Documentation
¶
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func ParseConfiguration ¶
func ParseConfiguration()
func ValidateConfiguration ¶
func ValidateConfiguration()
Types ¶
type DisallowedName ¶ added in v1.4.1
type DisallowedName struct {
// contains filtered or unexported fields
}
func (*DisallowedName) Decode ¶ added in v1.4.1
func (d *DisallowedName) Decode(value string) error
func (DisallowedName) Match ¶ added in v1.4.1
func (d DisallowedName) Match(value string) bool
func (DisallowedName) String ¶ added in v1.4.1
func (d DisallowedName) String() string
type Specification ¶
type Specification struct {
ContainerSocket string `json:"containerSocket" split_words:"true" required:"false"`
ContainerRuntime string `json:"containerRuntime" split_words:"true" required:"false"`
ContainerdNamespace string `json:"containerdNamespace" split_words:"true" required:"true" default:"k8s.io"`
DisableDiscoveryExcludes bool `required:"false" split_words:"true" default:"false"`
DiscoveryCallInterval string `json:"discoveryCallInterval" split_words:"true" required:"false" default:"15s"`
DiscoveryAttributesExcludes []string `` /* 174-byte string literal not displayed */
Port uint16 `json:"port" split_words:"true" required:"false" default:"8086"`
HealthPort uint16 `json:"healthPort" split_words:"true" required:"false" default:"8082"`
LivenessCheckInterval string `json:"livenessProbeInterval" split_words:"true" required:"false" default:"30s"` // 0 or empty string disables liveness check
Hostname string `json:"hostname" split_words:"true" required:"false"`
DisallowHostNetwork bool `json:"disallowHostNetwork" split_words:"true" required:"false" default:"false"`
DisallowK8sNamespaces []DisallowedName `json:"disallowK8sNamespaces" split_words:"true" required:"false"`
// NetworkStrictRootQdisc controls how network attacks behave on
// interfaces whose root qdisc isn't `noqueue` (e.g. the kernel default
// `mq` on managed-cloud nodes):
// - true (default): refuse the attack in the prepare step.
// - false: install the attack, but snapshot the root qdisc tree
// beforehand and replay it on revert so the cloud-tuned state
// (e.g. GKE's `mq + fq` with `buckets=32768 horizon=2s`) is
// preserved instead of being reset to kernel defaults.
// STEADYBIT_EXTENSION_NETWORK_STRICT_ROOT_QDISC
NetworkStrictRootQdisc bool `json:"networkStrictRootQdisc" split_words:"true" required:"false" default:"true"`
// TLSInterceptCaCert / TLSInterceptCaKey point at a PEM certificate authority
// used by 'Intercept Outgoing HTTP Request' to mint per-hostname certificates, which is
// what lets it return a synthesized response for an HTTPS dependency instead
// of cleartext HTTP only. Unset (the default) leaves HTTPS untouched.
//
// The CA is the customer's: they generate it, choose its validity, and install
// it in the truststores of the workloads they want to fault. Because it can
// impersonate any HTTPS endpoint to anything trusting it, mount it from a
// Secret and keep this to test environments.
// STEADYBIT_EXTENSION_TLS_INTERCEPT_CA_CERT / _KEY
TLSInterceptCaCert string `json:"tlsInterceptCaCert" split_words:"true" required:"false"`
TLSInterceptCaKey string `json:"tlsInterceptCaKey" split_words:"true" required:"false"`
// TLSInterceptLeafValidity is how long the per-hostname certificates the
// proxy mints stay valid. Shorter narrows the window in which a leaf that
// escaped the proxy could be used; it is always clamped to the CA's own
// expiry. Empty keeps the proxy's default (24h).
// STEADYBIT_EXTENSION_TLS_INTERCEPT_LEAF_VALIDITY
TLSInterceptLeafValidity time.Duration `json:"tlsInterceptLeafValidity" split_words:"true" required:"false"`
}
var (
Config Specification
)
func (Specification) TLSInterceptEnabled ¶ added in v1.8.0
func (s Specification) TLSInterceptEnabled() bool
TLSInterceptEnabled reports whether HTTPS response injection is configured.
Click to show internal directories.
Click to hide internal directories.