securitybaseline

package
v0.49.5 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 1, 2026 License: Apache-2.0 Imports: 3 Imported by: 0

Documentation

Overview

Package securitybaseline renders the canonical Architecture v2 universal host policy script (security-only unattended upgrades and managed kernel parameters). Firewall, sshd and fail2ban are owned per site kind by the Home and Cloud host-security owners, not by this script.

Index

Constants

View Source
const (
	EvidenceSchemaVersionArchitectureV2 = "stackkit.security-baseline/v2"
	EvidenceModeArchitectureV2          = "architecture-v2-foundation"
)

Variables

This section is empty.

Functions

func Build

func Build(cfg Config) (string, error)

Build renders a POSIX-sh compatible baseline script.

func ContractHash

func ContractHash(policy []byte) string

ContractHash returns the canonical sha256-prefixed digest of an exact rendered policy. It can be stored directly alongside a render unit for drift detection.

func RenderV2HostPolicy

func RenderV2HostPolicy() ([]byte, error)

RenderV2HostPolicy renders the canonical, self-contained architecture-v2 host policy. Renderers should use this convenience instead of constructing a v2 Config so the policy and its package-manager safety prelude cannot drift.

Types

type Config

type Config struct {
	Mode                         Mode
	PackageManagerLockWaitScript string
}

Config contains inputs for rendering a security-baseline script. The v2 policy is input-free apart from the package-manager safety prelude.

type Mode

type Mode string

Mode selects the governed policy generation. Architecture-v2 deliberately contains only target-neutral controls; access, identity, firewall, and routing remain owned by typed product modules.

const (
	ModeArchitectureV2 Mode = "architecture-v2"
)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL