coordinator

package
v0.16.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 4, 2026 License: Apache-2.0 Imports: 45 Imported by: 0

Documentation

Overview

Package coordinator wires the coordinator role: state collection, the spool and writer session, cluster rule evaluation, findings, the node agent API, and the local administration socket.

Index

Constants

View Source
const (
	EnvPodName        = "POD_NAME"
	EnvPodNamespace   = "POD_NAMESPACE"
	EnvNodeNamespace  = "EXITMESH_NODE_NAMESPACE"
	EnvNodeSA         = "EXITMESH_NODE_SERVICE_ACCOUNT"
	DefaultNodeNS     = "exitmesh-node"
	DefaultNodeSA     = "exitmesh-node"
	ClaimTemplateName = "data"
)

Environment variables read by the coordinator.

View Source
const (
	RuleSpoolPressure = "agent.spool_pressure"
	CategoryAgent     = "agent"
	NoBundle          = "none"
)

Reserved rule identity of the coordinator's own findings.

Variables

View Source
var Version = "dev"

Version is the agent version reported in hello, health, and enrollment.

Functions

func Run

func Run(ctx context.Context, cfg *config.Config, log *slog.Logger) error

Run builds the in-cluster dependencies and runs the coordinator until ctx ends.

Types

type Coordinator

type Coordinator struct {
	// contains filtered or unexported fields
}

Coordinator is one coordinator process.

func New

func New(cfg *config.Config, d Deps) (*Coordinator, error)

New validates the configuration and prepares a coordinator; Run opens the spool and starts it.

func (*Coordinator) NodeAPIAddr

func (c *Coordinator) NodeAPIAddr() string

NodeAPIAddr returns the node API listen address once Ready is closed.

func (*Coordinator) Ready

func (c *Coordinator) Ready() <-chan struct{}

Ready is closed once the state is synchronized and the node API listens.

func (*Coordinator) Run

func (c *Coordinator) Run(ctx context.Context) (err error)

Run starts the coordinator and blocks until ctx ends, a fatal error occurs, or the writer must stop.

type Deps

type Deps struct {
	Dynamic   dynamic.Interface
	Metadata  metadata.Interface
	Discovery discovery.DiscoveryInterface
	Kube      kubernetes.Interface
	// Roots overrides the trust roots from cfg.Trust.
	Roots *bundle.Roots
	Clock func() time.Time
	// Tunnel is the base tunnel configuration; Endpoint and CAFile default to cfg, Credential is set here.
	Tunnel tunnel.Options
	// APIServer and JWKSClient reach issuer discovery and /openid/v1/jwks for node token validation.
	APIServer  string
	JWKSClient *http.Client
	Logger     *slog.Logger
	Getenv     func(string) string
	// LookbackClient reaches configured lookback sources; nil uses the default transport.
	LookbackClient *http.Client
	Tuning         Tuning
}

Deps injects the external dependencies; Run builds the real ones.

type Health

type Health struct {
	Role        string            `json:"role"`
	Version     string            `json:"version"`
	Time        time.Time         `json:"time"`
	TargetID    string            `json:"target_id"`
	WriterID    string            `json:"writer_id"`
	Incarnation uint64            `json:"incarnation"`
	AirGap      bool              `json:"airgap"`
	Session     sessionHealth     `json:"session"`
	Spool       spoolHealth       `json:"spool"`
	Bundle      bundleView        `json:"bundle"`
	Rules       []ruleHealth      `json:"rules"`
	Nodes       []NodeStatus      `json:"nodes"`
	Placement   placementReport   `json:"storage_placement"`
	Chain       chainHealth       `json:"chain"`
	Coverage    []scopeHealth     `json:"coverage"`
	Unsupported []string          `json:"unsupported_resources,omitempty"`
	Security    securityHealth    `json:"security"`
	Findings    findingsHealth    `json:"findings"`
	Errors      map[string]string `json:"errors,omitempty"`
	// NodeRules rolls the node-local rule states of covered node agents up per rule version.
	NodeRules          []nodeRuleRollup `json:"node_rules,omitempty"`
	NodeRulesTruncated int              `json:"node_rules_truncated,omitempty"`
}

Health is the agent health record (PRD 8.1).

type NodeRule

type NodeRule struct {
	ID              string    `json:"id"`
	Version         int       `json:"version"`
	State           string    `json:"state"`
	Reason          string    `json:"reason,omitempty"`
	LastEval        time.Time `json:"last_eval,omitempty"`
	BudgetLimited   bool      `json:"budget_limited,omitempty"`
	EvidenceLimited bool      `json:"evidence_limited,omitempty"`
}

NodeRule is one node-local rule state as the node agent last registered it.

type NodeStatus

type NodeStatus struct {
	Name          string             `json:"name"`
	AgentVersion  string             `json:"agent_version"`
	BundleVersion string             `json:"bundle_version"`
	Capabilities  []string           `json:"capabilities,omitempty"`
	Coverage      map[string]string  `json:"coverage,omitempty"`
	Warming       bool               `json:"warming"`
	Queue         nodeapi.QueueUsage `json:"queue"`
	FirstSeen     time.Time          `json:"first_seen"`
	LastSeen      time.Time          `json:"last_seen"`
	LastSubmit    time.Time          `json:"last_submit,omitempty"`
	Covered       bool               `json:"covered"`
	// PartVersions is the bundle version of the latest part each cluster rule received from the node.
	PartVersions map[string]string `json:"part_versions,omitempty"`
	// FactsDropped counts pod metric facts not applied because the observed pod no longer exists on the node.
	FactsDropped uint64 `json:"facts_dropped,omitempty"`
	// Rules are the node's latest rule states other than plain active ones, most severe first, at most maxNodeRuleDetail.
	Rules []NodeRule `json:"rules,omitempty"`
	// RuleStates counts the node's rules per state.
	RuleStates map[string]int `json:"rule_states,omitempty"`
	// Process is the node agent's user and effective capabilities; UID 0 means the root fallback is in use.
	Process *nodeapi.Process `json:"process,omitempty"`
	// contains filtered or unexported fields
}

NodeStatus is the coordinator's view of one node agent.

type Tuning

type Tuning struct {
	EvalInterval   time.Duration // rule evaluation cycle, default 15s
	SnapshotEvery  time.Duration // recovery snapshot refresh throttle, default 5s
	AnchorDeltas   int           // deltas after which a periodic anchor is due, default 5000
	AnchorEvery    time.Duration // maximum time between anchors while connected, default 6h
	NodeTimeout    time.Duration // a node not seen for this long is uncovered, default 3m
	HousekeepEvery time.Duration // pressure, commit, and resync checks, default 5s
	PressureWarmup time.Duration // uptime before the projected window counts toward spool pressure, default 15m
	ExportEvery    time.Duration // air-gap export cadence, default 1m
	BundleEvery    time.Duration // bundle fetch retry and air-gap directory poll, default 1m
	RetryBase      time.Duration // enrollment retry base, default 2s
	BackoffBase    time.Duration // session reconnect backoff base, default 1s
	BackoffMax     time.Duration // default and maximum 5m
	HealthInterval time.Duration // agent.health cadence, default 60s
	LongPollMax    time.Duration // node API long-poll bound, default nodeapi.DefaultLongPollMax
	FlushInterval  time.Duration // collector event flush, default 30s
	CollectorRetry time.Duration // collector retry base after access failures; zero keeps the collector default
	// ReflectorBackoff overrides the collector's watch restart backoff.
	ReflectorBackoff *wait.Backoff
}

Tuning holds intervals and thresholds; zero fields take the defaults.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL