fleet/

directory
v0.2.3 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 27, 2026 License: Apache-2.0

Directories

Path Synopsis
Package baselineuc is the Phase D behavioral-baseline usecase (#594, D5 #738): it drives the pure-domain baseline lifecycle over a persistent store and produces the coverage-honest RiskContext.Behavior factor.
Package baselineuc is the Phase D behavioral-baseline usecase (#594, D5 #738): it drives the pure-domain baseline lifecycle over a persistent store and produces the coverage-honest RiskContext.Behavior factor.
Package behaviorbaseline turns the B5 per-host running-process projection plus the host's sealed runtime detections into the coverage-honest RiskContext.Behavior factor (#594 D).
Package behaviorbaseline turns the B5 per-host running-process projection plus the host's sealed runtime detections into the coverage-honest RiskContext.Behavior factor (#594 D).
Package clusterinventory is the use-case layer for the Kubernetes cluster agent (#411, epic #405).
Package clusterinventory is the use-case layer for the Kubernetes cluster agent (#411, epic #405).
Package correlationuc orchestrates durable, two-phase event-time correlation.
Package correlationuc orchestrates durable, two-phase event-time correlation.
Package coverage is the fleet coverage read model (#413, epic #405): a tenant-scoped PROJECTION over agents, work orders and the asset model that answers, for each (asset, capability), what the coverage verdict is — with unknown/stale/refused/unauthorized/agent-missing kept as distinct states (domain/fleetcoverage) rather than collapsed into "clean".
Package coverage is the fleet coverage read model (#413, epic #405): a tenant-scoped PROJECTION over agents, work orders and the asset model that answers, for each (asset, capability), what the coverage verdict is — with unknown/stale/refused/unauthorized/agent-missing kept as distinct states (domain/fleetcoverage) rather than collapsed into "clean".
Package coveragewindow composes immutable sensor, transport-accounting and loss facts into revisioned, tenant-scoped telemetry coverage windows.
Package coveragewindow composes immutable sensor, transport-accounting and loss facts into revisioned, tenant-scoped telemetry coverage windows.
Package fleetdesired reconciles operator-owned desired capabilities for canonical host/cluster assets against the latest server-authoritative agent bindings and observed fleet-agent state.
Package fleetdesired reconciles operator-owned desired capabilities for canonical host/cluster assets against the latest server-authoritative agent bindings and observed fleet-agent state.
Package detect is the agent-side detection engine (issue #422, phase 3).
Package detect is the agent-side detection engine (issue #422, phase 3).
Package detectionship drains confirmed detections from the durable P1 agent WAL into independently signed detection batches.
Package detectionship drains confirmed detections from the durable P1 agent WAL into independently signed detection batches.
Package detectledger turns the agent-side detection engine's output (#422) into hash-chained, attributable evidence (#423).
Package detectledger turns the agent-side detection engine's output (#422) into hash-chained, attributable evidence (#423).
Package endpointstate is the usecase seam over the endpoint State Timeline (Phase B / B7, #669).
Package endpointstate is the usecase seam over the endpoint State Timeline (Phase B / B7, #669).
Package exposurereader adapts the shipped SCA stores (asset↔component membership, vulnerability occurrences, and per-occurrence risk assessments) into the exposureuc.AssetVulnerabilityReader port — the missing join that lets the X5 Exposure producer read an asset's open vulnerable components with their evaluated Priority/KEV/Severity.
Package exposurereader adapts the shipped SCA stores (asset↔component membership, vulnerability occurrences, and per-occurrence risk assessments) into the exposureuc.AssetVulnerabilityReader port — the missing join that lets the X5 Exposure producer read an asset's open vulnerable components with their evaluated Priority/KEV/Severity.
Package exposureuc is the Phase-C/X5 (#634) producer of the coverage-honest RiskContext.Exposure factor: it reads an asset's currently-open vulnerable components (with their already-evaluated vulnerabilityrisk Priority/KEV and running/installed presence), fuses them via the pure-domain exposure.Fuse, and returns an abstain-capable Assessment for the tri-score risk assembler to place into RiskContext.Exposure.
Package exposureuc is the Phase-C/X5 (#634) producer of the coverage-honest RiskContext.Exposure factor: it reads an asset's currently-open vulnerable components (with their already-evaluated vulnerabilityrisk Priority/KEV and running/installed presence), fuses them via the pure-domain exposure.Fuse, and returns an abstain-capable Assessment for the tri-score risk assembler to place into RiskContext.Exposure.
Package hostinventory is the use-case layer for the VM host agent (#410/#446, epic #405).
Package hostinventory is the use-case layer for the VM host agent (#410/#446, epic #405).
Package hostvuln correlates the OS packages a fleet host agent reports with vulnerability advisories and exposes the result per host (#820).
Package hostvuln correlates the OS packages a fleet host agent reports with vulnerability advisories and exposes the result per host (#820).
Package incidenttriage is the Phase C analyst triage loop (#594, C5 #679): the human-driven mutations on an incident — take ownership, comment, change workflow status, and set a disposition — each recorded as an attributable incident.IncidentEvent on the append-only log (C7) and mirrored to the tamper-evident audit log.
Package incidenttriage is the Phase C analyst triage loop (#594, C5 #679): the human-driven mutations on an incident — take ownership, comment, change workflow status, and set a disposition — each recorded as an attributable incident.IncidentEvent on the append-only log (C7) and mirrored to the tamper-evident audit log.
Package incidentuc is the usecase seam over the event-sourced incident store.
Package incidentuc is the usecase seam over the event-sourced incident store.
Package keyregistry is the control-plane side of the agent signing-key lifecycle (#607, A0.2): an enrolled agent registers its Ed25519 signing public key together with a proof-of-possession bound to its canonical AgentID; operators list and revoke keys.
Package keyregistry is the control-plane side of the agent signing-key lifecycle (#607, A0.2): an enrolled agent registers its Ed25519 signing public key together with a proof-of-possession bound to its canonical AgentID; operators list and revoke keys.
Package legalholduc is the application service for legal holds (#635): an operator places/releases a hold on an engagement's data, and it exposes the IsHeld guard the retention deletion consults.
Package legalholduc is the application service for legal holds (#635): an operator places/releases a hold on an engagement's data, and it exposes the IsHeld guard the retention deletion consults.
Package normalize turns a decoded kernel event (the sensor's raw, pre-identity output) into the canonical telemetry.TelemetryEnvelope the whole data plane consumes (A1, #622).
Package normalize turns a decoded kernel event (the sensor's raw, pre-identity output) into the canonical telemetry.TelemetryEnvelope the whole data plane consumes (A1, #622).
Package privacyexport assembles a data-subject / DPO data-export bundle for one engagement (#635): the governance-relevant data the control plane holds — the detection projection rows + the engagement's active legal holds + a generated-at stamp — in a structured, read-only export.
Package privacyexport assembles a data-subject / DPO data-export bundle for one engagement (#635): the governance-relevant data the control plane holds — the detection projection rows + the engagement's active legal holds + a generated-at stamp — in a structured, read-only export.
Package privacypolicy manages immutable tenant source-redaction policy history and the independently mutable active assignment delivered to fleet agents.
Package privacypolicy manages immutable tenant source-redaction policy history and the independently mutable active assignment delivered to fleet agents.
Package processreport ingests an enrolled agent's running-process report and feeds the two consumers that gave the behavior baseline no input before it existed: the per-host running-process projection (#594 B5) and the behavior baseline learner (#594 D).
Package processreport ingests an enrolled agent's running-process report and feeds the two consumers that gave the behavior baseline no input before it existed: the per-host running-process projection (#594 B5) and the behavior baseline learner (#594 D).
Package responseexecute applies control-plane-signed response commands behind an endpoint-local journal.
Package responseexecute applies control-plane-signed response commands behind an endpoint-local journal.
Package responseobservation runs the endpoint-side, independent response-observation workflow.
Package responseobservation runs the endpoint-side, independent response-observation workflow.
Package responseobserver governs secondary agents that may observe response post-conditions.
Package responseobserver governs secondary agents that may observe response post-conditions.
Package responseverificationingest authenticates and persists purpose-signed response observations.
Package responseverificationingest authenticates and persists purpose-signed response observations.
Package retrohunt is the Phase C retro-hunt seam (#594, C4 #678): given a trigger (a detection or incident on an asset at a time), it pivots to the SURROUNDING endpoint State Timeline — the transitions just before and after the trigger — so an analyst can see what led up to and followed a detection after the raw telemetry that produced it has expired.
Package retrohunt is the Phase C retro-hunt seam (#594, C4 #678): given a trigger (a detection or incident on an asset at a time), it pivots to the SURROUNDING endpoint State Timeline — the transitions just before and after the trigger — so an analyst can see what led up to and followed a detection after the raw telemetry that produced it has expired.
Package riskscorebridge adapts the tri-score assembler's (riskscoreuc) three consumer-side factor ports to their real producers.
Package riskscorebridge adapts the tri-score assembler's (riskscoreuc) three consumer-side factor ports to their real producers.
Package riskscoreuc is the tri-score ASSEMBLER (#594, C3/D/X5 integration): the seam that gathers the three independent risk factors for an incident — Threat (from the incident's own correlated severity), Exposure (X5, exposureuc), Behavior (D, baselineuc) — plus per-class telemetry Coverage, runs the deterministic riskassessment.Scorer (previously called only in tests), and records the resulting RiskAssessment onto the incident via an EventRiskReassessed event.
Package riskscoreuc is the tri-score ASSEMBLER (#594, C3/D/X5 integration): the seam that gathers the three independent risk factors for an incident — Threat (from the incident's own correlated severity), Exposure (X5, exposureuc), Behavior (D, baselineuc) — plus per-class telemetry Coverage, runs the deterministic riskassessment.Scorer (previously called only in tests), and records the resulting RiskAssessment onto the incident via an EventRiskReassessed event.
Package runtimeevidence is the fleet ingest use case for host runtime-reachability evidence (EPIC #1042 #1060/#1061).
Package runtimeevidence is the fleet ingest use case for host runtime-reachability evidence (EPIC #1042 #1060/#1061).
Package telemetry is the agent-side raw-telemetry tier's control plane (#424, ADR 0001).
Package telemetry is the agent-side raw-telemetry tier's control plane (#424, ADR 0001).
Package telemetryingest is the control-plane side of the A3 (#624) agent→control-plane telemetry transport: it accepts a signed TelemetryBatchManifest plus its events, verifies the agent's identity, signing key, schema, canonical envelope attribution, and then sequences the batch idempotently.
Package telemetryingest is the control-plane side of the A3 (#624) agent→control-plane telemetry transport: it accepts a signed TelemetryBatchManifest plus its events, verifies the agent's identity, signing key, schema, canonical envelope attribution, and then sequences the batch idempotently.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL