node

package
v0.11.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 2, 2026 License: Apache-2.0 Imports: 57 Imported by: 0

Documentation

Overview

Package node wires the node agent role: scrape, logs, rules, findings, and delivery to the coordinator.

Index

Constants

This section is empty.

Variables

View Source
var Version string

Version is the agent release version, set by the binary from its build flags.

Functions

func Run

func Run(ctx context.Context, cfg *config.Config, log *slog.Logger) error

Run starts a node agent with in-cluster dependencies until ctx ends.

Types

type Agent

type Agent struct {
	// contains filtered or unexported fields
}

Agent is one node agent.

func New

func New(cfg *config.Config, d Deps) (*Agent, error)

New validates cfg and prepares an agent; Run opens the state directory.

func (*Agent) Run

func (a *Agent) Run(ctx context.Context) error

Run opens the state directory and runs every loop until ctx ends, then shuts down gracefully.

func (*Agent) Status

func (a *Agent) Status() Status

Status reports the agent's state; it is only meaningful while Run is active.

type Deps

type Deps struct {
	Kube kubernetes.Interface
	// Roots overrides the trust roots from cfg.Trust.
	Roots  *bundle.Roots
	Clock  func() time.Time
	NodeIP string
	// PodName is the agent's own pod, whose log streams are never tailed.
	PodName string
	// KubeletURL overrides https://NODE_IP:kubeletPort.
	KubeletURL       string
	KubeletTokenFile string
	KubeletCAFile    string
	// Coordinator fields left zero are filled from cfg.Coordinator.
	Coordinator  nodeapi.ClientOptions
	Executor     TaskExecutor
	AgentVersion string
	// Process overrides the identity read from /proc/self/status.
	Process *privdrop.Identity
	Logger  *slog.Logger
	Timing  Timing
}

Deps injects the external dependencies of an Agent.

type Status

type Status struct {
	Node          string
	AgentVersion  string
	Process       nodeapi.Process
	BundleVersion string
	TargetBundle  string
	BundleError   string
	Warming       bool
	Coverage      map[string]string
	Rules         []engine.RuleState
	Queue         spool.QueueUsage
	Acked         uint64
	Dropped       string
	DeliveryError string
	OpenFindings  int
	Disk          disk.Report
	TSDB          tsdb.Stats
	Targets       []scrape.TargetStatus
	Logs          logs.Stats
	Evidence      evidence.Stats
}

Status is a snapshot of a running agent.

type TaskExecutor

type TaskExecutor interface {
	Execute(ctx context.Context, t nodeapi.Task) nodeapi.TaskResult
}

TaskExecutor runs coordinator investigation tasks against local telemetry.

type Timing

type Timing struct {
	EvalTick      time.Duration // how often due rules are checked (default 1s)
	Register      time.Duration // default 30s
	Facts         time.Duration // metric facts interval (default 60s)
	KubeRefresh   time.Duration // re-stamping of kube_* series (default 60s)
	DiskCheck     time.Duration // default 30s
	RetryMin      time.Duration // delivery backoff start (default 1s)
	RetryMax      time.Duration // delivery backoff ceiling (default 30s)
	TSDBBlock     time.Duration // TSDB block duration (default tsdb.DefaultBlockDuration)
	TSDBWALBytes  int           // TSDB WAL segment size (default tsdb.DefaultWALSegmentBytes)
	LogPoll       time.Duration // default logs.DefaultPollInterval
	LogCheckpoint time.Duration // default logs.DefaultCheckpointInterval
}

Timing holds loop cadences; zero values take the defaults.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL