investigate

package
v0.7.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 1, 2026 License: Apache-2.0 Imports: 40 Imported by: 0

Documentation

Overview

Package investigate serves bounded live and lookback investigation tools with AST scope injection (docs/investigation.md).

Index

Constants

View Source
const (
	DefaultLookbackDelta    = 5 * time.Minute
	DefaultReadMaxLines     = 50000
	DefaultReadMaxBytes     = 16 << 20
	DefaultReadMaxScanBytes = 256 << 20
)

Executor defaults.

View Source
const (
	ClassInvalid        = "invalid_request"
	ClassUnauthorized   = "unauthorized"
	ClassUnavailable    = "unavailable"
	ClassTimeout        = "timeout"
	ClassBusy           = "busy"
	ClassSourceRejected = "source_rejected"
	ClassInternal       = "internal"
)

Error classes reported in results and audit records.

View Source
const (
	NamespaceLabel = "namespace"
	PodLabel       = "pod"
	NodeLabel      = "node"
)

Scope label names injected into telemetry queries.

View Source
const (
	TypeStreams = "streams"
	TypeVector  = "vector"
	TypeMatrix  = "matrix"
	TypeScalar  = "scalar"
)

Result types of telemetry data.

View Source
const (
	NodeOK        = "ok"
	NodeFailed    = "failed"
	NodeUncovered = "uncovered"
)

Node fan-out statuses.

View Source
const (
	LangPromQL    = "promql"
	LangMetricsQL = "metricsql"
	LangLogQL     = "logql"
	LangLogsQL    = "logsql"
)

Query languages.

View Source
const (
	RoleCoordinator = "coordinator"
	RoleHost        = "host"
)

Roles served by a Service.

View Source
const (
	ToolState       = "state.query"
	ToolGraph       = "graph.query"
	ToolPromQL      = "promql.query"
	ToolLogQL       = "logql.query"
	ToolLogsQL      = "logsql.query"
	ToolLookback    = "lookback.query"
	ToolFindingSave = "finding.save"
	ToolEvidence    = "evidence.query"
)

Tool names.

View Source
const (
	OutcomeOK       = "ok"
	OutcomeLimited  = "limited"
	OutcomeRejected = "rejected"
	OutcomeError    = "error"
)

Audit outcomes.

View Source
const LangEvidence = "evidence"

LangEvidence labels evidence reads in results and audit records.

View Source
const LimitationNoLookback = "historical search requires connecting the customer's own monitoring stack as a lookback source"

LimitationNoLookback is appended when history beyond the in-cluster window is requested without a lookback source.

View Source
const (
	SourceConcurrency = 2
)

Lookback adapter bounds.

Variables

This section is empty.

Functions

func InjectLogQL

func InjectLogQL(query string, m []*labels.Matcher) (string, error)

InjectLogQL ANDs m into every stream selector with logql.InjectScope and verifies the result.

func InjectLogsQL

func InjectLogsQL(query string, namespaces, pods, nodes []string, start, end time.Time) (string, error)

InjectLogsQL ANDs namespace, pod, and node stream filters and the window (unless start is zero) with the whole LogsQL query, including subqueries.

func InjectMetricsQL

func InjectMetricsQL(query string, m []*labels.Matcher) (string, error)

InjectMetricsQL appends m to every or-group of every metric expression of a MetricsQL query.

func InjectPromQL

func InjectPromQL(query string, m []*labels.Matcher) (string, error)

InjectPromQL ANDs m into every vector and matrix selector of a PromQL query and re-serializes it.

Types

type AuditRecord

type AuditRecord struct {
	RequestID       string    `json:"request_id"`
	Time            time.Time `json:"time"`
	Requester       string    `json:"requester"`
	Purpose         string    `json:"purpose"`
	Tool            string    `json:"tool"`
	Language        string    `json:"language,omitempty"`
	QueryHash       string    `json:"query_hash,omitempty"`
	Scope           Scope     `json:"scope"`
	Window          *Window   `json:"window,omitempty"`
	Limits          Limits    `json:"limits"`
	Source          string    `json:"source,omitempty"`
	Outcome         string    `json:"outcome"`
	Truncated       bool      `json:"truncated"`
	Limitations     int       `json:"limitations,omitempty"`
	ErrorClass      string    `json:"error_class,omitempty"`
	DurationMs      int64     `json:"duration_ms"`
	RetainedFinding bool      `json:"retained_finding,omitempty"`
}

AuditRecord is sanitized call metadata; it never carries credentials or result bodies.

type Error

type Error struct {
	Class string
	Msg   string
}

Error is a rejected or failed tool call with a class for audit.

func (*Error) Error

func (e *Error) Error() string

type EvidenceReader

type EvidenceReader interface {
	Peek(ruleID string, n int) []evidence.Sample
}

EvidenceReader reads rule evidence without consuming it (evidence.Ring satisfies it).

type ExecOptions

type ExecOptions struct {
	Node      string
	Queryable storage.Queryable
	// Retention reports the local TSDB retention; nil means unknown.
	Retention func() time.Duration
	// PodLogRoot is the /var/log/pods tree; empty disables pod log reads.
	PodLogRoot string
	Enrich     logs.EnrichFunc
	// HostLogPaths are the administrator-allowlisted host log files and directories.
	HostLogPaths []string
	Journal      logql.LineSource
	Evidence     EvidenceReader
	Limits       config.Investigation
	Redactor     *redact.Redactor
	// LookbackDelta is the PromQL staleness window.
	LookbackDelta time.Duration
	// ReadMaxLines and ReadMaxBytes bound lines held by one on-demand read before the pipeline runs.
	ReadMaxLines     int
	ReadMaxBytes     int64
	ReadMaxScanBytes int64
	Clock            func() time.Time
}

ExecOptions configures a node agent or host Executor.

type Executor

type Executor struct {
	// contains filtered or unexported fields
}

Executor runs investigation tasks against local telemetry and retains nothing.

func NewExecutor

func NewExecutor(o ExecOptions) *Executor

NewExecutor applies defaults.

func (*Executor) Execute

func (e *Executor) Execute(ctx context.Context, t nodeapi.Task) nodeapi.TaskResult

Execute runs one task; failures are reported in TaskResult.Error.

type GraphEdge

type GraphEdge struct {
	From  string         `json:"from"`
	Type  string         `json:"type"`
	To    string         `json:"to"`
	Attrs map[string]any `json:"attrs,omitempty"`
}

GraphEdge is one change-graph edge in a graph.query result.

type Limits

type Limits struct {
	MaxLines   int   `json:"max_lines,omitempty"`
	MaxBytes   int64 `json:"max_bytes,omitempty"`
	MaxSeries  int   `json:"max_series,omitempty"`
	MaxSamples int   `json:"max_samples,omitempty"`
	TimeoutMs  int64 `json:"timeout_ms,omitempty"`
}

Limits are requested or effective bounds; zero requests the configured maximum.

type LogLine

type LogLine struct {
	Source string            `json:"source,omitempty"`
	Time   time.Time         `json:"time"`
	Labels map[string]string `json:"labels"`
	Text   string            `json:"text"`
}

LogLine is one log line.

type NodeRouter

type NodeRouter interface {
	Nodes() []string
	Run(ctx context.Context, node string, t nodeapi.Task) (nodeapi.TaskResult, error)
}

NodeRouter runs tasks on node agents.

type NodeStatus

type NodeStatus struct {
	Node        string `json:"node"`
	Status      string `json:"status"`
	Error       string `json:"error,omitempty"`
	RetentionMs int64  `json:"retention_ms,omitempty"`
	Truncated   bool   `json:"truncated,omitempty"`
}

NodeStatus reports one fan-out target.

type Options

type Options struct {
	Role string
	// State returns a snapshot that is not mutated while a call reads it.
	State       func() *protocol.State
	Local       *Executor
	Nodes       NodeRouter
	Coordinator storage.Queryable
	Lookback    []config.Lookback
	HTTPClient  *http.Client
	Limits      config.Investigation
	Audit       func(AuditRecord)
	SaveFinding func(findings.Observation) error
	Clock       func() time.Time
	Redactor    *redact.Redactor
}

Options configures a Service.

type Point

type Point struct {
	T int64
	V float64
}

Point is a sample encoded as [unix_ms, "value"] so non-finite values survive JSON.

func (Point) MarshalJSON

func (p Point) MarshalJSON() ([]byte, error)

func (*Point) UnmarshalJSON

func (p *Point) UnmarshalJSON(b []byte) error

type Request

type Request struct {
	RequestID string  `json:"request_id,omitempty"`
	Requester string  `json:"requester"`
	Purpose   string  `json:"purpose"`
	Scope     Scope   `json:"scope"`
	Window    *Window `json:"window,omitempty"`
	Limits    Limits  `json:"limits"`
}

Request holds the fields every tool call carries.

type ResourceRef

type ResourceRef struct {
	UID       string `json:"uid,omitempty"`
	Kind      string `json:"kind,omitempty"`
	Namespace string `json:"namespace,omitempty"`
	Name      string `json:"name,omitempty"`
}

ResourceRef names a resource by UID or by kind, namespace, and name.

type Result

type Result struct {
	Source      string   `json:"source"`
	Window      Window   `json:"window"`
	Limits      Limits   `json:"limits"`
	Truncated   bool     `json:"truncated"`
	Limitations []string `json:"limitations"`
	QueryHash   string   `json:"query_hash,omitempty"`
	Language    string   `json:"language,omitempty"`
	Query       string   `json:"query,omitempty"`
	Executed    string   `json:"executed_query,omitempty"`
	RetentionMs int64    `json:"retention_ms,omitempty"`
	Data        any      `json:"data"`
}

Result is the envelope every tool returns (PRD I4).

type Scope

type Scope struct {
	Cluster    bool          `json:"cluster,omitempty"`
	Namespaces []string      `json:"namespaces,omitempty"`
	Resources  []ResourceRef `json:"resources,omitempty"`
	Nodes      []string      `json:"nodes,omitempty"`
}

Scope binds a request to namespaces, resources, and nodes; Cluster asserts a cluster-wide requester.

type Series

type Series struct {
	Source string            `json:"source,omitempty"`
	Metric map[string]string `json:"metric"`
	Points []Point           `json:"values"`
}

Series is one metric series; Source names the node, coordinator, host, or lookback source.

type Service

type Service struct {
	// contains filtered or unexported fields
}

Service executes investigation tools; results are never retained.

func NewService

func NewService(o Options) (*Service, error)

NewService validates options and lookback sources.

func (*Service) Call

func (s *Service) Call(ctx context.Context, name string, args json.RawMessage) (any, error)

Call validates and runs one tool call and emits its audit record.

func (*Service) Tools

func (s *Service) Tools() []client.Tool

Tools lists the MCP tool definitions.

type StateResource

type StateResource struct {
	UID       string         `json:"uid"`
	Kind      string         `json:"kind"`
	Namespace string         `json:"namespace,omitempty"`
	Name      string         `json:"name"`
	Fields    map[string]any `json:"fields,omitempty"`
}

StateResource is one resource in a state.query result.

type TaskQuery

type TaskQuery struct {
	Query      string   `json:"query"`
	StartMs    int64    `json:"start_ms"`
	EndMs      int64    `json:"end_ms"`
	StepMs     int64    `json:"step_ms,omitempty"`
	Forward    bool     `json:"forward,omitempty"`
	Namespaces []string `json:"namespaces,omitempty"`
	Pods       []string `json:"pods,omitempty"`
	Nodes      []string `json:"nodes,omitempty"`
	Limits     Limits   `json:"limits"`
}

TaskQuery is the JSON payload of promql_query, logql_query, and log_read tasks.

type TaskResponse

type TaskResponse struct {
	Data        Telemetry `json:"data"`
	Truncated   bool      `json:"truncated"`
	Limitations []string  `json:"limitations,omitempty"`
	RetentionMs int64     `json:"retention_ms,omitempty"`
}

TaskResponse is the JSON payload of a task result.

type Telemetry

type Telemetry struct {
	ResultType string       `json:"result_type"`
	Series     []Series     `json:"series,omitempty"`
	Lines      []LogLine    `json:"lines,omitempty"`
	Nodes      []NodeStatus `json:"nodes,omitempty"`
}

Telemetry is the data of promql, logql, logsql, and lookback results.

type Window

type Window struct {
	Start int64 `json:"start"`
	End   int64 `json:"end"`
}

Window is an inclusive time range in Unix milliseconds.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL