Documentation
¶
Overview ¶
Package coordinator wires the coordinator role: state collection, the spool and writer session, cluster rule evaluation, findings, the node agent API, and the local administration socket.
Index ¶
Constants ¶
const ( EnvPodName = "POD_NAME" EnvPodNamespace = "POD_NAMESPACE" EnvNodeNamespace = "EXITMESH_NODE_NAMESPACE" EnvNodeSA = "EXITMESH_NODE_SERVICE_ACCOUNT" DefaultNodeNS = "exitmesh-node" DefaultNodeSA = "exitmesh-node" ClaimTemplateName = "data" )
Environment variables read by the coordinator.
const ( RuleSpoolPressure = "agent.spool_pressure" CategoryAgent = "agent" NoBundle = "none" )
Reserved rule identity of the coordinator's own findings.
Variables ¶
var Version = "dev"
Version is the agent version reported in hello, health, and enrollment.
Functions ¶
Types ¶
type Coordinator ¶
type Coordinator struct {
// contains filtered or unexported fields
}
Coordinator is one coordinator process.
func New ¶
func New(cfg *config.Config, d Deps) (*Coordinator, error)
New validates the configuration and prepares a coordinator; Run opens the spool and starts it.
func (*Coordinator) NodeAPIAddr ¶
func (c *Coordinator) NodeAPIAddr() string
NodeAPIAddr returns the node API listen address once Ready is closed.
func (*Coordinator) Ready ¶
func (c *Coordinator) Ready() <-chan struct{}
Ready is closed once the state is synchronized and the node API listens.
type Deps ¶
type Deps struct {
Dynamic dynamic.Interface
Metadata metadata.Interface
Discovery discovery.DiscoveryInterface
Kube kubernetes.Interface
// Roots overrides the trust roots from cfg.Trust.
Roots *bundle.Roots
Clock func() time.Time
// Tunnel is the base tunnel configuration; Endpoint and CAFile default to cfg, Credential is set here.
Tunnel tunnel.Options
// APIServer and JWKSClient reach issuer discovery and /openid/v1/jwks for node token validation.
APIServer string
JWKSClient *http.Client
Logger *slog.Logger
Getenv func(string) string
// LookbackClient reaches configured lookback sources; nil uses the default transport.
LookbackClient *http.Client
Tuning Tuning
}
Deps injects the external dependencies; Run builds the real ones.
type Health ¶
type Health struct {
Role string `json:"role"`
Version string `json:"version"`
Time time.Time `json:"time"`
TargetID string `json:"target_id"`
WriterID string `json:"writer_id"`
Incarnation uint64 `json:"incarnation"`
AirGap bool `json:"airgap"`
Session sessionHealth `json:"session"`
Spool spoolHealth `json:"spool"`
Bundle bundleView `json:"bundle"`
Rules []ruleHealth `json:"rules"`
Nodes []NodeStatus `json:"nodes"`
Placement placementReport `json:"storage_placement"`
Chain chainHealth `json:"chain"`
Coverage []scopeHealth `json:"coverage"`
Unsupported []string `json:"unsupported_resources,omitempty"`
Security securityHealth `json:"security"`
Findings findingsHealth `json:"findings"`
Errors map[string]string `json:"errors,omitempty"`
// NodeRules rolls the node-local rule states of covered node agents up per rule version.
NodeRules []nodeRuleRollup `json:"node_rules,omitempty"`
NodeRulesTruncated int `json:"node_rules_truncated,omitempty"`
}
Health is the agent health record (PRD 8.1).
type NodeRule ¶
type NodeRule struct {
ID string `json:"id"`
Version int `json:"version"`
State string `json:"state"`
Reason string `json:"reason,omitempty"`
LastEval time.Time `json:"last_eval,omitempty"`
BudgetLimited bool `json:"budget_limited,omitempty"`
EvidenceLimited bool `json:"evidence_limited,omitempty"`
}
NodeRule is one node-local rule state as the node agent last registered it.
type NodeStatus ¶
type NodeStatus struct {
Name string `json:"name"`
AgentVersion string `json:"agent_version"`
BundleVersion string `json:"bundle_version"`
Capabilities []string `json:"capabilities,omitempty"`
Coverage map[string]string `json:"coverage,omitempty"`
Warming bool `json:"warming"`
Queue nodeapi.QueueUsage `json:"queue"`
FirstSeen time.Time `json:"first_seen"`
LastSeen time.Time `json:"last_seen"`
LastSubmit time.Time `json:"last_submit,omitempty"`
Covered bool `json:"covered"`
// PartVersions is the bundle version of the latest part each cluster rule received from the node.
PartVersions map[string]string `json:"part_versions,omitempty"`
// FactsDropped counts pod metric facts not applied because the observed pod no longer exists on the node.
FactsDropped uint64 `json:"facts_dropped,omitempty"`
// Rules are the node's latest rule states other than plain active ones, most severe first, at most maxNodeRuleDetail.
Rules []NodeRule `json:"rules,omitempty"`
// RuleStates counts the node's rules per state.
RuleStates map[string]int `json:"rule_states,omitempty"`
// Process is the node agent's user and effective capabilities; UID 0 means the root fallback is in use.
Process *nodeapi.Process `json:"process,omitempty"`
// contains filtered or unexported fields
}
NodeStatus is the coordinator's view of one node agent.
type Tuning ¶
type Tuning struct {
EvalInterval time.Duration // rule evaluation cycle, default 15s
SnapshotEvery time.Duration // recovery snapshot refresh throttle, default 5s
AnchorDeltas int // deltas after which a periodic anchor is due, default 5000
AnchorEvery time.Duration // maximum time between anchors while connected, default 6h
NodeTimeout time.Duration // a node not seen for this long is uncovered, default 3m
HousekeepEvery time.Duration // pressure, commit, and resync checks, default 5s
PressureWarmup time.Duration // uptime before the projected window counts toward spool pressure, default 15m
ExportEvery time.Duration // air-gap export cadence, default 1m
BundleEvery time.Duration // bundle fetch retry and air-gap directory poll, default 1m
RetryBase time.Duration // enrollment retry base, default 2s
BackoffBase time.Duration // session reconnect backoff base, default 1s
BackoffMax time.Duration // default and maximum 5m
HealthInterval time.Duration // agent.health cadence, default 60s
LongPollMax time.Duration // node API long-poll bound, default nodeapi.DefaultLongPollMax
FlushInterval time.Duration // collector event flush, default 30s
CollectorRetry time.Duration // collector retry base after access failures; zero keeps the collector default
// ReflectorBackoff overrides the collector's watch restart backoff.
ReflectorBackoff *wait.Backoff
}
Tuning holds intervals and thresholds; zero fields take the defaults.