engine

package
v0.2.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 30, 2026 License: Apache-2.0 Imports: 34 Imported by: 0

Documentation

Overview

Package engine evaluates CEL state rules and PromQL and LogQL alerting rules (docs/promql-rules.md).

Index

Constants

View Source
const (
	RoleNode        = "node"
	RoleCoordinator = "coordinator"
	RoleHost        = "host"
)

Roles decide which rules and which rule parts an engine evaluates.

View Source
const (
	TransitionFiring   = "firing"
	TransitionUpdate   = "update"
	TransitionResolved = "resolved"
	TransitionStale    = "stale"
)

Alert transitions carried by AlertEvent.

View Source
const (
	StateActive          = "active"
	StateUnsupported     = "unsupported"
	StateDisabled        = "disabled"
	StateStale           = "stale"
	StateWarmingUp       = "warming_up"
	StateFailed          = "failed"
	StateBudgetLimited   = "budget_limited"
	StateEvidenceLimited = "evidence_limited"
	StateConverging      = "converging"
)

Per-rule states (PRD R9).

View Source
const (
	SplitMetric      = "exitmesh_split"
	LabelRule        = "__exitmesh_rule__"
	LabelRuleVersion = "__exitmesh_rule_version__"
	LabelNode        = "__exitmesh_node__"
	LabelPart        = "__exitmesh_part__"
)

Labels used by pushed pre-aggregated series.

Variables

View Source
var DefaultBudget = bundle.Budget{
	MaxEvalTime:   10 * time.Second,
	MaxSamples:    1_000_000,
	MaxSeries:     1_000,
	MaxComplexity: 500,
}

DefaultBudget fills budget fields a rule leaves unset.

Functions

func ValidateCEL

func ValidateCEL(rule bundle.StateRule) error

ValidateCEL compiles a state rule and its label expressions and checks the complexity budget.

func ValidatePromQL

func ValidatePromQL(rule bundle.AlertRule, opts Options) error

ValidatePromQL checks grammar, complexity, the kube_* subset, and cluster decomposability.

Types

type AlertEvent

type AlertEvent struct {
	RuleID        string
	RuleVersion   int
	BundleVersion string
	Class         string
	Scope         string
	Transition    string
	// InstanceKey is the resource UID for state rules and the canonical label set otherwise.
	InstanceKey  string
	Labels       map[string]string
	Annotations  map[string]string
	Value        float64
	ActiveAt     time.Time
	FiredAt      time.Time
	ResolvedAt   time.Time
	EvalTime     time.Time
	ResourceUIDs []string
	Severity     string
	Category     string
	Summary      string
	// Incomplete is set when the evaluation behind the event did not see all of its inputs.
	Incomplete bool
}

AlertEvent is one alert instance transition emitted to the sink.

type BundleResult

type BundleResult struct {
	// Unsupported maps rule IDs to the reason they cannot run on this agent.
	Unsupported map[string]string
}

BundleResult carries per-rule outcomes of bundle validation performed before SetBundle.

type Coverage

type Coverage int

Coverage is the completeness of the telemetry a rule evaluates over.

const (
	CoverageCovered Coverage = iota
	CoverageWarming
	CoverageUncovered
	// CoverageConverging means some contributing nodes run another bundle version.
	CoverageConverging
)

func (Coverage) String

func (c Coverage) String() string

type Engine

type Engine struct {
	// contains filtered or unexported fields
}

Engine evaluates the rules of the active bundle in cycles.

func NewEngine

func NewEngine(opts Options) (*Engine, error)

NewEngine returns an engine and loads persisted alert state from opts.Store.

func (*Engine) BundleVersion

func (e *Engine) BundleVersion() string

BundleVersion returns the version of the active bundle.

func (*Engine) Evaluate

func (e *Engine) Evaluate(ctx context.Context, now time.Time) error

Evaluate runs one cycle at now over every rule whose interval is due.

func (*Engine) RuleStates

func (e *Engine) RuleStates() []RuleState

RuleStates returns the per-rule states as of the last cycle, ordered by rule ID.

func (*Engine) SetBundle

func (e *Engine) SetBundle(b *bundle.Bundle, res BundleResult) error

SetBundle compiles and stages b for the next cycle; an invalid bundle changes nothing.

type LogProgram

type LogProgram interface {
	Eval(ts time.Time) (promql.Vector, error)
}

LogProgram is a compiled LogQL rule expression evaluated over streaming counters.

type LogProgramFunc

type LogProgramFunc func(ts time.Time) (promql.Vector, error)

LogProgramFunc adapts a function to LogProgram.

func (LogProgramFunc) Eval

func (f LogProgramFunc) Eval(ts time.Time) (promql.Vector, error)

Eval calls f.

type MemSeries

type MemSeries struct {
	// contains filtered or unexported fields
}

MemSeries is an in-memory storage.Queryable fed per source; replaced-away series get staleness markers.

func NewMemSeries

func NewMemSeries(retention time.Duration, clock func() time.Time) *MemSeries

NewMemSeries returns an empty store keeping samples for retention (default 1h).

func (*MemSeries) Querier

func (m *MemSeries) Querier(mint, maxt int64) (storage.Querier, error)

Querier implements storage.Queryable.

func (*MemSeries) Replace

func (m *MemSeries) Replace(source string, series []Series)

Replace sets the current series of source. Series of source absent from series are marked stale.

func (*MemSeries) Sources

func (m *MemSeries) Sources() []string

Sources returns the names of sources currently holding series, sorted.

type Options

type Options struct {
	// Role is RoleNode, RoleCoordinator, or RoleHost (the default, which evaluates everything locally).
	Role  string
	Store kv.Store
	Clock func() time.Time
	Sink  func(AlertEvent)
	// Push receives node contributions to cluster rules (node role).
	Push       func(Part)
	KubeSubset map[string]bool
	// CompileLogQL compiles LogQL rule expressions; it may register the program with the log tailer.
	CompileLogQL func(expr string, b bundle.Budget) (LogProgram, error)
	Queryable    storage.Queryable
	// StateSource returns a state snapshot that is not mutated while the cycle runs.
	StateSource func() *protocol.State
	// ScopeMatch reports whether a state scope key covers resources of kind in namespace.
	ScopeMatch      func(scopeKey, kind, namespace string) bool
	ResolveResource func(kind, namespace, name string) (uid string, ok bool)
	// Coverage reports local telemetry coverage for node-local rules.
	Coverage func() Coverage
	// ClusterCoverage reports whether every node contributes to a cluster rule on a compatible version.
	ClusterCoverage func(ruleID string, ruleVersion int) Coverage
	EvidenceLimited func(ruleID string) bool
	Policy          Policy
	DefaultInterval time.Duration
	BudgetBackoff   time.Duration
	// OutageTolerance bounds the downtime after which persisted pending state is not resumed.
	OutageTolerance time.Duration
	LookbackDelta   time.Duration
}

Options configures an Engine. Only Store, Clock, and Sink are needed by every role.

type Part

type Part struct {
	RuleID        string
	RuleVersion   int
	BundleVersion string
	EvalTime      time.Time
	Vector        promql.Vector
}

Part is one node's pre-aggregated contribution to a cluster rule (PRD M4).

type Policy

type Policy struct {
	MaxEvalTime     time.Duration
	MaxSamples      int
	MaxSeries       int
	MaxComplexity   int
	MaxCounterBytes int
	DisabledRules   []string
	// Capabilities lists the capabilities available to rules; nil means all.
	Capabilities []string
}

Policy is the local administrator upper bound on rules. Zero values leave rule budgets uncapped.

type RuleState

type RuleState struct {
	RuleID       string
	Version      int
	Class        string
	Scope        string
	State        string
	Reason       string
	LastEval     time.Time
	LastDuration time.Duration
	Pending      int
	Firing       int
	BackoffUntil time.Time
}

RuleState reports one rule's evaluation state.

type Sample

type Sample struct {
	T int64
	F float64
}

Sample is one float sample at a millisecond timestamp.

type Series

type Series struct {
	Labels  labels.Labels
	Samples []Sample
}

Series is a labeled sequence of samples in ascending time order.

func PartSeries

func PartSeries(node string, p Part) []Series

PartSeries labels a node's part with rule, version, and node for the coordinator's MemSeries.

type Split

type Split struct {
	NodeExpr  string
	CoordExpr string
	Outer     string
	Grouping  []string
	Without   bool
}

Split is a cluster rule's node and coordinator expressions; kube_*-only rules have no NodeExpr.

func SplitPromQL

func SplitPromQL(rule bundle.AlertRule, opts Options) (*Split, error)

SplitPromQL validates a cluster rule and returns its node and coordinator expressions.

type ValidationError

type ValidationError struct {
	RuleID string
	Reason string
}

ValidationError is a precise rejection of one rule.

func (*ValidationError) Error

func (e *ValidationError) Error() string

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL