Versions in this module Expand all Collapse all v0 v0.49.5 Oct 1, 2026 Changes in this version + const BaselineVersion + const CloudFirewallTable + const ControlBruteForce + const ControlCertificateExpiry + const ControlFirewall + const ControlListeners + const ControlPendingSecurity + const ControlPublishedPorts + const ControlRebootRequired + const ControlSSHPassword + const ControlSSHPort + const ControlSSHRootLogin + const ControlSysctl + const ControlUnattended + const DefaultExceptionsPath + const DefaultFreshness + const EvidenceSchemaVersion + const ExceptionsSchemaVersion + const HomeFirewallChain + const HomeFirewallPolicyPath + const HomeFirewallRuleset + const HomeFirewallTable + const MaxFreshness + const MinFreshness + const ReasonExposedPublishedPort + const ReasonNoAuthorizedKey + const RepairSchemaVersion + const StateDir + func EnforcedControls() []string + func EvidencePath(workspaceRoot string) string + type AppliedException struct + ExpiresAt time.Time + Owner string + Reason string + type Control struct + Exception *AppliedException + Expected string + ID string + Observed string + ObservedAt time.Time + Reason string + ReasonCode string + Remediation Remediation + State State + type ControlSnapshot struct + Observed string + State State + type Engine struct + Host Host + func (e Engine) LoadEvidence(workspaceRoot string) (Evidence, error) + func (e Engine) Repair(ctx context.Context, opts RepairOptions) RepairReport + func (e Engine) SaveEvidence(workspaceRoot string, evidence Evidence) (string, error) + func (e Engine) Verify(ctx context.Context, options Options) Evidence + type Evidence struct + BaselineVersion string + Controls []Control + Exceptions []ExceptionRecord + ExpiresAt time.Time + FreshnessSecs int + Kit string + Mode Mode + NodeRef string + Notices []string + ObservedAt time.Time + Overall State + PlanHash string + SchemaVersion string + SiteKind SiteKind + func (e Evidence) AtTime(now time.Time) Evidence + func (e Evidence) Judge(now time.Time) State + type Exception struct + Control string + ExpiresAt time.Time + Owner string + Reason string + func LoadExceptions(host Host, path string) (exceptions []Exception, notices []string) + type ExceptionRecord struct + Control string + Detail string + ExpiresAt time.Time + Owner string + Reason string + Status ExceptionStatus + type ExceptionStatus string + const ExceptionActive + const ExceptionExpired + const ExceptionInvalid + const ExceptionUnused + type ExceptionsFile struct + Exceptions []Exception + SchemaVersion string + type FirewallPolicy struct + DeclaredOnly bool + DeclaredTCP []int + DeclaredUDP []int + ManagementSources []netip.Prefix + Peers []netip.Addr + SSHPorts []int + func (p FirewallPolicy) Admits(packet Packet) bool + func (p FirewallPolicy) Render() string + func (p FirewallPolicy) RenderRuleset() string + func (p FirewallPolicy) Validate() error + type Host interface + Getenv func(key string) string + Geteuid func() int + LookPath func(name string) (string, error) + MkdirAll func(path string, mode os.FileMode) error + Now func() time.Time + ReadFile func(path string) ([]byte, error) + Remove func(path string) error + Run func(ctx context.Context, name string, args ...string) (Output, error) + Sleep func(ctx context.Context, d time.Duration) error + Stat func(path string) (fs.FileInfo, error) + WriteFile func(path string, data []byte, mode os.FileMode) error + type Listener struct + Port int + Transport string + type LocalHost struct + func (LocalHost) Getenv(key string) string + func (LocalHost) Geteuid() int + func (LocalHost) LookPath(name string) (string, error) + func (LocalHost) MkdirAll(path string, mode os.FileMode) error + func (LocalHost) Now() time.Time + func (LocalHost) ReadFile(path string) ([]byte, error) + func (LocalHost) Remove(path string) error + func (LocalHost) Run(ctx context.Context, name string, args ...string) (Output, error) + func (LocalHost) Sleep(ctx context.Context, d time.Duration) error + func (LocalHost) Stat(path string) (fs.FileInfo, error) + func (LocalHost) WriteFile(path string, data []byte, mode os.FileMode) error + type ManagedSysctl struct + Key string + Minimum int + func ManagedSysctls() []ManagedSysctl + type ManagementPath struct + InSSHSession bool + KeyAccounts []string + ManagementSources []string + SSHInstalled bool + SSHPorts []int + SessionPeers []string + SessionUser string + type Mode string + const ModeAdvanced + const ModeStandard + type Options struct + DeclaredAuthority string + DeclaredListeners []Listener + ExceptionsPath string + Freshness time.Duration + Kit string + ManagementSources []netip.Prefix + Mode Mode + NodeRef string + PlanHash string + SiteKind SiteKind + WorkspaceRoot string + type Outcome string + const OutcomeApplied + const OutcomeBlocked + const OutcomeFailed + const OutcomeManual + const OutcomeNothingToDo + const OutcomePlanned + type Output struct + ExitCode int + Stderr string + Stdout string + type Packet struct + Established bool + Interface string + Invalid bool + Port int + Protocol string + Source netip.Addr + SourcePort int + type Remediation struct + Action string + Capability RemediationCapability + type RemediationCapability string + const RemediationAutomatic + const RemediationManual + const RemediationNone + type RepairOptions struct + Apply bool + Controls []string + type RepairReport struct + After *Evidence + Applied bool + Before Evidence + FinishedAt time.Time + Firewall *FirewallPolicy + Management ManagementPath + Outcome Outcome + SchemaVersion string + StartedAt time.Time + Steps []RepairStep + type RepairStep struct + After *ControlSnapshot + Before *ControlSnapshot + Changes []string + Control string + Reason string + ReasonCode string + Status StepStatus + Summary string + type SiteKind string + const SiteCloud + const SiteHome + const SiteUnknown + type State string + const StateCompliant + const StateDrifted + const StateException + const StateUnknown + type StepStatus string + const StepApplied + const StepBlocked + const StepFailed + const StepManual + const StepNoop + const StepPlanned