Documentation
¶
Overview ¶
Package fleetcoverage is the pure-domain truth model for fleet coverage (#413, epic #405): given the facts about one (asset, capability) pair, it resolves a single coverage verdict. The whole point is that ABSENCE OF DATA is never rendered as clean — "unknown", "stale", "refused", "unauthorized" and "agent missing" are distinct verdicts, resolved in a fixed order, so a green dashboard can never hide an unassessed estate. It imports only stdlib + shared.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func IsFresh ¶
IsFresh reports whether an assessment at lastAssessed is within target of now. A zero lastAssessed (never assessed) is never fresh. A non-positive target means "no freshness requirement" (always fresh once assessed) so a policy that has not set a target does not spuriously mark everything stale.
Types ¶
type AgentHealth ¶
type AgentHealth string
AgentHealth is the derived liveness state of a fleet agent. Stale is first-class: an agent that has not been seen within the threshold is neither healthy nor silently dropped.
const ( // AgentHealthy: seen within the staleness threshold. AgentHealthy AgentHealth = "healthy" // AgentStale: alive at last enrolment but not seen within the threshold (or never seen). AgentStale AgentHealth = "stale" // AgentRevoked: an operator revoked the credential; it must never count as covering anything. AgentRevoked AgentHealth = "revoked" // AgentDecommissioned: the agent cleanly uninstalled and self-reported removal (#412). Like revoked // it never covers, but it is surfaced DISTINCTLY so an orderly removal is not shown as a revocation. AgentDecommissioned AgentHealth = "decommissioned" )
func AgentStateFrom ¶
func AgentStateFrom(lastSeen, now time.Time, staleAfter time.Duration, revoked, decommissioned bool) AgentHealth
AgentStateFrom derives the health state from the last-seen time. A revoked agent is always revoked and a decommissioned agent is always decommissioned (revocation takes precedence when both are set, as it is the stronger, operator-attributed terminal state). Otherwise, an agent not seen within staleAfter (or never seen) is stale; a non-positive staleAfter disables the staleness check (an unset threshold must not mark every agent stale). now is injected for determinism.
func (AgentHealth) Live ¶
func (h AgentHealth) Live() bool
Live reports whether an agent in this state can currently cover work (only healthy agents do; a stale, revoked, or decommissioned agent contributes nothing to coverage).
func (AgentHealth) Valid ¶
func (h AgentHealth) Valid() bool
Valid reports whether h is a known agent-health state.
type Signals ¶
type Signals struct {
Authorized bool // asset is within an active authorization scope for the tenant
AgentAvailable bool // at least one live (non-stale) agent advertises this capability
Refused bool // the most recent relevant work order was refused
RefusedReason string // why (surfaced with the refused verdict)
Assessed bool // a completed assessment (successful run) exists for this pair
LastAssessed time.Time // when the last assessment ran (zero if never)
Fresh bool // the last assessment is within the capability's freshness target
Complete bool // the last assessment was complete (not partial/degraded)
}
Signals are the facts the projection reduces an (asset, capability) pair to. Resolve is a pure function of these — all the messy store lookups happen in the use case, the policy lives here.
type Verdict ¶
type Verdict string
Verdict is the coverage state of one (asset, capability) pair.
const ( // be described as merely stale, and no findings for it may leak into any aggregate. VerdictUnauthorized Verdict = "unauthorized" // VerdictAgentMissing: no live agent advertises this capability for the asset — coverage is absent // because nothing can assess it, not because it is clean. VerdictAgentMissing Verdict = "agent_missing" // VerdictRefused: the most recent relevant work order was refused (with a reason). VerdictRefused Verdict = "refused" // VerdictNever: an agent exists but the pair has never been assessed. VerdictNever Verdict = "never" // VerdictStale: the last assessment is older than the capability's freshness target. VerdictStale Verdict = "stale" // VerdictPartial: the last assessment was fresh but incomplete (coverage gaps / degraded). VerdictPartial Verdict = "partial" // VerdictCovered: assessed, fresh, and complete. VerdictCovered Verdict = "covered" )
func ResolutionOrder ¶
func ResolutionOrder() []Verdict
ResolutionOrder returns a copy of the fixed verdict resolution order.
func Resolve ¶
Resolve applies the fixed top-down order and returns the first matching verdict, plus a detail string (the refusal reason for refused; empty otherwise). It NEVER returns covered unless the pair is authorized, has a live agent, was not refused, and was assessed freshly and completely.