internal/

directory
v0.16.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 4, 2026 License: Apache-2.0

Directories

Path Synopsis
Package admin is the local unix-socket administration API used by the CLI while the agent holds its lock.
Package admin is the local unix-socket administration API used by the CLI while the agent holds its lock.
Package config loads and validates the agent configuration file (docs/configuration.md).
Package config loads and validates the agent configuration file (docs/configuration.md).
Package coordinator wires the coordinator role: state collection, the spool and writer session, cluster rule evaluation, findings, the node agent API, and the local administration socket.
Package coordinator wires the coordinator role: state collection, the spool and writer session, cluster rule evaluation, findings, the node agent API, and the local administration socket.
Package deploytest renders the Helm chart and checks the repository's deployment, packaging, and CI assets.
Package deploytest renders the Helm chart and checks the repository's deployment, packaging, and CI assets.
releaseinfo command
Command releaseinfo prints the protocol, schema, and rule engine versions for release notes as KEY=VALUE lines.
Command releaseinfo prints the protocol, schema, and rule engine versions for release notes as KEY=VALUE lines.
Package findings turns rule and query observations into finding episodes and records (PRD 7.7).
Package findings turns rule and query observations into finding episodes and records (PRD 7.7).
Package host runs the host role: node agent and coordinator in one process on a Linux host without Kubernetes.
Package host runs the host role: node agent and coordinator in one process on a Linux host without Kubernetes.
Package hostfacts collects normalized Linux host state, reports per-fact availability, and tracks it as protocol ops.
Package hostfacts collects normalized Linux host state, reports per-fact availability, and tracks it as protocol ops.
journal
Package journal is a pure-Go, read-only reader of the systemd journal file format.
Package journal is a pure-Go, read-only reader of the systemd journal file format.
nodemetrics
Package nodemetrics runs upstream node_exporter collectors in process so node_* series and upstream rules work unchanged.
Package nodemetrics runs upstream node_exporter collectors in process so node_* series and upstream rules work unchanged.
sqlitedb
Package sqlitedb reads rowid tables of SQLite files (with committed WAL frames) in pure Go and serves them to go-rpmdb as a database/sql driver.
Package sqlitedb reads rowid tables of SQLite files (with committed WAL frames) in pure Go and serves them to go-rpmdb as a database/sql driver.
Package investigate serves bounded live and lookback investigation tools with AST scope injection (docs/investigation.md).
Package investigate serves bounded live and lookback investigation tools with AST scope injection (docs/investigation.md).
Package kv is the small durable key-value store used for agent metadata: alert state, log offsets, bundle state, key manifest sequence, cursors.
Package kv is the small durable key-value store used for agent metadata: alert state, log offsets, bundle state, key manifest sequence, cursors.
Package node wires the node agent role: scrape, logs, rules, findings, and delivery to the coordinator.
Package node wires the node agent role: scrape, logs, rules, findings, and delivery to the coordinator.
Package nodeapi implements the in-cluster HTTPS API between node agents and the coordinator (docs/architecture.md).
Package nodeapi implements the in-cluster HTTPS API between node agents and the coordinator (docs/architecture.md).
Package privdrop re-executes the process as an unprivileged user that keeps selected capabilities as ambient capabilities.
Package privdrop re-executes the process as an unprivileged user that keeps selected capabilities as ambient capabilities.
Package redact removes secret-looking values from text before it reaches evidence rings, spools, transmission, or diagnostics (PRD L6, 10).
Package redact removes secret-looking values from text before it reaches evidence rings, spools, transmission, or diagnostics (PRD L6, 10).
rules
bundle
Package bundle defines the rule bundle format (docs/bundle-format.md): parsing, validation, signature and key manifest verification.
Package bundle defines the rule bundle format (docs/bundle-format.md): parsing, validation, signature and key manifest verification.
engine
Package engine evaluates CEL state rules and PromQL and LogQL alerting rules (docs/promql-rules.md).
Package engine evaluates CEL state rules and PromQL and LogQL alerting rules (docs/promql-rules.md).
logql
Package logql implements the LogQL subset published in docs/logql-subset.md without Loki code.
Package logql implements the LogQL subset published in docs/logql-subset.md without Loki code.
validators
Package validators builds the bundle validators backed by the real rule engines.
Package validators builds the bundle validators backed by the real rule engines.
Package rulesdefault serves the default ExitMesh rule bundle sources embedded from rules/ and builds their archives.
Package rulesdefault serves the default ExitMesh rule bundle sources embedded from rules/ and builds their archives.
Package spool is the writer's durable record store, the node agent queue, and directory locks.
Package spool is the writer's durable record store, the node agent queue, and directory locks.
Package state normalizes Kubernetes objects into protocol state, edges, scopes, and kube_* series.
Package state normalizes Kubernetes objects into protocol state, edges, scopes, and kube_* series.
telemetry
disk
Package disk enforces the state directory cap by shrinking the TSDB first and reporting pressure.
Package disk enforces the state directory cap by shrinking the TSDB first and reporting pressure.
evidence
Package evidence holds redacted matched lines under a per-node byte ceiling split into rule shares.
Package evidence holds redacted matched lines under a per-node byte ceiling split into rule shares.
logs
Package logs tails container and host log files per the contract in docs/log-contract.md.
Package logs tails container and host log files per the contract in docs/log-contract.md.
metricfacts
Package metricfacts summarizes local series into per-resource facts and change thresholds.
Package metricfacts summarizes local series into per-resource facts and change thresholds.
scrape
Package scrape is the agent's own scrape loop with per-node budgets, staleness, and coverage status.
Package scrape is the agent's own scrape loop with per-node budgets, staleness, and coverage status.
tsdb
Package tsdb wraps the Prometheus TSDB with rule-derived retention, a size ceiling, and pressure shrinking.
Package tsdb wraps the Prometheus TSDB with rule-derived retention, a size ceiling, and pressure shrinking.
Package tunnel implements the WebSocket tunnel binding (SPEC 9) and the enrollment client.
Package tunnel implements the WebSocket tunnel binding (SPEC 9) and the enrollment client.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL