nftban-core

command
v1.230.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 14, 2026 License: MPL-2.0 Imports: 63 Imported by: 0

Documentation

Overview

SPDX-License-Identifier: MPL-2.0 SPDX-FileCopyrightText: Copyright (c) 2024-2026 Antonios Voulvoulis <contact@nftban.com> meta:name="nftban-core-logretention" meta:type="cli" meta:owner="Antonios Voulvoulis <contact@nftban.com>" meta:created_date="2026-07-19" meta:description="nftban-core logretention subcommand (Gate B / v1.222.0): `status [--json]` reports the effective log-retention policy from the AUTHORITATIVE generated-state record + LIVE filesystem/usage/override facts (fabricating nothing — no bytes-reclaimed/last-cleanup guesses); `generate` runs the atomic generated-policy transaction (INTENDED to be invoked by install/%post + timer + config-change hooks — that wiring is pending audit R2; today it is a manual/root entrypoint). This imports internal/logretention, so the nftban-core binary changes; the nftband daemon does NOT import it." meta:input="generated-state JSON, statfs(/var/log), du(/var/log/nftban), conf.d/logs.conf" meta:output="human or JSON status; generation transaction" meta:depends="github.com/itcmsgr/nftban/internal/logretention,github.com/itcmsgr/nftban/pkg/version" meta:inventory.files="cmd/nftban-core/cmd_logretention.go" meta:inventory.binaries="nftban-core,logrotate" meta:inventory.env_vars="" meta:inventory.config_files="/etc/nftban/conf.d/logs.conf,/etc/logrotate.d/nftban,/etc/logrotate.d/nftban-suricata" meta:inventory.systemd_units="" meta:inventory.network="" meta:inventory.privileges="root (generate writes /etc/logrotate.d + /var/lib/nftban/generated); status is read-only"

SPDX-License-Identifier: MPL-2.0 SPDX-FileCopyrightText: Copyright (c) 2024-2026 Antonios Voulvoulis <contact@nftban.com> meta:name="cmd_resources.go" meta:type="cmd" meta:owner="Antonios Voulvoulis <contact@nftban.com>" meta:description="v1.222.1 Lane 3: `nftban-core resources [--json]` — READ-ONLY diagnostics for the health-service resource policy. Reports host facts (canonical safety), the CALCULATED policy (safety.HealthServiceMemoryLimits), the persisted installer HEALTH_RESOURCE_* state, and the LIVE systemd effective values (systemctl show, read-only), then classifies protection via the shared healthresource.ClassifyEffectiveDetailed. Live systemd is authoritative for the current verdict. NO new RAM/tier classifier, NO /proc parser, NO mutation (no write/reload/reset). The public `nftban health resources` shell command delegates here." meta:inventory.files="cmd/nftban-core/cmd_resources.go" meta:inventory.binaries="systemctl" meta:inventory.env_vars="" meta:inventory.config_files="" meta:inventory.systemd_units="nftban-health.service" meta:inventory.network="" meta:inventory.privileges="none"

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL