Versions in this module Expand all Collapse all v0 v0.50.0 Oct 1, 2026 v0.49.8 Oct 1, 2026 v0.49.7 Oct 1, 2026 v0.49.6 Oct 1, 2026 v0.49.5 Oct 1, 2026 Changes in this version + const BaselineVersion + const CloudFirewallTable + const ControlBruteForce + const ControlCertificateExpiry + const ControlFirewall + const ControlListeners + const ControlPendingSecurity + const ControlPublishedPorts + const ControlRebootRequired + const ControlSSHPassword + const ControlSSHPort + const ControlSSHRootLogin + const ControlSysctl + const ControlUnattended + const DefaultExceptionsPath + const DefaultFreshness + const EvidenceSchemaVersion + const ExceptionsSchemaVersion + const HomeFirewallChain + const HomeFirewallPolicyPath + const HomeFirewallRuleset + const HomeFirewallTable + const MaxFreshness + const MinFreshness + const ReasonExposedPublishedPort + const ReasonNoAuthorizedKey + const RepairSchemaVersion + const StateDir + func EnforcedControls() []string + func EvidencePath(workspaceRoot string) string + type AppliedException struct + ExpiresAt time.Time + Owner string + Reason string + type Control struct + Exception *AppliedException + Expected string + ID string + Observed string + ObservedAt time.Time + Reason string + ReasonCode string + Remediation Remediation + State State + type ControlSnapshot struct + Observed string + State State + type Engine struct + Host Host + func (e Engine) LoadEvidence(workspaceRoot string) (Evidence, error) + func (e Engine) Repair(ctx context.Context, opts RepairOptions) RepairReport + func (e Engine) SaveEvidence(workspaceRoot string, evidence Evidence) (string, error) + func (e Engine) Verify(ctx context.Context, options Options) Evidence + type Evidence struct + BaselineVersion string + Controls []Control + Exceptions []ExceptionRecord + ExpiresAt time.Time + FreshnessSecs int + Kit string + Mode Mode + NodeRef string + Notices []string + ObservedAt time.Time + Overall State + PlanHash string + SchemaVersion string + SiteKind SiteKind + func (e Evidence) AtTime(now time.Time) Evidence + func (e Evidence) Judge(now time.Time) State + type Exception struct + Control string + ExpiresAt time.Time + Owner string + Reason string + func LoadExceptions(host Host, path string) (exceptions []Exception, notices []string) + type ExceptionRecord struct + Control string + Detail string + ExpiresAt time.Time + Owner string + Reason string + Status ExceptionStatus + type ExceptionStatus string + const ExceptionActive + const ExceptionExpired + const ExceptionInvalid + const ExceptionUnused + type ExceptionsFile struct + Exceptions []Exception + SchemaVersion string + type FirewallPolicy struct + DeclaredOnly bool + DeclaredTCP []int + DeclaredUDP []int + ManagementSources []netip.Prefix + Peers []netip.Addr + SSHPorts []int + func (p FirewallPolicy) Admits(packet Packet) bool + func (p FirewallPolicy) Render() string + func (p FirewallPolicy) RenderRuleset() string + func (p FirewallPolicy) Validate() error + type Host interface + Getenv func(key string) string + Geteuid func() int + LookPath func(name string) (string, error) + MkdirAll func(path string, mode os.FileMode) error + Now func() time.Time + ReadFile func(path string) ([]byte, error) + Remove func(path string) error + Run func(ctx context.Context, name string, args ...string) (Output, error) + Sleep func(ctx context.Context, d time.Duration) error + Stat func(path string) (fs.FileInfo, error) + WriteFile func(path string, data []byte, mode os.FileMode) error + type Listener struct + Port int + Transport string + type LocalHost struct + func (LocalHost) Getenv(key string) string + func (LocalHost) Geteuid() int + func (LocalHost) LookPath(name string) (string, error) + func (LocalHost) MkdirAll(path string, mode os.FileMode) error + func (LocalHost) Now() time.Time + func (LocalHost) ReadFile(path string) ([]byte, error) + func (LocalHost) Remove(path string) error + func (LocalHost) Run(ctx context.Context, name string, args ...string) (Output, error) + func (LocalHost) Sleep(ctx context.Context, d time.Duration) error + func (LocalHost) Stat(path string) (fs.FileInfo, error) + func (LocalHost) WriteFile(path string, data []byte, mode os.FileMode) error + type ManagedSysctl struct + Key string + Minimum int + func ManagedSysctls() []ManagedSysctl + type ManagementPath struct + InSSHSession bool + KeyAccounts []string + ManagementSources []string + SSHInstalled bool + SSHPorts []int + SessionPeers []string + SessionUser string + type Mode string + const ModeAdvanced + const ModeStandard + type Options struct + DeclaredAuthority string + DeclaredListeners []Listener + ExceptionsPath string + Freshness time.Duration + Kit string + ManagementSources []netip.Prefix + Mode Mode + NodeRef string + PlanHash string + SiteKind SiteKind + WorkspaceRoot string + type Outcome string + const OutcomeApplied + const OutcomeBlocked + const OutcomeFailed + const OutcomeManual + const OutcomeNothingToDo + const OutcomePlanned + type Output struct + ExitCode int + Stderr string + Stdout string + type Packet struct + Established bool + Interface string + Invalid bool + Port int + Protocol string + Source netip.Addr + SourcePort int + type Remediation struct + Action string + Capability RemediationCapability + type RemediationCapability string + const RemediationAutomatic + const RemediationManual + const RemediationNone + type RepairOptions struct + Apply bool + Controls []string + type RepairReport struct + After *Evidence + Applied bool + Before Evidence + FinishedAt time.Time + Firewall *FirewallPolicy + Management ManagementPath + Outcome Outcome + SchemaVersion string + StartedAt time.Time + Steps []RepairStep + type RepairStep struct + After *ControlSnapshot + Before *ControlSnapshot + Changes []string + Control string + Reason string + ReasonCode string + Status StepStatus + Summary string + type SiteKind string + const SiteCloud + const SiteHome + const SiteUnknown + type State string + const StateCompliant + const StateDrifted + const StateException + const StateUnknown + type StepStatus string + const StepApplied + const StepBlocked + const StepFailed + const StepManual + const StepNoop + const StepPlanned