Documentation
¶
Overview ¶
Package fleetclient is the agent-side HTTP client for the fleet transport (#410): it enrols, heartbeats, claims work and reports results against the control plane's /api/v1/fleet API. It is used by the synapse-agent binary. Enrollment uses its one-time bearer credential; subsequent production traffic uses the issued client certificate and private key, which are never logged.
Index ¶
- func BuildResponseResultSigningKey(agentID string, private ed25519.PrivateKey, notBefore, notAfter time.Time) (fleetagent.AgentSigningKey, error)
- func BuildTelemetrySigningKey(agentID string, private ed25519.PrivateKey, notBefore, notAfter time.Time) (fleetagent.AgentSigningKey, error)
- func GenerateKeyAndCSR(commonName string) (csrPEM, keyPEM []byte, err error)
- func HTTPStatus(err error) (status int, retryAfter string, ok bool)
- func IsNetworkError(err error) bool
- func LoadPrivacyPolicy(dir string, expectedAgentID shared.ID, expectedControlPlane string) (privacy.Assignment, bool)
- func PersistPrivacyPolicy(dir string, agentID shared.ID, controlPlane string, ...) error
- func ReadEnrolTokenFile(path string) (string, error)
- func ValidateControlPlaneURL(raw string) error
- func WriteSecret(path string, data []byte, mode os.FileMode) error
- type Client
- func (c *Client) ActivateCredential(cred Credential, keyPEM []byte) error
- func (c *Client) ActivePrivacyPolicy(ctx context.Context, token string) (PrivacyPolicyResponse, error)
- func (c *Client) ClaimWork(ctx context.Context, token string, max int) ([]Order, error)
- func (c *Client) Enrol(ctx context.Context, enrolToken string, req EnrolRequest) (EnrolResponse, error)
- func (c *Client) Heartbeat(ctx context.Context, token string, req EnrolRequest) (HeartbeatResponse, error)
- func (c *Client) Progress(ctx context.Context, token, orderID, leaseID string) error
- func (c *Client) RegisterDetectionKey(ctx context.Context, token string, key fleetagent.AgentSigningKey, ...) error
- func (c *Client) RegisterSigningKey(ctx context.Context, token string, key fleetagent.AgentSigningKey, ...) error
- func (c *Client) RegisterTelemetrySigningKey(ctx context.Context, token string, key fleetagent.AgentSigningKey, ...) error
- func (c *Client) ReportProcesses(ctx context.Context, token string, procs []ReportedProcess, complete bool) error
- func (c *Client) SendClusterInventory(ctx context.Context, token string, snap any) error
- func (c *Client) SendDetectionBatch(ctx context.Context, token string, batch fleetagent.AgentBatch, ...) error
- func (c *Client) SendDetectionBatchV2(ctx context.Context, token string, batch fleetagent.AgentBatchV2, ...) error
- func (c *Client) SendHostInventory(ctx context.Context, token string, inv any) error
- func (c *Client) SendHostInventoryResolved(ctx context.Context, token string, inv any) (HostInventoryResponse, error)
- func (c *Client) SendRuntimeEvidence(ctx context.Context, token string, report any) error
- func (c *Client) ShipResponseVerification(ctx context.Context, token string, ...) (ResponseVerificationShipResponse, error)
- func (c *Client) ShipSensorState(ctx context.Context, token string, report fleetagent.SensorStateReport) (SensorStateShipResponse, error)
- func (c *Client) ShipTelemetry(ctx context.Context, token string, in TelemetryIngestRequest) (TelemetryShipResponse, error)
- func (c *Client) ShipTelemetryGap(ctx context.Context, token string, report fleetagent.TelemetryGapReport) (TelemetryGapShipResponse, error)
- func (c *Client) SubmitResponseResult(ctx context.Context, token, orderID string, request ResponseResultRequest) error
- func (c *Client) SubmitResult(ctx context.Context, token, orderID, leaseID, status, reason string) error
- type Credential
- type CredentialStore
- func (s *CredentialStore) AcknowledgeResponseVerificationReport(attemptKey string) error
- func (s *CredentialStore) EnsureResponseVerificationSigner(agentID string, now time.Time) (ResponseVerificationSigner, error)
- func (s *CredentialStore) EnsureTelemetrySigner(agentID string, now time.Time) (TelemetrySigner, error)
- func (s *CredentialStore) Load() (Credential, bool)
- func (s *CredentialStore) LoadPrivateKey() ([]byte, error)
- func (s *CredentialStore) LoadResponseVerificationReport(attemptKey string) (fleetagent.ResponseVerificationReport, bool, error)
- func (s *CredentialStore) Persist(cred Credential, keyPEM []byte) error
- func (s *CredentialStore) PersistAssetBinding(cred Credential, assetID string) (Credential, error)
- func (s *CredentialStore) PersistResponseObserverAssetBinding(cred Credential, assetID string) (Credential, error)
- func (s *CredentialStore) SaveResponseVerificationReport(report fleetagent.ResponseVerificationReport) error
- type EnrolRequest
- type EnrolResponse
- type Enroller
- type HTTPError
- type HTTPStatusError
- type HeartbeatResponse
- type HostInventoryResponse
- type NetworkError
- type Order
- type PersistedPrivacyPolicy
- type PrivacyPolicy
- type PrivacyPolicyAssignment
- type PrivacyPolicyResponse
- type ReportedProcess
- type ResponseResultRequest
- type ResponseVerificationShipResponse
- type ResponseVerificationSigner
- type SensorStateShipResponse
- type TelemetryEventPayload
- type TelemetryGapShipResponse
- type TelemetryIngestRequest
- type TelemetryShipResponse
- type TelemetrySigner
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func BuildResponseResultSigningKey ¶ added in v0.2.0
func BuildResponseResultSigningKey(agentID string, private ed25519.PrivateKey, notBefore, notAfter time.Time) (fleetagent.AgentSigningKey, error)
func BuildTelemetrySigningKey ¶ added in v0.2.0
func BuildTelemetrySigningKey(agentID string, private ed25519.PrivateKey, notBefore, notAfter time.Time) (fleetagent.AgentSigningKey, error)
BuildTelemetrySigningKey reconstructs the public lifecycle value from an agent's persisted private key and exact registration window.
func GenerateKeyAndCSR ¶
GenerateKeyAndCSR creates a fresh P-256 key pair and a PKCS#10 certificate-signing request for commonName, returning both PEM-encoded. The private key never leaves the agent; only the CSR is sent to the control plane, which signs it with the fleet CA (see internal/infrastructure/fleetca). P-256 satisfies the CA's minimum key-strength check (ECDSA >= 256 bits).
func HTTPStatus ¶ added in v0.2.0
HTTPStatus returns the status metadata carried by an HTTPError.
func IsNetworkError ¶ added in v0.2.0
IsNetworkError reports whether the request failed before an HTTP response was available.
func LoadPrivacyPolicy ¶ added in v0.2.0
func LoadPrivacyPolicy( dir string, expectedAgentID shared.ID, expectedControlPlane string, ) (privacy.Assignment, bool)
LoadPrivacyPolicy returns only a structurally and cryptographically consistent cached policy; malformed or stale-on-disk content fails closed.
func PersistPrivacyPolicy ¶ added in v0.2.0
func PersistPrivacyPolicy( dir string, agentID shared.ID, controlPlane string, assignment privacy.Assignment, ) error
PersistPrivacyPolicy validates and atomically replaces the cached active policy.
func ReadEnrolTokenFile ¶
ReadEnrolTokenFile reads a one-time enrolment token from path, treating an ABSENT file as "no token supplied" rather than as an error.
The distinction is the whole point. An enrolment token is consumed on first use, after which the agent holds a long-lived credential and the token is dead weight — so an operator deleting the consumed secret is doing the right thing. If a missing file were fatal, that correct hygiene would mean the agent could never restart, which is how a Kubernetes deployment ends up unable to come back after its Secret is cleaned up. EnsureEnrolled already decides correctly from here: a stored credential wins, and only "no credential AND no token" is an error.
Every OTHER read failure stays an error. A file that exists but cannot be read — wrong mode, a directory, a broken mount — is a misconfiguration, and silently treating it as "no token" would convert it into a confusing enrolment failure somewhere further away.
func ValidateControlPlaneURL ¶
ValidateControlPlaneURL refuses a cleartext control-plane URL so the bearer credential cannot traverse plaintext HTTP. http is allowed only for a loopback host (local development/testing). Shared by every agent binary so the transport-security rule is enforced identically.
func WriteSecret ¶
WriteSecret writes secret material and enforces the mode even if the file pre-existed with looser permissions (os.WriteFile applies the mode only on create). The explicit Chmod closes the window where a pre-seeded, world-readable file would keep its old mode after a rewrite. Exported so agent binaries reuse it for their own on-disk secrets (e.g. a buffered inventory) rather than duplicating it.
Types ¶
type Client ¶
type Client struct {
// contains filtered or unexported fields
}
Client talks to the control plane fleet API.
func New ¶
New builds a client for baseURL (e.g. https://control-plane). timeout bounds each request.
func NewWithEnrollmentURL ¶ added in v0.2.0
NewWithEnrollmentURL separates the TLS-only one-time enrollment endpoint from the strict mTLS endpoint used after enrollment. Both URLs must identify the same control plane trust domain.
func (*Client) ActivateCredential ¶ added in v0.2.0
func (c *Client) ActivateCredential(cred Credential, keyPEM []byte) error
ActivateCredential installs the enrolled agent's client certificate on the HTTP transport. A certificate-less bearer transport is retained only for an explicitly configured loopback control plane used by local development and tests.
func (*Client) ActivePrivacyPolicy ¶ added in v0.2.0
func (c *Client) ActivePrivacyPolicy(ctx context.Context, token string) (PrivacyPolicyResponse, error)
ActivePrivacyPolicy fetches the tenant's active source-redaction policy for an authenticated agent.
func (*Client) Enrol ¶
func (c *Client) Enrol(ctx context.Context, enrolToken string, req EnrolRequest) (EnrolResponse, error)
Enrol exchanges an enrolment token for an agent credential.
func (*Client) Heartbeat ¶
func (c *Client) Heartbeat(ctx context.Context, token string, req EnrolRequest) (HeartbeatResponse, error)
Heartbeat reports liveness and current attributes and returns the control plane's version-skew signals.
func (*Client) RegisterDetectionKey ¶ added in v0.2.0
func (c *Client) RegisterDetectionKey(ctx context.Context, token string, key fleetagent.AgentSigningKey, proof string) error
func (*Client) RegisterSigningKey ¶ added in v0.2.0
func (c *Client) RegisterSigningKey(ctx context.Context, token string, key fleetagent.AgentSigningKey, proof string) error
RegisterSigningKey registers an agent-owned purpose-scoped signing key with proof-of-possession. The private key never enters this adapter; only the public lifecycle record and its PoP signature cross the wire. Registration is idempotent server-side.
func (*Client) RegisterTelemetrySigningKey ¶ added in v0.2.0
func (c *Client) RegisterTelemetrySigningKey(ctx context.Context, token string, key fleetagent.AgentSigningKey, proof string) error
RegisterTelemetrySigningKey registers the telemetry-batch key through the canonical A0.2/A4 fleet key registry. The private key never crosses the API; proof is the purpose/agent/window-bound proof-of-possession produced by fleetagent.ProveKeyPossession.
func (*Client) ReportProcesses ¶ added in v0.2.0
func (c *Client) ReportProcesses(ctx context.Context, token string, procs []ReportedProcess, complete bool) error
ReportProcesses posts the host's running-process snapshot for the behavior baseline (#594 D). The control plane resolves the host asset from the authenticated agent, so no asset id crosses the wire.
func (*Client) SendClusterInventory ¶
SendClusterInventory posts a collected Kubernetes cluster snapshot to the control plane, which maps and persists it into the asset model (#446). snap must be a JSON-tagged clusterinventory.Snapshot; the caller passes it as the marshalable value so this package keeps no domain dependency.
func (*Client) SendDetectionBatch ¶ added in v0.2.0
func (c *Client) SendDetectionBatch(ctx context.Context, token string, batch fleetagent.AgentBatch, items []fleetagent.DetectionBatchItem) error
SendDetectionBatch posts one signed detection batch. A 2xx response means the complete membership was durably admitted (or idempotently skipped), which is the point at which the caller may ACK its WAL.
func (*Client) SendDetectionBatchV2 ¶ added in v0.2.0
func (c *Client) SendDetectionBatchV2(ctx context.Context, token string, batch fleetagent.AgentBatchV2, items []fleetagent.DetectionBatchItemV2) error
SendDetectionBatchV2 posts the separately signed v2 attribution contract. The endpoint remains shared with v1 so enrolled agents retain one narrowly scoped delivery capability.
func (*Client) SendHostInventory ¶
SendHostInventory posts a collected VM host inventory to the control plane, which persists the host into the asset model (#446). inv must be a JSON-tagged hostinventory.HostInventory; the caller passes it as the marshalable value so this package keeps no domain dependency.
func (*Client) SendHostInventoryResolved ¶ added in v0.2.0
func (*Client) SendRuntimeEvidence ¶ added in v0.2.0
SendRuntimeEvidence posts the host's runtime-reachability evidence (observed shared-library loads plus the OS packages that own them) to the agent plane (#1060/#1061). The control plane resolves the host asset from the authenticated agent, so no asset id crosses the wire. Best-effort like the other agent reports: a transport failure is retried on the next sweep.
func (*Client) ShipResponseVerification ¶ added in v0.2.0
func (c *Client) ShipResponseVerification(ctx context.Context, token string, report fleetagent.ResponseVerificationReport) (ResponseVerificationShipResponse, error)
ShipResponseVerification sends one purpose-signed P0 post-condition report and requires an exact ACK.
func (*Client) ShipSensorState ¶ added in v0.2.0
func (c *Client) ShipSensorState(ctx context.Context, token string, report fleetagent.SensorStateReport) (SensorStateShipResponse, error)
ShipSensorState sends a signed P0 coverage or sensor-state report. The caller retains its durable WAL record until the returned acknowledgement names the exact report ID it issued.
func (*Client) ShipTelemetry ¶ added in v0.2.0
func (c *Client) ShipTelemetry(ctx context.Context, token string, in TelemetryIngestRequest) (TelemetryShipResponse, error)
ShipTelemetry sends the canonical ingest request gzip-compressed. The manifest signature commits to the uncompressed event bytes; HTTP compression happens only after signing and therefore cannot change the transport commitment.
func (*Client) ShipTelemetryGap ¶ added in v0.2.0
func (c *Client) ShipTelemetryGap(ctx context.Context, token string, report fleetagent.TelemetryGapReport) (TelemetryGapShipResponse, error)
ShipTelemetryGap sends one purpose-bound signed durable-loss report over the authenticated telemetry endpoint with a distinct media type. HTTP gzip is transport-only: the Ed25519 signature commits to canonical report fields.
func (*Client) SubmitResponseResult ¶ added in v0.2.0
type Credential ¶
type Credential struct {
AgentID string `json:"agent_id"`
Token string `json:"token"`
CertificatePEM string `json:"certificate_pem,omitempty"`
// AssetID is this enrolled agent's immutable primary telemetry host binding.
AssetID string `json:"asset_id,omitempty"`
// ResponseObserverAssetID is a server-assigned secondary target for bounded
// response-observation telemetry. It never replaces AssetID.
ResponseObserverAssetID string `json:"response_observer_asset_id,omitempty"`
}
Credential is a persisted agent identity. Token is a secret: the file is written 0600 and its contents are never logged. AssetID is the last canonical binding returned by the control plane's host-inventory reconciliation; the agent never derives it from its name or AgentID.
func EnsureEnrolled ¶
func EnsureEnrolled(ctx context.Context, e Enroller, store *CredentialStore, enrolToken string, req EnrolRequest) (Credential, error)
EnsureEnrolled returns a stored credential, or on first run generates a P-256 key + CSR, enrols via e using enrolToken, and persists the result. req carries the agent's name/platform/version/ capabilities; its CSRPEM is filled in here (the private key never leaves the host — only the CSR is sent). It errors when there is neither a stored credential nor an enrolment token.
type CredentialStore ¶
type CredentialStore struct {
// contains filtered or unexported fields
}
CredentialStore persists an agent credential + private key under a state directory. It is shared by every agent binary so the security-sensitive persistence (0600, chmod on rewrite) lives in one place.
func NewCredentialStore ¶
func NewCredentialStore(dir string) *CredentialStore
NewCredentialStore returns a store rooted at dir.
func (*CredentialStore) AcknowledgeResponseVerificationReport ¶ added in v0.2.0
func (s *CredentialStore) AcknowledgeResponseVerificationReport(attemptKey string) error
func (*CredentialStore) EnsureResponseVerificationSigner ¶ added in v0.2.0
func (s *CredentialStore) EnsureResponseVerificationSigner(agentID string, now time.Time) (ResponseVerificationSigner, error)
func (*CredentialStore) EnsureTelemetrySigner ¶ added in v0.2.0
func (s *CredentialStore) EnsureTelemetrySigner(agentID string, now time.Time) (TelemetrySigner, error)
EnsureTelemetrySigner loads a usable signer or creates one when the signer is absent, expired, or inside the bounded pre-expiry rotation window.
func (*CredentialStore) Load ¶
func (s *CredentialStore) Load() (Credential, bool)
Load returns a stored credential, or ok=false when none is present/usable.
func (*CredentialStore) LoadPrivateKey ¶ added in v0.2.0
func (s *CredentialStore) LoadPrivateKey() ([]byte, error)
LoadPrivateKey reads the enrolled agent's private key for client-certificate authentication.
func (*CredentialStore) LoadResponseVerificationReport ¶ added in v0.2.0
func (s *CredentialStore) LoadResponseVerificationReport(attemptKey string) (fleetagent.ResponseVerificationReport, bool, error)
func (*CredentialStore) Persist ¶
func (s *CredentialStore) Persist(cred Credential, keyPEM []byte) error
Persist writes the credential (and the private key, when supplied) with 0600 permissions.
func (*CredentialStore) PersistAssetBinding ¶ added in v0.2.0
func (s *CredentialStore) PersistAssetBinding(cred Credential, assetID string) (Credential, error)
PersistAssetBinding updates only the server-reconciled canonical asset while retaining all credential material. A missing identity/asset fails closed rather than persisting an unusable telemetry attribution.
func (*CredentialStore) PersistResponseObserverAssetBinding ¶ added in v0.2.0
func (s *CredentialStore) PersistResponseObserverAssetBinding(cred Credential, assetID string) (Credential, error)
PersistResponseObserverAssetBinding records a server-assigned observation target without altering the agent's primary telemetry host identity.
func (*CredentialStore) SaveResponseVerificationReport ¶ added in v0.2.0
func (s *CredentialStore) SaveResponseVerificationReport(report fleetagent.ResponseVerificationReport) error
type EnrolRequest ¶
type EnrolRequest struct {
Name string `json:"name"`
Platform string `json:"platform"`
OSVersion string `json:"os_version"`
AgentVersion string `json:"agent_version"`
Capabilities []string `json:"capabilities"`
CSRPEM string `json:"csr_pem,omitempty"`
}
EnrolRequest is the agent's enrolment payload; CSRPEM is optional (certificate identity).
type EnrolResponse ¶
type EnrolResponse struct {
AgentID string `json:"agent_id"`
Token string `json:"token"`
CertificatePEM string `json:"certificate_pem,omitempty"`
}
EnrolResponse carries the once-only credential material.
type Enroller ¶
type Enroller interface {
Enrol(ctx context.Context, enrolToken string, req EnrolRequest) (EnrolResponse, error)
ActivateCredential(cred Credential, keyPEM []byte) error
}
Enroller is the subset of the client EnsureEnrolled needs; *Client satisfies it, and an agent's test fake can too.
type HTTPError ¶ added in v0.2.0
HTTPError preserves the response metadata the durable delivery loop needs to distinguish retryable backpressure/server failures from permanent 4xx failures and a revoked signing key. Body is a bounded, trimmed diagnostic snippet and must never contain the bearer credential (headers are not copied).
func (*HTTPError) ResponseStatus ¶ added in v0.2.0
ResponseStatus lets delivery use cases classify the response without depending on this adapter.
type HTTPStatusError ¶ added in v0.2.0
HTTPStatusError preserves the status required by A2's retry policy without exposing or depending on server response text.
func (*HTTPStatusError) Error ¶ added in v0.2.0
func (e *HTTPStatusError) Error() string
func (*HTTPStatusError) ResponseStatusCode ¶ added in v0.2.0
func (e *HTTPStatusError) ResponseStatusCode() int
ResponseStatusCode exposes only retry classification to use cases without coupling them to HTTP.
func (*HTTPStatusError) Retryable ¶ added in v0.2.0
func (e *HTTPStatusError) Retryable() bool
type HeartbeatResponse ¶
type HeartbeatResponse struct {
Proto string `json:"proto"`
ControlPlaneVersion string `json:"control_plane_version"`
MinSupportedAgentVersion string `json:"min_supported_agent_version"`
ResponseHalted bool `json:"response_halted"`
ResponseHaltGeneration int64 `json:"response_halt_generation"`
ResponseObserverAssetID string `json:"response_observer_asset_id"`
}
HeartbeatResponse carries the control plane's version-skew signals (#412): its own version and the minimum agent version it will serve. An agent uses these to update itself or to refuse running against a control plane older than it requires.
type HostInventoryResponse ¶ added in v0.2.0
type HostInventoryResponse struct {
AssetID string `json:"asset_id"`
}
HostInventoryResponse returns the server-reconciled canonical asset identity. The agent persists this value and never substitutes its mutable name or AgentID for it.
type NetworkError ¶ added in v0.2.0
NetworkError distinguishes a request that never received an HTTP response from a permanent local validation/state failure. Durable shippers may retry it with bounded jitter.
func (*NetworkError) Error ¶ added in v0.2.0
func (e *NetworkError) Error() string
func (*NetworkError) Unwrap ¶ added in v0.2.0
func (e *NetworkError) Unwrap() error
type Order ¶
type Order struct {
ID string `json:"ID"`
Capability string `json:"Capability"`
AssetID string `json:"AssetID"`
IdempotencyKey string `json:"IdempotencyKey"`
LeaseID string `json:"LeaseID"`
LeaseUntil time.Time `json:"LeaseUntil"`
ResponseCommand *fleetagent.ResponseCommand `json:"ResponseCommand,omitempty"`
ResponseHalt *fleetagent.ResponseHaltCommand `json:"ResponseHalt,omitempty"`
ResponseObserve *fleetagent.ResponseObservationRequest `json:"ResponseObserve,omitempty"`
}
type PersistedPrivacyPolicy ¶ added in v0.2.0
type PersistedPrivacyPolicy struct {
AgentID shared.ID `json:"agent_id"`
ControlPlane string `json:"control_plane"`
TenantID shared.ID `json:"tenant_id"`
Policy privacy.Policy `json:"policy"`
Digest string `json:"digest"`
CreatedBy string `json:"created_by"`
CreatedAt time.Time `json:"created_at"`
}
PersistedPrivacyPolicy is the validated active source-redaction policy cached independently from bearer credentials and telemetry WAL content.
type PrivacyPolicy ¶ added in v0.2.0
type PrivacyPolicy struct {
Dispositions map[string]string `json:"dispositions"`
RedactSecrets bool `json:"redact_secrets"`
MaxArgLen int `json:"max_arg_len"`
MaxArgCount int `json:"max_arg_count"`
MaxPathLen int `json:"max_path_len"`
HashSalt string `json:"hash_salt,omitempty"`
Version string `json:"version"`
}
Order is the subset of a work order the agent needs to act. The tags are PascalCase deliberately: the control plane serialises domain/workorder.WorkOrder with NO json tags, so encoding/json emits the exact Go field names (ID, Capability, AssetID). Matching that here is what lets these decode; snake_case tags would silently zero these fields. Verified against the server's claim handler.
type PrivacyPolicyAssignment ¶ added in v0.2.0
type PrivacyPolicyResponse ¶ added in v0.2.0
type PrivacyPolicyResponse struct {
Assignment PrivacyPolicyAssignment `json:"assignment"`
}
func (PrivacyPolicyResponse) AssignmentDomain ¶ added in v0.2.0
func (r PrivacyPolicyResponse) AssignmentDomain() (privacy.Assignment, error)
Assignment converts a validated wire response into the domain assignment used at the source-observation boundary.
type ReportedProcess ¶ added in v0.2.0
type ReportedProcess struct {
PID int `json:"pid"`
Comm string `json:"comm"`
Path string `json:"path"`
Running bool `json:"running"`
}
ReportedProcess is one running process the agent observed, in the wire shape the process-report endpoint accepts. The agent maps its OS enumeration to this; the client keeps no OS dependency.
type ResponseResultRequest ¶ added in v0.2.0
type ResponseResultRequest struct {
Status string `json:"status"`
Reason string `json:"reason"`
AttemptKey string `json:"attempt_key"`
CommandDigest string `json:"command_digest"`
ExecutionState fleetagent.ResponseExecutionState `json:"execution_state"`
ObservedRadius offensivepolicy.Radius `json:"observed_radius"`
AffectedCount int `json:"affected_count"`
AlreadyApplied bool `json:"already_applied"`
CompletedAt time.Time `json:"completed_at"`
LeaseID string `json:"lease_id"`
}
type ResponseVerificationShipResponse ¶ added in v0.2.0
type ResponseVerificationSigner ¶ added in v0.2.0
type ResponseVerificationSigner struct {
PrivateKey ed25519.PrivateKey
Key fleetagent.AgentSigningKey
}
func (ResponseVerificationSigner) NeedsRotation ¶ added in v0.2.0
func (s ResponseVerificationSigner) NeedsRotation(now time.Time) bool
type SensorStateShipResponse ¶ added in v0.2.0
type SensorStateShipResponse struct {
Acknowledged bool `json:"acknowledged"`
ReportID shared.ID `json:"report_id"`
}
SensorStateShipResponse acknowledges the precise immutable sensor-state report which the control plane has accepted into append-only history.
type TelemetryEventPayload ¶ added in v0.2.0
type TelemetryEventPayload struct {
EventID shared.ID
Class detection.Class
Payload []byte
ObservedAt time.Time
}
TelemetryEventPayload is the client-side wire mirror of telemetryingest.EventPayload. It intentionally keeps the canonical Go field names because the server currently decodes telemetryingest.IngestRequest directly.
type TelemetryGapShipResponse ¶ added in v0.2.0
type TelemetryGapShipResponse struct {
Acknowledged bool `json:"acknowledged"`
GapID shared.ID `json:"gap_id"`
}
TelemetryGapShipResponse acknowledges one stable local loss object. GapID is echoed by the server only after the signed report has passed validation and durable persistence; callers must match it before deleting the local journal.
type TelemetryIngestRequest ¶ added in v0.2.0
type TelemetryIngestRequest struct {
Manifest fleetagent.TelemetryBatchManifest
Events []TelemetryEventPayload
}
TelemetryIngestRequest is the client-side wire mirror of telemetryingest.IngestRequest. Keeping this mirror in infrastructure avoids making the fleet client depend on a use-case package.
type TelemetryShipResponse ¶ added in v0.2.0
type TelemetryShipResponse struct {
Accepted bool `json:"accepted"`
Duplicate bool `json:"duplicate"`
ACK uint64 `json:"ack"`
Provenance string `json:"provenance"`
GapOpen bool `json:"gap_open"`
}
TelemetryShipResponse is the canonical #651 ingest response. ACK is the highest contiguous batch sequence for the stream incarnation represented by the request.
type TelemetrySigner ¶ added in v0.2.0
type TelemetrySigner struct {
PrivateKey ed25519.PrivateKey
Key fleetagent.AgentSigningKey
}
TelemetrySigner is the private agent-side half plus the exact public lifecycle registration it proves possession of. The private key never crosses the API.
func (TelemetrySigner) NeedsRotation ¶ added in v0.2.0
func (s TelemetrySigner) NeedsRotation(now time.Time) bool
NeedsRotation reports whether the signer is absent or too close to expiry to safely start another transport cycle.