netpolicy

package
v0.60.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 3, 2026 License: Apache-2.0 Imports: 3 Imported by: 0

Documentation

Overview

Package netpolicy holds one answer to one question: may this process reach the network?

Draugr reaches out from several places — a release check, a vulnerability database, a template set, the exploitability feeds, tool downloads. Each used to decide for itself, so an air-gapped runner met the failures one at a time, each separately explicable and collectively a bad first hour. There is now one way to say it, and every caller asks here.

A package-level value rather than something threaded through a context: offline is a property of the machine, decided once at startup and read everywhere, and a request-scoped mechanism would imply it can vary per request.

Index

Constants

View Source
const EnvVar = "DRAUGR_OFFLINE"

EnvVar is the environment variable that says this machine has no network.

Variables

This section is empty.

Functions

func Offline

func Offline() bool

Offline reports whether this process should avoid the network.

True when --offline was passed or DRAUGR_OFFLINE is set to anything that is not a recognised falsey value. An unparseable value counts as true: someone who wrote DRAUGR_OFFLINE=yes meant yes, and the safe reading of "I could not understand your request not to use the network" is not to use the network.

func Refuse

func Refuse(action, url string) error

Refuse returns the error a command should return when it needs the network and has been told there is none.

Names what would have been fetched, because "offline" on its own leaves the reader to work out which of Draugr's several network calls they just prevented.

func SetOffline

func SetOffline(v bool)

SetOffline records that the operator asked for offline on the command line.

func SkipUpdateCheck

func SkipUpdateCheck() bool

SkipUpdateCheck reports whether the check for a newer Draugr release should be skipped.

Offline implies it, and the older DRAUGR_NO_UPDATE_CHECK still asks for it on its own — the narrower request remains sayable for someone who has a network and simply does not want to be told about releases.

Types

type RefusedError

type RefusedError struct {
	// Action is what was being attempted, in the user's terms.
	Action string
	// URL is what would have been fetched. Empty when there is no single one.
	URL string
}

RefusedError reports that an operation needing the network was declined.

func (*RefusedError) Error

func (e *RefusedError) Error() string

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL