Directories
¶
| Path | Synopsis |
|---|---|
|
Package admin is the local unix-socket administration API used by the CLI while the agent holds its lock.
|
Package admin is the local unix-socket administration API used by the CLI while the agent holds its lock. |
|
Package config loads and validates the agent configuration file (docs/configuration.md).
|
Package config loads and validates the agent configuration file (docs/configuration.md). |
|
Package coordinator wires the coordinator role: state collection, the spool and writer session, cluster rule evaluation, findings, the node agent API, and the local administration socket.
|
Package coordinator wires the coordinator role: state collection, the spool and writer session, cluster rule evaluation, findings, the node agent API, and the local administration socket. |
|
Package deploytest renders the Helm chart and checks the repository's deployment, packaging, and CI assets.
|
Package deploytest renders the Helm chart and checks the repository's deployment, packaging, and CI assets. |
|
releaseinfo
command
Command releaseinfo prints the protocol, schema, and rule engine versions for release notes as KEY=VALUE lines.
|
Command releaseinfo prints the protocol, schema, and rule engine versions for release notes as KEY=VALUE lines. |
|
Package findings turns rule and query observations into finding episodes and records (PRD 7.7).
|
Package findings turns rule and query observations into finding episodes and records (PRD 7.7). |
|
Package host runs the host role: node agent and coordinator in one process on a Linux host without Kubernetes.
|
Package host runs the host role: node agent and coordinator in one process on a Linux host without Kubernetes. |
|
Package hostfacts collects normalized Linux host state, reports per-fact availability, and tracks it as protocol ops.
|
Package hostfacts collects normalized Linux host state, reports per-fact availability, and tracks it as protocol ops. |
|
journal
Package journal is a pure-Go, read-only reader of the systemd journal file format.
|
Package journal is a pure-Go, read-only reader of the systemd journal file format. |
|
nodemetrics
Package nodemetrics runs upstream node_exporter collectors in process so node_* series and upstream rules work unchanged.
|
Package nodemetrics runs upstream node_exporter collectors in process so node_* series and upstream rules work unchanged. |
|
sqlitedb
Package sqlitedb reads rowid tables of SQLite files (with committed WAL frames) in pure Go and serves them to go-rpmdb as a database/sql driver.
|
Package sqlitedb reads rowid tables of SQLite files (with committed WAL frames) in pure Go and serves them to go-rpmdb as a database/sql driver. |
|
Package investigate serves bounded live and lookback investigation tools with AST scope injection (docs/investigation.md).
|
Package investigate serves bounded live and lookback investigation tools with AST scope injection (docs/investigation.md). |
|
Package kv is the small durable key-value store used for agent metadata: alert state, log offsets, bundle state, key manifest sequence, cursors.
|
Package kv is the small durable key-value store used for agent metadata: alert state, log offsets, bundle state, key manifest sequence, cursors. |
|
Package node wires the node agent role: scrape, logs, rules, findings, and delivery to the coordinator.
|
Package node wires the node agent role: scrape, logs, rules, findings, and delivery to the coordinator. |
|
Package nodeapi implements the in-cluster HTTPS API between node agents and the coordinator (docs/architecture.md).
|
Package nodeapi implements the in-cluster HTTPS API between node agents and the coordinator (docs/architecture.md). |
|
Package privdrop re-executes the process as an unprivileged user that keeps selected capabilities as ambient capabilities.
|
Package privdrop re-executes the process as an unprivileged user that keeps selected capabilities as ambient capabilities. |
|
Package redact removes secret-looking values from text before it reaches evidence rings, spools, transmission, or diagnostics (PRD L6, 10).
|
Package redact removes secret-looking values from text before it reaches evidence rings, spools, transmission, or diagnostics (PRD L6, 10). |
|
rules
|
|
|
bundle
Package bundle defines the rule bundle format (docs/bundle-format.md): parsing, validation, signature and key manifest verification.
|
Package bundle defines the rule bundle format (docs/bundle-format.md): parsing, validation, signature and key manifest verification. |
|
engine
Package engine evaluates CEL state rules and PromQL and LogQL alerting rules (docs/promql-rules.md).
|
Package engine evaluates CEL state rules and PromQL and LogQL alerting rules (docs/promql-rules.md). |
|
logql
Package logql implements the LogQL subset published in docs/logql-subset.md without Loki code.
|
Package logql implements the LogQL subset published in docs/logql-subset.md without Loki code. |
|
validators
Package validators builds the bundle validators backed by the real rule engines.
|
Package validators builds the bundle validators backed by the real rule engines. |
|
Package rulesdefault serves the default ExitMesh rule bundle sources embedded from rules/ and builds their archives.
|
Package rulesdefault serves the default ExitMesh rule bundle sources embedded from rules/ and builds their archives. |
|
Package spool is the writer's durable record store, the node agent queue, and directory locks.
|
Package spool is the writer's durable record store, the node agent queue, and directory locks. |
|
Package state normalizes Kubernetes objects into protocol state, edges, scopes, and kube_* series.
|
Package state normalizes Kubernetes objects into protocol state, edges, scopes, and kube_* series. |
|
telemetry
|
|
|
disk
Package disk enforces the state directory cap by shrinking the TSDB first and reporting pressure.
|
Package disk enforces the state directory cap by shrinking the TSDB first and reporting pressure. |
|
evidence
Package evidence holds redacted matched lines under a per-node byte ceiling split into rule shares.
|
Package evidence holds redacted matched lines under a per-node byte ceiling split into rule shares. |
|
logs
Package logs tails container and host log files per the contract in docs/log-contract.md.
|
Package logs tails container and host log files per the contract in docs/log-contract.md. |
|
metricfacts
Package metricfacts summarizes local series into per-resource facts and change thresholds.
|
Package metricfacts summarizes local series into per-resource facts and change thresholds. |
|
scrape
Package scrape is the agent's own scrape loop with per-node budgets, staleness, and coverage status.
|
Package scrape is the agent's own scrape loop with per-node budgets, staleness, and coverage status. |
|
tsdb
Package tsdb wraps the Prometheus TSDB with rule-derived retention, a size ceiling, and pressure shrinking.
|
Package tsdb wraps the Prometheus TSDB with rule-derived retention, a size ceiling, and pressure shrinking. |
|
Package tunnel implements the WebSocket tunnel binding (SPEC 9) and the enrollment client.
|
Package tunnel implements the WebSocket tunnel binding (SPEC 9) and the enrollment client. |
Click to show internal directories.
Click to hide internal directories.