Documentation
¶
Overview ¶
Package geoip owns protocol-neutral ingress policy semantics and the narrow country-lookup port. It deliberately imports no HTTP, database, or runtime composition implementation.
Package geoip contains protocol-neutral GeoIP ingress policy semantics.
Index ¶
Constants ¶
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type CompileInput ¶
type CompileInput struct {
Order Order
Allow RuleConfig
Deny RuleConfig
}
CompileInput describes one immutable policy.
type CountryLookup ¶
CountryLookup is the only database capability required by policy evaluation.
type Policy ¶
type Policy struct {
// contains filtered or unexported fields
}
Policy is immutable after Compile returns. Its maps and slices are private, and no accessor exposes mutable backing storage.
func Compile ¶
func Compile(in CompileInput) (*Policy, error)
Compile validates and compiles a policy without retaining mutable caller data.
func (*Policy) Evaluate ¶
func (p *Policy) Evaluate(addr netip.Addr, lookup CountryLookup) Decision
Evaluate applies the exact two-class truth table. Mapped IPv4 addresses are normalized before matching and lookup. A CIDR in the final precedence phase short-circuits country lookup because its outcome cannot be changed.
func (*Policy) NeedsCountryLookup ¶
NeedsCountryLookup reports whether some address decisions may require a country lookup.
type Reason ¶
type Reason string
Reason is a finite, bounded decision classification suitable for metrics.
const ( ReasonCIDRAllow Reason = "cidr_allow" ReasonCIDRDeny Reason = "cidr_deny" ReasonCountryAllow Reason = "country_allow" ReasonCountryDeny Reason = "country_deny" ReasonDefaultAllow Reason = "default_allow" ReasonDefaultDeny Reason = "default_deny" ReasonClientIPError Reason = "client_ip_error" ReasonLookupError Reason = "lookup_error" )
type RuleConfig ¶
RuleConfig is a source representation for one rule class. Compile takes ownership of copies; callers may safely reuse or mutate their inputs later.