps

type Caps struct {
	MaxRate     float64       // iterations per second (rate mode)
	MaxVUs      int           // virtual users
	MaxDuration time.Duration // planned load duration
}

Caps bound the load a run may generate.

type HostPolicy

type HostPolicy struct {
	// contains filtered or unexported fields
}

HostPolicy decides which hosts requests may reach. The target host and private hosts are allowed; any other public host must be listed explicitly. This stops a scenario from sending load to third parties.

func NewHostPolicy

func NewHostPolicy(targetHost string, extra []string) *HostPolicy

NewHostPolicy allows the target host plus extra hosts.

func (*HostPolicy) Allow

func (p *HostPolicy) Allow(u *url.URL) bool

Allow reports whether a request to u is permitted.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL