Documentation
¶
Overview ¶
Package investigate serves bounded live and lookback investigation tools with AST scope injection (docs/investigation.md).
Index ¶
- Constants
- func InjectLogQL(query string, m []*labels.Matcher) (string, error)
- func InjectLogsQL(query string, namespaces, pods, nodes []string, start, end time.Time) (string, error)
- func InjectMetricsQL(query string, m []*labels.Matcher) (string, error)
- func InjectPromQL(query string, m []*labels.Matcher) (string, error)
- type AuditRecord
- type Error
- type EvidenceReader
- type ExecOptions
- type Executor
- type GraphEdge
- type Limits
- type LogLine
- type NodeRouter
- type NodeStatus
- type Options
- type Point
- type Request
- type ResourceRef
- type Result
- type Scope
- type Series
- type Service
- type StateResource
- type TaskQuery
- type TaskResponse
- type Telemetry
- type Window
Constants ¶
const ( DefaultLookbackDelta = 5 * time.Minute DefaultReadMaxLines = 50000 DefaultReadMaxBytes = 16 << 20 DefaultReadMaxScanBytes = 256 << 20 )
Executor defaults.
const ( ClassInvalid = "invalid_request" ClassTimeout = "timeout" ClassBusy = "busy" ClassSourceRejected = "source_rejected" ClassInternal = "internal" )
Error classes reported in results and audit records.
const ( NamespaceLabel = "namespace" PodLabel = "pod" NodeLabel = "node" )
Scope label names injected into telemetry queries.
const ( TypeStreams = "streams" TypeVector = "vector" TypeMatrix = "matrix" TypeScalar = "scalar" )
Result types of telemetry data.
const ( NodeOK = "ok" NodeFailed = "failed" NodeUncovered = "uncovered" )
Node fan-out statuses.
const ( LangPromQL = "promql" LangMetricsQL = "metricsql" LangLogQL = "logql" LangLogsQL = "logsql" )
Query languages.
const ( RoleCoordinator = "coordinator" RoleHost = "host" )
Roles served by a Service.
const ( ToolState = "state.query" ToolGraph = "graph.query" ToolPromQL = "promql.query" ToolLogQL = "logql.query" ToolLogsQL = "logsql.query" ToolLookback = "lookback.query" ToolFindingSave = "finding.save" ToolEvidence = "evidence.query" )
Tool names.
const ( OutcomeOK = "ok" OutcomeLimited = "limited" OutcomeRejected = "rejected" OutcomeError = "error" )
Audit outcomes.
const LangEvidence = "evidence"
LangEvidence labels evidence reads in results and audit records.
const LimitationNoLookback = "historical search requires connecting the customer's own monitoring stack as a lookback source"
LimitationNoLookback is appended when history beyond the in-cluster window is requested without a lookback source.
const (
SourceConcurrency = 2
)
Lookback adapter bounds.
Variables ¶
This section is empty.
Functions ¶
func InjectLogQL ¶
InjectLogQL ANDs m into every stream selector with logql.InjectScope and verifies the result.
func InjectLogsQL ¶
func InjectLogsQL(query string, namespaces, pods, nodes []string, start, end time.Time) (string, error)
InjectLogsQL ANDs namespace, pod, and node stream filters and the window (unless start is zero) with the whole LogsQL query, including subqueries.
func InjectMetricsQL ¶
InjectMetricsQL appends m to every or-group of every metric expression of a MetricsQL query.
Types ¶
type AuditRecord ¶
type AuditRecord struct {
RequestID string `json:"request_id"`
Time time.Time `json:"time"`
Requester string `json:"requester"`
Purpose string `json:"purpose"`
Tool string `json:"tool"`
Language string `json:"language,omitempty"`
QueryHash string `json:"query_hash,omitempty"`
Scope Scope `json:"scope"`
Window *Window `json:"window,omitempty"`
Limits Limits `json:"limits"`
Source string `json:"source,omitempty"`
Outcome string `json:"outcome"`
Truncated bool `json:"truncated"`
Limitations int `json:"limitations,omitempty"`
ErrorClass string `json:"error_class,omitempty"`
DurationMs int64 `json:"duration_ms"`
RetainedFinding bool `json:"retained_finding,omitempty"`
}
AuditRecord is sanitized call metadata; it never carries credentials or result bodies.
type EvidenceReader ¶
EvidenceReader reads rule evidence without consuming it (evidence.Ring satisfies it).
type ExecOptions ¶
type ExecOptions struct {
Node string
Queryable storage.Queryable
// Retention reports the local TSDB retention; nil means unknown.
Retention func() time.Duration
// PodLogRoot is the /var/log/pods tree; empty disables pod log reads.
PodLogRoot string
Enrich logs.EnrichFunc
// HostLogPaths are the administrator-allowlisted host log files and directories.
HostLogPaths []string
Journal logql.LineSource
Evidence EvidenceReader
Limits config.Investigation
Redactor *redact.Redactor
// LookbackDelta is the PromQL staleness window.
LookbackDelta time.Duration
// ReadMaxLines and ReadMaxBytes bound lines held by one on-demand read before the pipeline runs.
ReadMaxLines int
ReadMaxBytes int64
ReadMaxScanBytes int64
Clock func() time.Time
}
ExecOptions configures a node agent or host Executor.
type Executor ¶
type Executor struct {
// contains filtered or unexported fields
}
Executor runs investigation tasks against local telemetry and retains nothing.
type GraphEdge ¶
type GraphEdge struct {
From string `json:"from"`
Type string `json:"type"`
To string `json:"to"`
Attrs map[string]any `json:"attrs,omitempty"`
}
GraphEdge is one change-graph edge in a graph.query result.
type Limits ¶
type Limits struct {
MaxLines int `json:"max_lines,omitempty"`
MaxBytes int64 `json:"max_bytes,omitempty"`
MaxSeries int `json:"max_series,omitempty"`
MaxSamples int `json:"max_samples,omitempty"`
TimeoutMs int64 `json:"timeout_ms,omitempty"`
}
Limits are requested or effective bounds; zero requests the configured maximum.
type LogLine ¶
type LogLine struct {
Source string `json:"source,omitempty"`
Time time.Time `json:"time"`
Labels map[string]string `json:"labels"`
Text string `json:"text"`
}
LogLine is one log line.
type NodeRouter ¶
type NodeRouter interface {
Nodes() []string
Run(ctx context.Context, node string, t nodeapi.Task) (nodeapi.TaskResult, error)
}
NodeRouter runs tasks on node agents.
type NodeStatus ¶
type NodeStatus struct {
Node string `json:"node"`
Status string `json:"status"`
Error string `json:"error,omitempty"`
RetentionMs int64 `json:"retention_ms,omitempty"`
Truncated bool `json:"truncated,omitempty"`
}
NodeStatus reports one fan-out target.
type Options ¶
type Options struct {
Role string
// State returns a snapshot that is not mutated while a call reads it.
State func() *protocol.State
Local *Executor
Nodes NodeRouter
Coordinator storage.Queryable
Lookback []config.Lookback
HTTPClient *http.Client
Limits config.Investigation
Audit func(AuditRecord)
SaveFinding func(findings.Observation) error
Clock func() time.Time
Redactor *redact.Redactor
}
Options configures a Service.
type Point ¶
Point is a sample encoded as [unix_ms, "value"] so non-finite values survive JSON.
func (Point) MarshalJSON ¶
func (*Point) UnmarshalJSON ¶
type Request ¶
type Request struct {
RequestID string `json:"request_id,omitempty"`
Requester string `json:"requester"`
Purpose string `json:"purpose"`
Scope Scope `json:"scope"`
Window *Window `json:"window,omitempty"`
Limits Limits `json:"limits"`
}
Request holds the fields every tool call carries.
type ResourceRef ¶
type ResourceRef struct {
UID string `json:"uid,omitempty"`
Kind string `json:"kind,omitempty"`
Namespace string `json:"namespace,omitempty"`
Name string `json:"name,omitempty"`
}
ResourceRef names a resource by UID or by kind, namespace, and name.
type Result ¶
type Result struct {
Source string `json:"source"`
Window Window `json:"window"`
Limits Limits `json:"limits"`
Truncated bool `json:"truncated"`
Limitations []string `json:"limitations"`
QueryHash string `json:"query_hash,omitempty"`
Language string `json:"language,omitempty"`
Query string `json:"query,omitempty"`
Executed string `json:"executed_query,omitempty"`
RetentionMs int64 `json:"retention_ms,omitempty"`
Data any `json:"data"`
}
Result is the envelope every tool returns (PRD I4).
type Scope ¶
type Scope struct {
Cluster bool `json:"cluster,omitempty"`
Namespaces []string `json:"namespaces,omitempty"`
Resources []ResourceRef `json:"resources,omitempty"`
Nodes []string `json:"nodes,omitempty"`
}
Scope binds a request to namespaces, resources, and nodes; Cluster asserts a cluster-wide requester.
type Series ¶
type Series struct {
Source string `json:"source,omitempty"`
Metric map[string]string `json:"metric"`
Points []Point `json:"values"`
}
Series is one metric series; Source names the node, coordinator, host, or lookback source.
type Service ¶
type Service struct {
// contains filtered or unexported fields
}
Service executes investigation tools; results are never retained.
func NewService ¶
NewService validates options and lookback sources.
type StateResource ¶
type StateResource struct {
UID string `json:"uid"`
Kind string `json:"kind"`
Namespace string `json:"namespace,omitempty"`
Name string `json:"name"`
Fields map[string]any `json:"fields,omitempty"`
}
StateResource is one resource in a state.query result.
type TaskQuery ¶
type TaskQuery struct {
Query string `json:"query"`
StartMs int64 `json:"start_ms"`
EndMs int64 `json:"end_ms"`
StepMs int64 `json:"step_ms,omitempty"`
Forward bool `json:"forward,omitempty"`
Namespaces []string `json:"namespaces,omitempty"`
Pods []string `json:"pods,omitempty"`
Nodes []string `json:"nodes,omitempty"`
Limits Limits `json:"limits"`
}
TaskQuery is the JSON payload of promql_query, logql_query, and log_read tasks.
type TaskResponse ¶
type TaskResponse struct {
Data Telemetry `json:"data"`
Truncated bool `json:"truncated"`
Limitations []string `json:"limitations,omitempty"`
RetentionMs int64 `json:"retention_ms,omitempty"`
}
TaskResponse is the JSON payload of a task result.