Documentation
¶
Overview ¶
Package config loads and validates the agent configuration file (docs/configuration.md).
Index ¶
Constants ¶
const ( RoleNode = "node" RoleCoordinator = "coordinator" RoleHost = "host" )
Roles.
const ( CapInventory = "inventory" CapMetrics = "metrics" CapLogs = "logs" )
Capabilities.
const ( SourcePrometheus = "prometheus" SourceMimir = "mimir" SourceVictoriaMetrics = "victoriametrics" SourceLoki = "loki" SourceVictoriaLogs = "victorialogs" )
Lookback source types (PRD I6a, I6b).
Variables ¶
This section is empty.
Functions ¶
func ParseBytes ¶
ParseBytes parses a size such as 16Mi or 1G.
Types ¶
type AirGap ¶
type AirGap struct {
Enabled bool `yaml:"enabled"`
BundleDir string `yaml:"bundleDir"`
ExportDir string `yaml:"exportDir"`
}
AirGap configures the air-gap profile (PRD A9).
type Config ¶
type Config struct {
Role string `yaml:"role"`
Endpoint string `yaml:"endpoint"`
EndpointCAFile string `yaml:"endpointCAFile"`
EnrollmentTokenFile string `yaml:"enrollmentTokenFile"`
StateDir string `yaml:"stateDir"`
Capabilities []string `yaml:"capabilities"`
Kubernetes Kubernetes `yaml:"kubernetes"`
Coordinator Coordinator `yaml:"coordinator"`
Spool Spool `yaml:"spool"`
Node Node `yaml:"node"`
Host Host `yaml:"host"`
Lookback []Lookback `yaml:"lookback"`
AirGap AirGap `yaml:"airgap"`
Trust Trust `yaml:"trust"`
Policy Policy `yaml:"policy"`
Investigation Investigation `yaml:"investigation"`
Logging Logging `yaml:"logging"`
}
Config is the full agent configuration.
func (*Config) ApplyDefaults ¶
func (c *Config) ApplyDefaults()
ApplyDefaults fills unset fields with the proposed defaults of PRD 8.2 and H15.
func (*Config) HasCapability ¶
HasCapability reports whether cap is enabled.
type Coordinator ¶
type Coordinator struct {
Listen string `yaml:"listen"`
TLSCertFile string `yaml:"tlsCertFile"`
TLSKeyFile string `yaml:"tlsKeyFile"`
ServiceURL string `yaml:"serviceURL"`
CAFile string `yaml:"caFile"`
Audience string `yaml:"audience"`
TokenFile string `yaml:"tokenFile"`
Namespace string `yaml:"namespace"`
PodName string `yaml:"podName"`
}
Coordinator configures the coordinator listener and the node side of the node API.
type Host ¶
type Host struct {
DiskCap Bytes `yaml:"diskCap"`
SpoolReserve Bytes `yaml:"spoolReserve"`
TSDBMax Bytes `yaml:"tsdbMax"`
EvidenceRing Bytes `yaml:"evidenceRing"`
ScrapeInterval Duration `yaml:"scrapeInterval"`
LogFiles []string `yaml:"logFiles"`
Journal bool `yaml:"journal"`
JournalDir string `yaml:"journalDir"`
MetricsEndpoints []string `yaml:"metricsEndpoints"`
AllowNonLoopback bool `yaml:"allowNonLoopback"`
}
Host configures host mode (PRD 7.10).
type Investigation ¶
type Investigation struct {
MaxConcurrency int `yaml:"maxConcurrency"`
Timeout Duration `yaml:"timeout"`
MaxBytes Bytes `yaml:"maxBytes"`
MaxLines int `yaml:"maxLines"`
MaxSeries int `yaml:"maxSeries"`
MaxSamples int `yaml:"maxSamples"`
MaxWindow Duration `yaml:"maxWindow"`
}
Investigation bounds live queries (PRD I3).
type Kubernetes ¶
type Kubernetes struct {
Scope string `yaml:"scope"`
Namespaces []string `yaml:"namespaces"`
ExcludeNamespaces []string `yaml:"excludeNamespaces"`
LabelAllowlist []string `yaml:"labelAllowlist"`
AnnotationAllowlist []string `yaml:"annotationAllowlist"`
Resources []string `yaml:"resources"`
ClusterName string `yaml:"clusterName"`
}
Kubernetes configures collection scope (PRD A3, 7.2).
type Lookback ¶
type Lookback struct {
Name string `yaml:"name"`
Type string `yaml:"type"`
URL string `yaml:"url"`
Tenant string `yaml:"tenant"`
AccountID string `yaml:"accountID"`
ProjectID string `yaml:"projectID"`
BearerTokenFile string `yaml:"bearerTokenFile"`
BasicUsernameFile string `yaml:"basicUsernameFile"`
BasicPasswordFile string `yaml:"basicPasswordFile"`
CAFile string `yaml:"caFile"`
Timeout Duration `yaml:"timeout"`
Retention Duration `yaml:"retention"`
}
Lookback is one optional read-only external store (PRD I6).
type Node ¶
type Node struct {
Name string `yaml:"name"`
DiskCap Bytes `yaml:"diskCap"`
EvidenceRing Bytes `yaml:"evidenceRing"`
LogsPath string `yaml:"logsPath"`
ScrapeInterval Duration `yaml:"scrapeInterval"`
MaxTargets int `yaml:"maxTargets"`
MaxSeries int `yaml:"maxSeries"`
MaxSamplesRate int `yaml:"maxSamplesPerSecond"`
KubeletTLS string `yaml:"kubeletTLS"`
KubeletPort int `yaml:"kubeletPort"`
}
Node configures a node agent (PRD 6.3, 7.6).
type Policy ¶
type Policy struct {
MaxRuleEvalTime Duration `yaml:"maxRuleEvalTime"`
MaxRuleSamples int `yaml:"maxRuleSamples"`
MaxRuleSeries int `yaml:"maxRuleSeries"`
MaxCounterBytes Bytes `yaml:"maxCounterBytes"`
MaxEvidenceBytes Bytes `yaml:"maxEvidenceBytes"`
DisabledRules []string `yaml:"disabledRules"`
LateThreshold Duration `yaml:"lateThreshold"`
RedactionPatterns []string `yaml:"redactionPatterns"`
}
Policy is the local administrator upper bound on rules (PRD 7.5).
type Spool ¶
type Spool struct {
Capacity Bytes `yaml:"capacity"`
Window Bytes `yaml:"window"`
CoalesceAt float64 `yaml:"coalesceAt"`
}
Spool sizes the coordinator spool (PRD 8.2).
type Trust ¶
type Trust struct {
// Roots are "<id>:<base64 ed25519 public key>" entries.
Roots []string `yaml:"roots"`
RootsFile string `yaml:"rootsFile"`
Threshold int `yaml:"threshold"`
}
Trust is the public half of the ExitMesh workspace's agent trust root (PRD R2a), shown on the connector page.