geoip

package
v0.1.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 5, 2026 License: Apache-2.0 Imports: 4 Imported by: 0

Documentation

Overview

Package geoip owns protocol-neutral ingress policy semantics and the narrow country-lookup port. It deliberately imports no HTTP, database, or runtime composition implementation.

Package geoip contains protocol-neutral GeoIP ingress policy semantics.

Index

Constants

View Source
const (
	MaxForwardedHeaderBytes  = 16 << 10
	MaxForwardedHops         = 32
	MaxDatabaseDownloadBytes = 128 << 20
	DatabaseOperationTimeout = 2 * time.Minute
	DefaultUpdateInterval    = 24 * time.Hour
	MinUpdateInterval        = 6 * time.Hour
	MaxUpdateInterval        = 168 * time.Hour
	UpdateJitterFraction     = 0.10
)

Variables

This section is empty.

Functions

This section is empty.

Types

type CompileInput

type CompileInput struct {
	Order Order
	Allow RuleConfig
	Deny  RuleConfig
}

CompileInput describes one immutable policy.

type CountryLookup

type CountryLookup interface {
	LookupCountry(netip.Addr) (country string, found bool, err error)
}

CountryLookup is the only database capability required by policy evaluation.

type Decision

type Decision struct {
	Allow  bool
	Reason Reason
}

Decision is the result of evaluating one normalized address.

type Order

type Order string

Order controls the Apache-style rule-class precedence.

const (
	// OrderDenyAllow evaluates deny first and allow second; allow wins ties and
	// the default is allow.
	OrderDenyAllow Order = "deny_allow"
	// OrderAllowDeny evaluates allow first and deny second; deny wins ties and
	// the default is deny.
	OrderAllowDeny Order = "allow_deny"
)

type Policy

type Policy struct {
	// contains filtered or unexported fields
}

Policy is immutable after Compile returns. Its maps and slices are private, and no accessor exposes mutable backing storage.

func Compile

func Compile(in CompileInput) (*Policy, error)

Compile validates and compiles a policy without retaining mutable caller data.

func (*Policy) Evaluate

func (p *Policy) Evaluate(addr netip.Addr, lookup CountryLookup) Decision

Evaluate applies the exact two-class truth table. Mapped IPv4 addresses are normalized before matching and lookup. A CIDR in the final precedence phase short-circuits country lookup because its outcome cannot be changed.

func (*Policy) NeedsCountryLookup

func (p *Policy) NeedsCountryLookup() bool

NeedsCountryLookup reports whether some address decisions may require a country lookup.

func (*Policy) Order

func (p *Policy) Order() Order

Order reports the immutable policy order.

type Reason

type Reason string

Reason is a finite, bounded decision classification suitable for metrics.

const (
	ReasonCIDRAllow     Reason = "cidr_allow"
	ReasonCIDRDeny      Reason = "cidr_deny"
	ReasonCountryAllow  Reason = "country_allow"
	ReasonCountryDeny   Reason = "country_deny"
	ReasonDefaultAllow  Reason = "default_allow"
	ReasonDefaultDeny   Reason = "default_deny"
	ReasonClientIPError Reason = "client_ip_error"
	ReasonLookupError   Reason = "lookup_error"
)

type RuleConfig

type RuleConfig struct {
	Countries []string
	CIDRs     []string
}

RuleConfig is a source representation for one rule class. Compile takes ownership of copies; callers may safely reuse or mutate their inputs later.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL