Documentation
¶
Overview ¶
Package agentspool adapts the existing detection sensor and sink contracts to the canonical telemetry normalizer and the durable agent spool. It contains orchestration only: normalization remains a pure use case and persistence is owned by infrastructure/spool.
Index ¶
- func RecordCoverage(ctx context.Context, durable ports.TelemetrySpool, ...) error
- type CoverageSnapshot
- type DetectionSink
- type DurableSensor
- func (s *DurableSensor) Close() error
- func (s *DurableSensor) Coverage() []detection.ClassCoverage
- func (s *DurableSensor) Dropped() map[detection.Class]uint64
- func (s *DurableSensor) Events() <-chan detection.Event
- func (s *DurableSensor) SetProcessLifecycleObserver(observer ProcessLifecycleObserver) error
- func (s *DurableSensor) SetRedactionPolicy(p privacy.Policy) error
- func (s *DurableSensor) Start(ctx context.Context) error
- type ProcessLifecycleObserver
- type ProcessLifecycleTimestampObserver
- type SensorIdentity
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func RecordCoverage ¶
func RecordCoverage(ctx context.Context, durable ports.TelemetrySpool, coverage []detection.ClassCoverage, observedAt time.Time) error
RecordCoverage persists both an aggregate coverage window and one sensor state record per class. All records are P0 and never shed: absence of health evidence must never make an unobserved host appear clean.
Types ¶
type CoverageSnapshot ¶
type CoverageSnapshot struct {
SchemaVersion int `json:"schema_version"`
ObservedAt time.Time `json:"observed_at"`
Classes []detection.ClassCoverage `json:"classes"`
}
CoverageSnapshot is the agent-side P0 representation consumed by A3/A6. It deliberately wraps the existing coverage domain records instead of defining a second competing coverage state machine.
type DetectionSink ¶
type DetectionSink struct {
// contains filtered or unexported fields
}
DetectionSink persists confirmed detections in P1. Its deterministic event id is derived from the canonical JSON, making an engine retry idempotent.
func NewDetectionSink ¶
func NewDetectionSink(durable ports.TelemetrySpool) (*DetectionSink, error)
func (*DetectionSink) EmitAttributed ¶
func (s *DetectionSink) EmitAttributed(ctx context.Context, value detection.Detection, attribution fleetagent.DetectionAttribution) error
EmitAttributed creates a v2 spool record only for sources that possess actual transport facts. The current DetectionSensor API does not expose those facts, so its ordinary Emit path remains v1 rather than fabricating causal coordinates from a host or timestamp.
func (*DetectionSink) SetRedactionPolicy ¶
func (s *DetectionSink) SetRedactionPolicy(p privacy.Policy) error
SetRedactionPolicy overrides the source-side redaction policy applied to detection evidence (A6, #627). The sink defaults to privacy.DefaultPolicy(); an invalid policy is rejected so evidence is never shipped with a broken (fail-open) redaction config.
type DurableSensor ¶
type DurableSensor struct {
// contains filtered or unexported fields
}
DurableSensor tees every decoded event through Normalize and the WAL before exposing it to the detection engine. This ordering means a confirmed detection never references a raw event which was silently discarded first.
func NewDurableSensor ¶
func NewDurableSensor(source ports.DetectionSensor, durable ports.TelemetrySpool, identity SensorIdentity) (*DurableSensor, error)
NewDurableSensor validates dependencies and returns a sensor wrapper. A zero-buffer output intentionally propagates pressure back to the kernel reader rather than growing an unbounded second queue in memory.
func (*DurableSensor) Close ¶
func (s *DurableSensor) Close() error
func (*DurableSensor) Coverage ¶
func (s *DurableSensor) Coverage() []detection.ClassCoverage
func (*DurableSensor) Events ¶
func (s *DurableSensor) Events() <-chan detection.Event
func (*DurableSensor) SetProcessLifecycleObserver ¶
func (s *DurableSensor) SetProcessLifecycleObserver(observer ProcessLifecycleObserver) error
SetProcessLifecycleObserver wires the descriptor-pinning boundary before the sensor starts. The observer is invoked only after the telemetry WAL accepts the event, so response can never target identity that lacks durable telemetry.
func (*DurableSensor) SetRedactionPolicy ¶
func (s *DurableSensor) SetRedactionPolicy(p privacy.Policy) error
SetRedactionPolicy overrides the source-side redaction policy (A6, #627). A DurableSensor is created with privacy.DefaultPolicy(); an operator/tenant policy is applied here before Start. An invalid policy is rejected so the sensor never ships with a broken (fail-open) redaction config.
type ProcessLifecycleObserver ¶
type ProcessLifecycleObserver interface {
ObserveProcess(assetID, bootID shared.ID, event detection.ProcessEvent)
}
ProcessLifecycleObserver receives process identity only after the matching canonical telemetry envelope is durable in the local WAL.
type ProcessLifecycleTimestampObserver ¶
type ProcessLifecycleTimestampObserver interface {
ObserveProcessAt(assetID, bootID shared.ID, observedAt time.Time, event detection.ProcessEvent)
}
ProcessLifecycleTimestampObserver preserves the local sensor timestamp for consumers that need to bound post-condition observation windows.
type SensorIdentity ¶
type SensorIdentity struct {
AgentID shared.ID
AssetID shared.ID
AgentSession shared.ID
BootID shared.ID
SensorID string
SensorVersion string
}
SensorIdentity contains the stable attribution needed to turn the legacy detection sensor's decoded event into A1's canonical envelope.