Documentation
¶
Overview ¶
Package capabilities answers one product question: which optional subsystems are switched on in this deployment, and which SYNAPSE_* variable switches each one.
Without it the dashboard cannot tell "this subsystem is off" from "this subsystem is broken": every optional route is registered conditionally in the composition root, so a disabled subsystem and a crashed one both answer 404. The catalog is static product knowledge, so it lives in the use case layer; the composition root only hands it the resolved flag values.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Capability ¶
Capability describes one optional subsystem to a client. Key is stable API: a dashboard keys its navigation off it. Switch names the SYNAPSE_* variable an operator sets to change Enabled, so the product can say "Fleet is off because SYNAPSE_FLEET_ENABLED is false" instead of showing a dead link. Requires lists the keys of other capabilities this one needs, so a client can explain an enabled switch that still yields a disabled subsystem.
type Flags ¶
type Flags struct {
Fleet bool // SYNAPSE_FLEET_ENABLED
FleetAssets bool // SYNAPSE_FLEET_ASSETS_ENABLED
FleetHostIngest bool // SYNAPSE_FLEET_HOST_INGEST_ENABLED
FleetClusterIngest bool // SYNAPSE_FLEET_CLUSTER_INGEST_ENABLED
FleetTelemetryIngest bool // SYNAPSE_FLEET_TELEMETRY_INGEST_ENABLED
FleetDetectionIngest bool // SYNAPSE_FLEET_DETECTION_INGEST_ENABLED
CSPM bool // SYNAPSE_CSPM_ENABLED
Agent bool // SYNAPSE_AGENT_ENABLED
FPTriage bool // SYNAPSE_FP_TRIAGE_ENABLED
SLA bool // SYNAPSE_SLA_ENABLED
Judgments bool // SYNAPSE_JUDGMENTS_ENABLED
Sandbox bool // SYNAPSE_SANDBOX_ENABLED
WriteupDrafts bool // SYNAPSE_WRITEUP_DRAFTS_ENABLED
Taint bool // SYNAPSE_TAINT_ENABLED
JSReachability bool // SYNAPSE_JSREACH_ENABLED
SingleTenant bool // SYNAPSE_SINGLE_TENANT
OIDC bool // SYNAPSE_OIDC_ENABLED
Ownership bool // effective SYNAPSE_OWNERSHIP_MODE != off with PostgreSQL
}
Flags carries the resolved value of every SYNAPSE_* switch that gates an optional subsystem. The composition root assigns each field straight from config; no derivation happens there. A subsystem whose enablement depends on more than one switch is derived here, once.
type Service ¶
type Service struct {
// contains filtered or unexported fields
}
Service serves the immutable capability catalog resolved at startup.
func NewService ¶
NewService resolves the catalog from the deployment's flags. It rejects a catalog with a duplicate or incomplete entry, so a future edit cannot ship an ambiguous key or a capability that names no switch.
func (*Service) List ¶
func (s *Service) List() []Capability
List returns the catalog in a stable order. The slice is copied so a caller cannot mutate the startup-resolved answer. It reads no I/O, so it takes no context.