fleetcoverage

package
v0.2.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 26, 2026 License: Apache-2.0 Imports: 1 Imported by: 0

Documentation

Overview

Package fleetcoverage is the pure-domain truth model for fleet coverage (#413, epic #405): given the facts about one (asset, capability) pair, it resolves a single coverage verdict. The whole point is that ABSENCE OF DATA is never rendered as clean — "unknown", "stale", "refused", "unauthorized" and "agent missing" are distinct verdicts, resolved in a fixed order, so a green dashboard can never hide an unassessed estate. It imports only stdlib + shared.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func IsFresh

func IsFresh(lastAssessed, now time.Time, target time.Duration) bool

IsFresh reports whether an assessment at lastAssessed is within target of now. A zero lastAssessed (never assessed) is never fresh. A non-positive target means "no freshness requirement" (always fresh once assessed) so a policy that has not set a target does not spuriously mark everything stale.

Types

type AgentHealth

type AgentHealth string

AgentHealth is the derived liveness state of a fleet agent. Stale is first-class: an agent that has not been seen within the threshold is neither healthy nor silently dropped.

const (
	// AgentHealthy: seen within the staleness threshold.
	AgentHealthy AgentHealth = "healthy"
	// AgentStale: alive at last enrolment but not seen within the threshold (or never seen).
	AgentStale AgentHealth = "stale"
	// AgentRevoked: an operator revoked the credential; it must never count as covering anything.
	AgentRevoked AgentHealth = "revoked"
	// AgentDecommissioned: the agent cleanly uninstalled and self-reported removal (#412). Like revoked
	// it never covers, but it is surfaced DISTINCTLY so an orderly removal is not shown as a revocation.
	AgentDecommissioned AgentHealth = "decommissioned"
)

func AgentStateFrom

func AgentStateFrom(lastSeen, now time.Time, staleAfter time.Duration, revoked, decommissioned bool) AgentHealth

AgentStateFrom derives the health state from the last-seen time. A revoked agent is always revoked and a decommissioned agent is always decommissioned (revocation takes precedence when both are set, as it is the stronger, operator-attributed terminal state). Otherwise, an agent not seen within staleAfter (or never seen) is stale; a non-positive staleAfter disables the staleness check (an unset threshold must not mark every agent stale). now is injected for determinism.

func (AgentHealth) Live

func (h AgentHealth) Live() bool

Live reports whether an agent in this state can currently cover work (only healthy agents do; a stale, revoked, or decommissioned agent contributes nothing to coverage).

func (AgentHealth) Valid

func (h AgentHealth) Valid() bool

Valid reports whether h is a known agent-health state.

type Signals

type Signals struct {
	Authorized     bool      // asset is within an active authorization scope for the tenant
	AgentAvailable bool      // at least one live (non-stale) agent advertises this capability
	Refused        bool      // the most recent relevant work order was refused
	RefusedReason  string    // why (surfaced with the refused verdict)
	Assessed       bool      // a completed assessment (successful run) exists for this pair
	LastAssessed   time.Time // when the last assessment ran (zero if never)
	Fresh          bool      // the last assessment is within the capability's freshness target
	Complete       bool      // the last assessment was complete (not partial/degraded)
}

Signals are the facts the projection reduces an (asset, capability) pair to. Resolve is a pure function of these — all the messy store lookups happen in the use case, the policy lives here.

type Verdict

type Verdict string

Verdict is the coverage state of one (asset, capability) pair.

const (
	// VerdictUnauthorized: the asset is outside the tenant's active authorization scope. It must never
	// be described as merely stale, and no findings for it may leak into any aggregate.
	VerdictUnauthorized Verdict = "unauthorized"
	// VerdictAgentMissing: no live agent advertises this capability for the asset — coverage is absent
	// because nothing can assess it, not because it is clean.
	VerdictAgentMissing Verdict = "agent_missing"
	// VerdictRefused: the most recent relevant work order was refused (with a reason).
	VerdictRefused Verdict = "refused"
	// VerdictNever: an agent exists but the pair has never been assessed.
	VerdictNever Verdict = "never"
	// VerdictStale: the last assessment is older than the capability's freshness target.
	VerdictStale Verdict = "stale"
	// VerdictPartial: the last assessment was fresh but incomplete (coverage gaps / degraded).
	VerdictPartial Verdict = "partial"
	// VerdictCovered: assessed, fresh, and complete.
	VerdictCovered Verdict = "covered"
)

func ResolutionOrder

func ResolutionOrder() []Verdict

ResolutionOrder returns a copy of the fixed verdict resolution order.

func Resolve

func Resolve(s Signals) (Verdict, string)

Resolve applies the fixed top-down order and returns the first matching verdict, plus a detail string (the refusal reason for refused; empty otherwise). It NEVER returns covered unless the pair is authorized, has a live agent, was not refused, and was assessed freshly and completely.

func (Verdict) Passing

func (v Verdict) Passing() bool

Passing reports whether the verdict represents actual, trustworthy coverage. Only "covered" passes — every other verdict (including partial and stale) is a non-passing state a dashboard must surface.

func (Verdict) Valid

func (v Verdict) Valid() bool

Valid reports whether v is a known verdict.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL