agentspool

package
v0.2.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 27, 2026 License: Apache-2.0 Imports: 17 Imported by: 0

Documentation

Overview

Package agentspool adapts the existing detection sensor and sink contracts to the canonical telemetry normalizer and the durable agent spool. It contains orchestration only: normalization remains a pure use case and persistence is owned by infrastructure/spool.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func RecordCoverage

func RecordCoverage(ctx context.Context, durable ports.TelemetrySpool, coverage []detection.ClassCoverage, observedAt time.Time) error

RecordCoverage persists both an aggregate coverage window and one sensor state record per class. All records are P0 and never shed: absence of health evidence must never make an unobserved host appear clean.

Types

type CoverageSnapshot

type CoverageSnapshot struct {
	SchemaVersion int                       `json:"schema_version"`
	ObservedAt    time.Time                 `json:"observed_at"`
	Classes       []detection.ClassCoverage `json:"classes"`
}

CoverageSnapshot is the agent-side P0 representation consumed by A3/A6. It deliberately wraps the existing coverage domain records instead of defining a second competing coverage state machine.

type DetectionSink

type DetectionSink struct {
	// contains filtered or unexported fields
}

DetectionSink persists confirmed detections in P1. Its deterministic event id is derived from the canonical JSON, making an engine retry idempotent.

func NewDetectionSink

func NewDetectionSink(durable ports.TelemetrySpool) (*DetectionSink, error)

func (*DetectionSink) Emit

func (s *DetectionSink) Emit(ctx context.Context, value detection.Detection) error

func (*DetectionSink) EmitAttributed

func (s *DetectionSink) EmitAttributed(ctx context.Context, value detection.Detection, attribution fleetagent.DetectionAttribution) error

EmitAttributed creates a v2 spool record only for sources that possess actual transport facts. The current DetectionSensor API does not expose those facts, so its ordinary Emit path remains v1 rather than fabricating causal coordinates from a host or timestamp.

func (*DetectionSink) SetRedactionPolicy

func (s *DetectionSink) SetRedactionPolicy(p privacy.Policy) error

SetRedactionPolicy overrides the source-side redaction policy applied to detection evidence (A6, #627). The sink defaults to privacy.DefaultPolicy(); an invalid policy is rejected so evidence is never shipped with a broken (fail-open) redaction config.

type DurableSensor

type DurableSensor struct {
	// contains filtered or unexported fields
}

DurableSensor tees every decoded event through Normalize and the WAL before exposing it to the detection engine. This ordering means a confirmed detection never references a raw event which was silently discarded first.

func NewDurableSensor

func NewDurableSensor(source ports.DetectionSensor, durable ports.TelemetrySpool, identity SensorIdentity) (*DurableSensor, error)

NewDurableSensor validates dependencies and returns a sensor wrapper. A zero-buffer output intentionally propagates pressure back to the kernel reader rather than growing an unbounded second queue in memory.

func (*DurableSensor) Close

func (s *DurableSensor) Close() error

func (*DurableSensor) Coverage

func (s *DurableSensor) Coverage() []detection.ClassCoverage

func (*DurableSensor) Dropped

func (s *DurableSensor) Dropped() map[detection.Class]uint64

func (*DurableSensor) Events

func (s *DurableSensor) Events() <-chan detection.Event

func (*DurableSensor) SetProcessLifecycleObserver

func (s *DurableSensor) SetProcessLifecycleObserver(observer ProcessLifecycleObserver) error

SetProcessLifecycleObserver wires the descriptor-pinning boundary before the sensor starts. The observer is invoked only after the telemetry WAL accepts the event, so response can never target identity that lacks durable telemetry.

func (*DurableSensor) SetRedactionPolicy

func (s *DurableSensor) SetRedactionPolicy(p privacy.Policy) error

SetRedactionPolicy overrides the source-side redaction policy (A6, #627). A DurableSensor is created with privacy.DefaultPolicy(); an operator/tenant policy is applied here before Start. An invalid policy is rejected so the sensor never ships with a broken (fail-open) redaction config.

func (*DurableSensor) Start

func (s *DurableSensor) Start(ctx context.Context) error

type ProcessLifecycleObserver

type ProcessLifecycleObserver interface {
	ObserveProcess(assetID, bootID shared.ID, event detection.ProcessEvent)
}

ProcessLifecycleObserver receives process identity only after the matching canonical telemetry envelope is durable in the local WAL.

type ProcessLifecycleTimestampObserver

type ProcessLifecycleTimestampObserver interface {
	ObserveProcessAt(assetID, bootID shared.ID, observedAt time.Time, event detection.ProcessEvent)
}

ProcessLifecycleTimestampObserver preserves the local sensor timestamp for consumers that need to bound post-condition observation windows.

type SensorIdentity

type SensorIdentity struct {
	AgentID       shared.ID
	AssetID       shared.ID
	AgentSession  shared.ID
	BootID        shared.ID
	SensorID      string
	SensorVersion string
}

SensorIdentity contains the stable attribution needed to turn the legacy detection sensor's decoded event into A1's canonical envelope.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL