api

package
v1.14.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 31, 2026 License: Apache-2.0 Imports: 36 Imported by: 0

Documentation

Overview

Package api provides primitives to interact with the openapi HTTP API.

Code generated by github.com/oapi-codegen/oapi-codegen/v2 version v2.7.1 DO NOT EDIT.

Package api contains the HTTP handlers for the longue-vue REST API and the server/model code generated from api/openapi/openapi.yaml.

Run `go generate ./...` (or `make generate`) after editing the OpenAPI specification to refresh api.gen.go.

Index

Constants

View Source
const (
	BearerAuthScopes    bearerAuthContextKey    = "BearerAuth.Scopes"
	SessionCookieScopes sessionCookieContextKey = "SessionCookie.Scopes"
)
View Source
const (
	CloudAccountStatusPendingCredentials = "pending_credentials"
	CloudAccountStatusActive             = "active"
	CloudAccountStatusError              = "error"
	CloudAccountStatusDisabled           = "disabled"
)

CloudAccount status constants — matches the CHECK constraint on the cloud_accounts table.

View Source
const (
	LayerCluster               = InfrastructureLogical
	LayerNode                  = InfrastructurePhysical
	LayerNamespace             = InfrastructureLogical
	LayerPod                   = Applicative
	LayerWorkload              = Applicative
	LayerService               = Applicative
	LayerIngress               = Applicative
	LayerPersistentVolume      = InfrastructurePhysical
	LayerPersistentVolumeClaim = Applicative
)

Per-entity ANSSI cartography layer assignments, per ADR-0002. The layer is a property of the entity *kind*, not of any individual row, so it is set by the server on every response rather than persisted.

When adding a new entity kind, add its layer constant here and use the matching decorator helper below in its handlers.

View Source
const (
	DefaultVerifyRateLimitRPS   = 100
	DefaultVerifyRateLimitBurst = 200
)

Default per-IP limits for the ingest /v1/auth/verify endpoint (ADR-0016 §5). Generous enough that a healthy gateway never hits it, strict enough to make a buggy build that bypassed the verify cache visible immediately. The "source IP" in practice is always the gateway pod's IP since this listener is only reachable across one mTLS hop — but with many push-collectors fanning through a single gateway IP, operators may need to raise these via LONGUE_VUE_VERIFY_RATE_LIMIT_{RPS,BURST}.

View Source
const (
	SourceCollector = "collector"
	SourceAPI       = "api"
)

Source discriminators for reconcilable rows. Collector-originated rows are swept on each tick; API-originated rows survive reconcile.

View Source
const AuditSourceAPI = "api"

AuditSourceAPI discriminates API-originated audit_events.source rows (ADR-0016; the column also admits "ingest_gw" and "system"). Separate from the Kyverno reconcilable-source constants to avoid cross-domain coupling — the values happen to overlap but the domains are distinct.

Variables

View Source
var (
	ErrNotFound = errors.New("not found")
	ErrConflict = errors.New("conflict")
	// ErrLastAdmin is returned by UpdateUserGuarded / DeleteUserGuarded
	// when a patch or delete would leave the deployment with zero active
	// admin users. The transactional guard closes the TOCTOU race that a
	// handler-level CountActiveAdmins + UPDATE pair would otherwise leave
	// open under concurrent admin-degrading requests (audit finding H1).
	ErrLastAdmin = errors.New("last admin")
	// ErrInvalidCursor is returned by List* methods when a pagination
	// cursor is malformed, or was minted under different sort/order
	// parameters than the current request. Handlers translate it into
	// a 400 problem+json.
	ErrInvalidCursor = errors.New("invalid cursor")
	// ErrInvalidSort is returned by List* methods when sort/order are
	// not in the entity's allowlist. Handlers translate it into a 400
	// problem+json.
	ErrInvalidSort = errors.New("invalid sort")
)

Sentinel errors returned by Store implementations. Handlers translate these into RFC 7807 responses with the matching HTTP status.

View Source
var IngestRoutes = []struct {
	Method  string
	Pattern string
}{

	{http.MethodPost, "/v1/auth/verify"},

	{http.MethodPost, "/v1/clusters"},
	{http.MethodPatch, "/v1/clusters/{id}"},

	{http.MethodPost, "/v1/nodes"},
	{http.MethodPost, "/v1/nodes/reconcile"},
	{http.MethodPost, "/v1/namespaces"},
	{http.MethodPost, "/v1/namespaces/reconcile"},
	{http.MethodPost, "/v1/pods"},
	{http.MethodPost, "/v1/pods/reconcile"},
	{http.MethodPost, "/v1/workloads"},
	{http.MethodPost, "/v1/workloads/reconcile"},
	{http.MethodPost, "/v1/services"},
	{http.MethodPost, "/v1/services/reconcile"},
	{http.MethodPost, "/v1/ingresses"},
	{http.MethodPost, "/v1/ingresses/reconcile"},
	{http.MethodPost, "/v1/persistentvolumes"},
	{http.MethodPost, "/v1/persistentvolumes/reconcile"},
	{http.MethodPost, "/v1/persistentvolumeclaims"},
	{http.MethodPost, "/v1/persistentvolumeclaims/reconcile"},

	{http.MethodPost, "/v1/network-policies"},
	{http.MethodPost, "/v1/network-policies/reconcile"},
}

IngestRoutes is the canonical, hardcoded list of (method, path) pairs the ingest listener serves. Exposed for tests and security review — a single table of literals you can read out loud during an audit.

Keep this list synchronised with internal/ingestgw's gateway-side allowlist (ADR-0016 §2). A route that longue-vue serves but the gateway blocks is fine (defence in depth); a route the gateway forwards but longue-vue does not register here is a configuration error and produces a 404 at the listener.

Functions

func AsOfMiddleware

func AsOfMiddleware(store Store, authMiddleware func(http.Handler) http.Handler) func(next http.Handler) http.Handler

AsOfMiddleware wraps next and intercepts GET requests that carry a ?as_of=<RFC3339> query parameter for the four history-bearing entity paths. When ?as_of is present and the path matches /v1/{kind}/{id} (no trailing segment), the middleware resolves the snapshot from the history table and responds directly; otherwise it delegates to next.

authMiddleware is applied to the intercepted path so that auth.CallerFromContext is populated before serveAsOf checks it. Non-intercepted requests pass through to next (which has its own auth middleware via the generated router).

func DetectWorkloadUnlinkMiddleware added in v0.28.0

func DetectWorkloadUnlinkMiddleware(next http.Handler) http.Handler

DetectWorkloadUnlinkMiddleware records, for PATCH /v1/workloads/{id}, whether the body carries an explicit `"application_id": null`. It restores r.Body so the codegen decode still sees the full payload.

func GetSpec added in v1.12.1

func GetSpec() (swagger *openapi3.T, err error)

GetSpec returns the OpenAPI specification corresponding to the generated code in this file. External references in the spec are resolved through PathToRawSpec; externally-referenced files must be embedded in their corresponding Go packages (via the import-mapping feature). URL-based external refs are not supported.

func GetSpecJSON added in v1.12.1

func GetSpecJSON() ([]byte, error)

GetSpecJSON returns the raw JSON bytes of the embedded OpenAPI specification: decompressed but not unmarshaled. External references are not resolved here; the bytes are the spec exactly as embedded by codegen. The result is cached at package init time, so repeated calls are cheap.

func GetSwagger deprecated

func GetSwagger() (*openapi3.T, error)

GetSwagger returns the OpenAPI specification corresponding to the generated code in this file.

Deprecated: GetSwagger predates kin-openapi renaming openapi3.Swagger to openapi3.T. Use GetSpec instead. This wrapper is retained for backwards compatibility.

func HandleBackfillNodeImages added in v1.7.0

func HandleBackfillNodeImages(store Store) http.HandlerFunc

HandleBackfillNodeImages — vm-collector scope, bound to the cloud account. Backfills nodes.image_id/image_name from the reported node-VM mappings (ADR-0040). Vendor-neutral CMDB inventory; no outbound calls.

POST /v1/ingest/cloud-accounts/{id}/node-images Response: 200 {"matched":N,"updated":M}.

func HandleClusterFlowMatrix added in v1.2.0

func HandleClusterFlowMatrix(store Store) http.HandlerFunc

HandleClusterFlowMatrix — read scope. GET /v1/clusters/{id}/flow-matrix. Gated by flow_matrix_enabled; returns 409 problem+json when disabled. It loads the cluster's perimeter SG rules, internal NetworkPolicy rules, reference rows, and endpoint groups, flattens them into flowmatrix.Inputs, and serializes the read-time flowmatrix.Synthesis as JSON. The pure classification lives in internal/flowmatrix.

func HandleCollectorGetCredentialsByID

func HandleCollectorGetCredentialsByID(store Store, enc *secrets.Encrypter) http.HandlerFunc

HandleCollectorGetCredentialsByID — vm-collector scope. GET /v1/cloud-accounts/{id}/credentials.

func HandleCollectorGetCredentialsByName

func HandleCollectorGetCredentialsByName(store Store, enc *secrets.Encrypter) http.HandlerFunc

HandleCollectorGetCredentialsByName — vm-collector scope. GET /v1/cloud-accounts/by-name/{name}/credentials. Returns plaintext SK.

func HandleCollectorPatchCloudAccountStatus

func HandleCollectorPatchCloudAccountStatus(store Store) http.HandlerFunc

HandleCollectorPatchCloudAccountStatus — vm-collector scope. PATCH /v1/cloud-accounts/{id}/status.

func HandleCollectorRegisterCloudAccount

func HandleCollectorRegisterCloudAccount(store Store) http.HandlerFunc

HandleCollectorRegisterCloudAccount — vm-collector scope. POST /v1/cloud-accounts. Idempotent first-contact registration.

func HandleContainerFreshnessExtract added in v1.9.0

func HandleContainerFreshnessExtract(s Store, maxRows int) http.HandlerFunc

HandleContainerFreshnessExtract — read scope. GET /v1/container-freshness/extract?format=csv|json

Walks the full workload fleet via BuildContainerFreshness, flattens every deployed container into a ContainerFreshnessRow and emits CSV or JSON. The response body is buffered before flushing so the X-Longue-Vue-Truncated header can be written before any bytes hit the wire (mirrors HandleEolExtract).

func HandleCreateApplication added in v0.28.0

func HandleCreateApplication(store Store) http.HandlerFunc

HandleCreateApplication — write scope. POST /v1/applications. Idempotent on name: a duplicate returns 200 with the existing row; first insert returns 201. DICT validation runs BEFORE the store call so an invalid axis surfaces as 400, not a server-side 5xx.

func HandleCreateApplicationBlock added in v0.28.0

func HandleCreateApplicationBlock(store Store) http.HandlerFunc

HandleCreateApplicationBlock — write scope. POST /v1/application-blocks. Idempotent on name: returns 200 with the existing row on a duplicate, 201 with the new row on first insert. Mirrors EnsureCluster.

func HandleCreateCloudAccount

func HandleCreateCloudAccount(store Store, enc *secrets.Encrypter) http.HandlerFunc

HandleCreateCloudAccount — admin scope. POST /v1/admin/cloud-accounts.

func HandleCreateCloudAccountToken

func HandleCreateCloudAccountToken(store Store) http.HandlerFunc

HandleCreateCloudAccountToken — admin scope. Mints a vm-collector PAT bound to the cloud account in the URL path. Body: {name, expires_at?}. The plaintext is returned exactly once. Audit middleware scrubs the response body (responses are not logged) — this endpoint is safe to audit by request only.

func HandleCreateClusterPolicy added in v1.13.0

func HandleCreateClusterPolicy(store Store) http.HandlerFunc

HandleCreateClusterPolicy serves POST /v1/cluster-policies: upsert by (cluster_id, namespace_id, name), source='api' (ADR-0043 §3b).

func HandleCreateEndpointGroup added in v1.2.0

func HandleCreateEndpointGroup(store Store) http.HandlerFunc

HandleCreateEndpointGroup — admin scope. POST /v1/admin/endpoint-groups.

func HandleCreateFlowReference added in v1.2.0

func HandleCreateFlowReference(store Store) http.HandlerFunc

HandleCreateFlowReference — editor scope. POST /v1/clusters/{id}/flow-references.

func HandleCreateImageRegistry

func HandleCreateImageRegistry(s Store) http.Handler

HandleCreateImageRegistry inserts a new registry row. Returns 400 on bad input, 409 on hostname conflict, 201 with the row otherwise.

func HandleCreatePolicyReport added in v1.13.0

func HandleCreatePolicyReport(store Store) http.HandlerFunc

HandleCreatePolicyReport serves POST /v1/policy-reports: upsert by (cluster_id, namespace_id, name), source='api' (ADR-0043 §3b).

func HandleDeleteApplication added in v0.28.0

func HandleDeleteApplication(store Store) http.HandlerFunc

HandleDeleteApplication — admin scope. DELETE /v1/applications/{id}. Migration 00047 declares ON DELETE SET NULL on workloads.application_id and virtual_machines.application_id, so dependent rows survive (curated linkage is cleared). The store additionally sweeps VM-app JSONB entries inside the same transaction.

func HandleDeleteApplicationBlock added in v0.28.0

func HandleDeleteApplicationBlock(store Store) http.HandlerFunc

HandleDeleteApplicationBlock — admin scope. DELETE /v1/application-blocks/{id}. Migration 00046 declares ON DELETE SET NULL on applications.application_block_id, so dependent Applications survive (just become un-blocked).

func HandleDeleteCloudAccount

func HandleDeleteCloudAccount(store Store) http.HandlerFunc

HandleDeleteCloudAccount — admin scope. DELETE .../{id}.

func HandleDeleteClusterPolicy added in v1.13.0

func HandleDeleteClusterPolicy(store Store) http.HandlerFunc

HandleDeleteClusterPolicy serves DELETE /v1/cluster-policies/{id}. Only API-authored rows (source='api') can be deleted; collector-managed rows return 404 (ADR-0043 §3b).

func HandleDeleteEndpointGroup added in v1.2.0

func HandleDeleteEndpointGroup(store Store) http.HandlerFunc

HandleDeleteEndpointGroup — admin scope. DELETE /v1/admin/endpoint-groups/{id}.

func HandleDeleteFlowReference added in v1.2.0

func HandleDeleteFlowReference(store Store) http.HandlerFunc

HandleDeleteFlowReference — editor scope. DELETE /v1/flow-references/{id}.

func HandleDeleteImageRegistry

func HandleDeleteImageRegistry(s Store) http.Handler

HandleDeleteImageRegistry removes a registry. Returns 204 on success.

func HandleDeletePolicyReport added in v1.13.0

func HandleDeletePolicyReport(store Store) http.HandlerFunc

HandleDeletePolicyReport serves DELETE /v1/policy-reports/{id}. Only API-authored rows (source='api') can be deleted; collector-managed rows return 404 (ADR-0043 §3b).

func HandleDeleteVirtualMachine

func HandleDeleteVirtualMachine(store Store) http.HandlerFunc

HandleDeleteVirtualMachine — delete scope. DELETE /v1/virtual-machines/{id}.

func HandleDisableCloudAccount

func HandleDisableCloudAccount(store Store) http.HandlerFunc

HandleDisableCloudAccount — admin scope. POST .../{id}/disable.

func HandleEnableCloudAccount

func HandleEnableCloudAccount(store Store) http.HandlerFunc

HandleEnableCloudAccount — admin scope. POST .../{id}/enable.

func HandleEntityHistory

func HandleEntityHistory(store Store, kind string) http.HandlerFunc

HandleEntityHistory returns the paginated history for one entity. Route: GET /v1/{kind}/{id}/history kind is one of: clusters, namespaces, nodes, workloads.

func HandleEolExtract added in v0.22.0

func HandleEolExtract(store ExtractStore, maxRows int) http.HandlerFunc

HandleEolExtract — read scope. GET /v1/eol/extract?format=csv|json [&entity_type=...&status=...]. Iterates clusters / nodes / VMs, flattens EOL annotations via internal/eolagg, applies optional filters, and emits CSV or JSON. The response body is buffered before flushing so the X-Longue-Vue-Truncated header can be written before any bytes hit the wire — at the row cap, peak buffer is ~10 MB.

func HandleExportFlowReferences added in v1.2.0

func HandleExportFlowReferences(store Store) http.HandlerFunc

HandleExportFlowReferences — read scope. GET /v1/clusters/{id}/flow-references/export. Emits a text/yaml document of the cluster's reference rows, suitable for version control and round-tripping through the import endpoint.

func HandleExtractApplicationsCSV added in v0.28.0

func HandleExtractApplicationsCSV(store ApplicationExtractStore, maxRows int) http.HandlerFunc

HandleExtractApplicationsCSV — read scope. GET /v1/applications/extract.csv. Accepts the same filters as GET /v1/applications.

func HandleExtractApplicationsJSON added in v0.28.0

func HandleExtractApplicationsJSON(store ApplicationExtractStore, maxRows int) http.HandlerFunc

HandleExtractApplicationsJSON — read scope. GET /v1/applications/extract.json. Accepts the same filters as GET /v1/applications.

func HandleFlowMatrixExtract added in v1.2.0

func HandleFlowMatrixExtract(store Store, maxRows int) http.HandlerFunc

HandleFlowMatrixExtract — read scope. GET /v1/clusters/{id}/flow-matrix/extract?format=csv|json. Gated by flow_matrix_enabled (409). Serializes the perimeter+internal flows as CSV (default) or a JSON envelope, capped at maxRows with the truncation header set before any bytes are written. Audited via the shouldAudit allowlist.

func HandleFlowMatrixExtractZip added in v1.2.0

func HandleFlowMatrixExtractZip(store Store, maxRows int) http.HandlerFunc

HandleFlowMatrixExtractZip — read scope. GET /v1/clusters/{id}/flow-matrix/extract.zip. Bundles flow-matrix.csv (same rows/columns as the flat CSV extract) plus _sources.json (deduped {kind,id} from every Flow.Sources). Gated by flow_matrix_enabled (409), capped at maxRows with the truncation header set before any bytes, and audited via the shouldAudit allowlist.

func HandleGetApplication added in v0.28.0

func HandleGetApplication(store Store) http.HandlerFunc

HandleGetApplication — read scope. GET /v1/applications/{id}.

func HandleGetApplicationBlock added in v0.28.0

func HandleGetApplicationBlock(store Store) http.HandlerFunc

HandleGetApplicationBlock — read scope. GET /v1/application-blocks/{id}.

func HandleGetApplicationByName added in v0.28.0

func HandleGetApplicationByName(store Store) http.HandlerFunc

HandleGetApplicationByName — read scope. GET /v1/applications/by-name/{name}. The handler normalises the path value (NormalizeApplicationName ⇒ kebab-case) so operator-typed "HashiCorp Vault" matches the stored "hashicorp-vault" row. The store applies the same normalisation, so the explicit step here is defence-in-depth.

func HandleGetApplicationEOL added in v0.28.0

func HandleGetApplicationEOL(store Store) http.HandlerFunc

HandleGetApplicationEOL — read scope. GET /v1/applications/{id}/eol. Confirms the application exists (404 if not), then read-time aggregates the EOL signal across its three member sources (workloads' image-versions enrichment, linked VMs' annotations, and VM-application JSONB entries whose per-entry application_id matches — even when the parent VM is not itself linked). No enricher pass, no DB writes (ADR-0029 §5).

func HandleGetCloudAccount

func HandleGetCloudAccount(store Store) http.HandlerFunc

HandleGetCloudAccount — admin scope. GET /v1/admin/cloud-accounts/{id}.

func HandleGetClusterPolicy added in v1.13.0

func HandleGetClusterPolicy(store Store) http.HandlerFunc

HandleGetClusterPolicy serves GET /v1/cluster-policies/{id}.

func HandleGetEndpointGroup added in v1.2.0

func HandleGetEndpointGroup(store Store) http.HandlerFunc

HandleGetEndpointGroup — read scope. GET /v1/admin/endpoint-groups/{id}.

func HandleGetImageRegistryCredentials added in v0.24.0

func HandleGetImageRegistryCredentials(s Store) http.Handler

HandleGetImageRegistryCredentials returns the plaintext robot-account credentials for a mirror registry row. Admin-only, audit-logged.

func HandleGetImageVersion

func HandleGetImageVersion(s Store) http.Handler

HandleGetImageVersion returns the detail (all variants) for one image_repo. The image_repo path parameter is URL-encoded.

func HandleGetNetworkPolicy added in v1.1.0

func HandleGetNetworkPolicy(store Store) http.HandlerFunc

HandleGetNetworkPolicy — read scope. GET /v1/network-policies/{id}.

Fetches the policy by UUID and embeds all its rules in the response. 404 when the policy does not exist.

func HandleGetPolicyReport added in v1.13.0

func HandleGetPolicyReport(store Store) http.HandlerFunc

HandleGetPolicyReport serves GET /v1/policy-reports/{id}.

func HandleGetSecurityGroup added in v1.1.0

func HandleGetSecurityGroup(store Store) http.HandlerFunc

HandleGetSecurityGroup — read scope. GET /v1/security-groups/{id}.

Fetches the security group by UUID and embeds all its rules in the response. 404 when the group does not exist.

func HandleGetSettings

func HandleGetSettings(store Store) http.HandlerFunc

HandleGetSettings returns the current runtime settings.

func HandleGetVirtualMachine

func HandleGetVirtualMachine(store Store) http.HandlerFunc

HandleGetVirtualMachine — read scope. GET /v1/virtual-machines/{id}.

func HandleImportFlowReferences added in v1.2.0

func HandleImportFlowReferences(store Store) http.HandlerFunc

HandleImportFlowReferences — editor scope. POST /v1/clusters/{id}/flow-references/import. Replace-all (OQ-1): the posted YAML document fully supersedes the cluster's existing reference rows. Every entry is validated before any write; a single invalid row fails the whole import with a 409 naming the offending index.

func HandleListApplicationBlocks added in v0.28.0

func HandleListApplicationBlocks(store Store) http.HandlerFunc

HandleListApplicationBlocks — read scope. GET /v1/application-blocks. Query params: name (ci substring / anchored glob over name + display_name), owner (exact), plus the uniform limit + cursor + sort + order controls.

func HandleListApplicationMembers added in v0.28.0

func HandleListApplicationMembers(store Store) http.HandlerFunc

HandleListApplicationMembers — read scope. GET /v1/applications/{id}/members. Returns the three-source walk (workloads + VMs + VM-app JSONB entries) in stable order, optionally narrowed to a single source via kind= (workload | virtual_machine | vm_application). Pagination keeps the bespoke members cursor (offset walk across the sources).

func HandleListApplications added in v0.28.0

func HandleListApplications(store Store) http.HandlerFunc

HandleListApplications — read scope. GET /v1/applications. Filter params: name (substring / anchored glob), application_block_id (UUID), application_block_name, criticality, has_dict (bool), dict_min (int 0..4), plus the uniform cursor + limit + sort + order controls.

func HandleListCloudAccounts

func HandleListCloudAccounts(store Store) http.HandlerFunc

HandleListCloudAccounts — admin scope. Paginated list.

func HandleListClusterPolicies added in v1.13.0

func HandleListClusterPolicies(store Store) http.HandlerFunc

HandleListClusterPolicies serves GET /v1/cluster-policies with the cursor-paginated, filterable policy inventory (ADR-0043).

func HandleListContainerFreshness added in v1.9.0

func HandleListContainerFreshness(s Store) http.HandlerFunc

HandleListContainerFreshness handles GET /v1/container-freshness. Query params: image, freshness, cluster, namespace, kind, limit, cursor.

func HandleListDistinctVMApplications

func HandleListDistinctVMApplications(store Store) http.HandlerFunc

HandleListDistinctVMApplications — read scope. GET /v1/virtual-machines/applications/distinct. Used by the UI to populate the application-filter autocomplete (ADR-0019 §3).

func HandleListEndpointGroups added in v1.2.0

func HandleListEndpointGroups(store Store) http.HandlerFunc

HandleListEndpointGroups — read scope. GET /v1/admin/endpoint-groups.

func HandleListFlowReferences added in v1.2.0

func HandleListFlowReferences(store Store) http.HandlerFunc

HandleListFlowReferences — read scope. GET /v1/clusters/{id}/flow-references.

func HandleListImageRegistries

func HandleListImageRegistries(s Store) http.Handler

HandleListImageRegistries returns all rows from image_versions_registries.

func HandleListImageVersions

func HandleListImageVersions(s Store) http.Handler

HandleListImageVersions returns a paginated list of distinct image_repos with their variants nested. Filters: registry, image_repo (substring), variant, has_error, last_checked_before. Pagination via opaque cursor.

func HandleListNetworkPolicies added in v1.1.0

func HandleListNetworkPolicies(store Store) http.HandlerFunc

HandleListNetworkPolicies — read scope. GET /v1/network-policies.

Required query param: cluster_id (UUID). Optional: namespace_id (UUID), name (substring/glob, max 100), sort, order, limit, cursor.

Errors: 400 on missing/invalid params or invalid sort/cursor; 500 on store failure.

func HandleListOSImages added in v1.7.0

func HandleListOSImages(store Store) http.HandlerFunc

HandleListOSImages — read scope. GET /v1/os-images. Returns the deduplicated inventory of OS images in service (cloud VMs ∪ cluster nodes), keyed by image name (ADR-0040). Vendor-neutral CMDB inventory.

func HandleListPolicyReports added in v1.13.0

func HandleListPolicyReports(store Store) http.HandlerFunc

HandleListPolicyReports serves GET /v1/policy-reports with the cursor-paginated, filterable report inventory (ADR-0043).

func HandleListSecurityGroups added in v1.1.0

func HandleListSecurityGroups(store Store) http.HandlerFunc

HandleListSecurityGroups — read scope. GET /v1/security-groups.

Required query param: cloud_account_id (UUID). Optional: name (substring/glob, max 100), sort, order, limit, cursor.

func HandleListVirtualMachines

func HandleListVirtualMachines(store Store) http.HandlerFunc

HandleListVirtualMachines — read scope. GET /v1/virtual-machines.

func HandlePatchApplication added in v0.28.0

func HandlePatchApplication(store Store) http.HandlerFunc

HandlePatchApplication — write scope. PATCH /v1/applications/{id}. Merge-patch on the mutable fields (name intentionally NOT mutable here — renaming would orphan inbound links). DICT validation runs BEFORE the store call.

func HandlePatchApplicationBlock added in v0.28.0

func HandlePatchApplicationBlock(store Store) http.HandlerFunc

HandlePatchApplicationBlock — write scope. PATCH /v1/application-blocks/{id}. Merge-patch on the mutable fields; name is intentionally NOT mutable here (ADR-0029 §2.2 — renaming would orphan inbound links).

func HandlePatchCloudAccount

func HandlePatchCloudAccount(store Store) http.HandlerFunc

HandlePatchCloudAccount — admin scope. PATCH /v1/admin/cloud-accounts/{id}.

func HandlePatchCloudAccountCredentials

func HandlePatchCloudAccountCredentials(store Store, enc *secrets.Encrypter) http.HandlerFunc

HandlePatchCloudAccountCredentials — admin scope. PATCH /v1/admin/cloud-accounts/{id}/credentials. SK is encrypted with AES-256-GCM, AAD = row UUID.

func HandlePatchVirtualMachine

func HandlePatchVirtualMachine(store Store) http.HandlerFunc

HandlePatchVirtualMachine — write scope. PATCH /v1/virtual-machines/{id}.

func HandleReconcileVirtualMachines

func HandleReconcileVirtualMachines(store Store) http.HandlerFunc

HandleReconcileVirtualMachines — vm-collector scope. POST /v1/virtual-machines/reconcile.

func HandleRefreshImageVersions

func HandleRefreshImageVersions(s Store, enr EnricherTrigger) http.Handler

HandleRefreshImageVersions triggers an immediate enrichment cycle. Returns 409 if the feature is disabled, 202 with {queued, already_running} otherwise.

func HandleSearchExtract added in v0.22.0

func HandleSearchExtract(store ExtractStore, maxRows int) http.HandlerFunc

HandleSearchExtract — read scope. GET /v1/search/extract?q=...&kind=workloads|pods|virtual_machines&format=csv|json[&application=<substring>] Searches container images (workloads/pods) or VM image/application (virtual_machines). ADR-0029 §2.4: optional `application` parameter narrows to entities linked to an application whose name matches the substring (case-insensitive).

func HandleSearchExtractZip added in v0.22.0

func HandleSearchExtractZip(store ExtractStore, maxRows int) http.HandlerFunc

HandleSearchExtractZip — read scope. GET /v1/search/extract.zip?q=... Returns a ZIP bundle of workloads.csv + pods.csv + virtual_machines.csv + README.txt. Truncation is a per-CSV decision; if any of the three exceeds maxRows it is truncated independently and X-Longue-Vue-Truncated is set on the response. Row counts in the README reflect the truncated counts.

func HandleSweepSecurityGroups added in v1.1.0

func HandleSweepSecurityGroups(store Store) http.HandlerFunc

HandleSweepSecurityGroups — vm-collector scope, bound to the cloud account. Deletes every security group in the account whose provider_sg_id is NOT in the request's seen_provider_sg_ids list. Called once per account refresh tick after all VM upserts are done.

POST /v1/ingest/cloud-accounts/{id}/security-groups/sweep Response: 204 No Content on success.

func HandleUpdateEndpointGroup added in v1.2.0

func HandleUpdateEndpointGroup(store Store) http.HandlerFunc

HandleUpdateEndpointGroup — admin scope. PATCH /v1/admin/endpoint-groups/{id}.

func HandleUpdateFlowReference added in v1.2.0

func HandleUpdateFlowReference(store Store) http.HandlerFunc

HandleUpdateFlowReference — editor scope. PATCH /v1/flow-references/{id}.

func HandleUpdateImageRegistry

func HandleUpdateImageRegistry(s Store) http.Handler

HandleUpdateImageRegistry applies a merge-patch to a registry row.

func HandleUpdateSettings

func HandleUpdateSettings(store Store) http.HandlerFunc

HandleUpdateSettings applies a merge-patch on the settings row.

func HandleUpsertVirtualMachine

func HandleUpsertVirtualMachine(store Store) http.HandlerFunc

HandleUpsertVirtualMachine — vm-collector scope. POST /v1/virtual-machines.

func HandleVMNetworkRules added in v1.1.0

func HandleVMNetworkRules(store Store) http.HandlerFunc

HandleVMNetworkRules — read scope. GET /v1/virtual-machines/{id}/network-rules

Returns the security groups attached to the VM (via the canonical security_groups JSONB column) and their rules. When the VM's security_groups field predates the canonical schema, stale: true is returned and the caller should await the next collector tick.

func HandleWorkloadNetworkRules added in v1.1.0

func HandleWorkloadNetworkRules(store Store) http.HandlerFunc

HandleWorkloadNetworkRules — read scope. GET /v1/workloads/{id}/network-rules

Returns every NetworkPolicy in the workload's namespace whose pod_selector matchLabels is a subset of the workload's labels (Postgres @> operator). The empty selector (`{}`) matches everything. Rules for each matching policy are embedded in the response. When no policy matches, k8s_default_allow: true is returned to signal the Kubernetes "open by default" posture.

func Handler

func Handler(si ServerInterface) http.Handler

Handler creates http.Handler with routing matching OpenAPI spec.

func HandlerFromMux

func HandlerFromMux(si ServerInterface, m ServeMux) http.Handler

HandlerFromMux creates http.Handler with routing matching OpenAPI spec based on the provided mux.

func HandlerFromMuxWithBaseURL

func HandlerFromMuxWithBaseURL(si ServerInterface, m ServeMux, baseURL string) http.Handler

func HandlerWithOptions

func HandlerWithOptions(si ServerInterface, options StdHTTPServerOptions) http.Handler

HandlerWithOptions creates http.Handler with additional options

func IsCanonicalSGPayload added in v1.1.0

func IsCanonicalSGPayload(raw json.RawMessage) bool

IsCanonicalSGPayload returns true when the JSONB carries a schema_version >= 1. Pre-deploy rows (missing or zero version) return false; the VM ingest handler skips SG persistence for those rows and they are rendered with stale=true by the read path.

func LoadFlowInputsForMetrics added in v1.2.0

func LoadFlowInputsForMetrics(ctx context.Context, store Store, clusterID uuid.UUID) (flowmatrix.Inputs, []flowmatrix.Warning, error)

LoadFlowInputsForMetrics exposes loadFlowInputs to the metrics refresh loop (package main and the metricsrefresh package cannot reach the unexported helper). Returns the same inputs + warnings the synthesis handler uses.

func NewIngestMux

func NewIngestMux(cfg IngestMuxConfig) *http.ServeMux

NewIngestMux builds the http.ServeMux for the ingest listener. Returns a fully wired handler — caller mounts it on its own *http.Server with the appropriate tls.Config (mTLS, RequireAndVerifyClientCert).

The returned mux registers exactly len(IngestRoutes) handlers; a request to any other path/method returns 404 by net/http's default.

func NormalizeApplicationName added in v0.28.0

func NormalizeApplicationName(s string) string

NormalizeApplicationName normalises an Application or ApplicationBlock name for use as a stable key: trim → lowercase → collapse runs of whitespace, underscores, and hyphens into single hyphens. Delegates to NormalizeProductName (cloud_types.go) so Application names follow the same kebab-case convention as VMApplication.Product (ADR-0019).

func NormalizeProductName

func NormalizeProductName(s string) string

NormalizeProductName collapses operator-typed product names into a stable kebab-case key. Trim, lowercase, collapse runs of whitespace and underscores into single hyphens. The result is what gets indexed, matched, and used as the suffix in `longue-vue.io/eol.<product>` annotations.

func PathToRawSpec

func PathToRawSpec(pathToFile string) map[string]func() ([]byte, error)

Constructs a synthetic filesystem for resolving external references when loading openapi specifications.

func ResolveApplicationID added in v0.28.0

func ResolveApplicationID(
	ctx context.Context,
	store Store,
	id *uuid.UUID,
	name *string,
) (*uuid.UUID, error)

ResolveApplicationID picks the application id from (id, name).

Precedence (ADR-0029 §2.3): id wins when both are set; mirrors the cloud_account_id / cloud_account_name precedence from ADR-0019.

Returns:

  • (id, nil) when id is non-nil and the row exists.
  • (&app.ID, nil) when only name is non-nil/non-empty and resolves.
  • (nil, nil) when neither is provided (caller treats as "no change").
  • (nil, error) on lookup failures, including a 400-friendly "not found" error wrapped around api.ErrNotFound so callers can map to RFC 7807.

The helper is shared by the workload and virtual-machine PATCH handlers (Task 2.2 / 2.3) and by any future surface that accepts the same {id, name} pair.

func SecurityHeadersMiddleware

func SecurityHeadersMiddleware(trustedProxies []*net.IPNet, forceHSTS bool) func(http.Handler) http.Handler

SecurityHeadersMiddleware sets security-related HTTP headers on every response.

HSTS gating (ADR-0017): the header is emitted when the request actually arrived over TLS — either natively (r.TLS != nil) or via a TLS-terminating proxy whose peer address is in `trustedProxies`. With an empty trust list, X-Forwarded-Proto is ignored entirely so an attacker connecting directly can never spoof "https" and steer the trust posture of the response.

`forceHSTS` reflects the operator's LONGUE_VUE_REQUIRE_HTTPS=true declaration that the deployment is HTTPS-only. When set, HSTS is emitted on every response regardless of the per-request shape — a browser that ever lands on the public hostname is told never to downgrade, even if a stray plain HTTP request slipped through.

func SetAuditDetails

func SetAuditDetails(ctx context.Context, details map[string]any)

SetAuditDetails stores extra detail fields in the audit bag carried by ctx. Handlers call this to enrich the audit event with domain- specific data (e.g., a pre-deletion cascade snapshot per ADR-0010). Safe to call when no bag is present (no-op).

func SetAuditSkip added in v0.20.0

func SetAuditSkip(ctx context.Context)

SetAuditSkip marks the current request as droppable by the audit middleware. Handlers call this when the request did not change any business state (e.g., a collector upsert that touched only clock fields, or a reconcile that deleted zero rows). The middleware honors the flag unless the response status is >= 400 (forensic) or the path is on the auth-endpoint allowlist. See ADR-0024.

Safe to call when no bag is present (no-op).

func SetAuditSkipReason added in v0.20.0

func SetAuditSkipReason(ctx context.Context, reason string)

SetAuditSkipReason overrides the default "no_change" reason label on the Prometheus skipped counter. Call from reconcile handlers that dropped zero rows with reason="reconcile_empty".

func SummarizeAndFilterContainerFreshness added in v1.9.0

func SummarizeAndFilterContainerFreshness(ws []Workload, f ContainerFreshnessFilter) ([]ContainerFreshnessRow, ContainerFreshnessSummary)

SummarizeAndFilterContainerFreshness flattens the deployed containers from every Workload in ws into a []ContainerFreshnessRow and a ContainerFreshnessSummary. Every container with a non-empty name and image produces a row; containers lacking version enrichment are reported with the "unknown" freshness tier. Summary counts reflect the full unfiltered set so the caller can display total coverage regardless of which filter is active.

func VMApplicationKey

func VMApplicationKey(a *VMApplication) string

VMApplicationKey returns a stable identity key for diffing PATCH input against the existing applications list — `(product, version, name)` so two `vault@1.15.4` entries with different `name` labels are distinct.

Types

type APITokenInsert

type APITokenInsert struct {
	ID              uuid.UUID
	Name            string
	Prefix          string
	Hash            string
	Scopes          []string
	CreatedByUserID uuid.UUID
	ExpiresAt       *time.Time
	// BoundCloudAccountID is set when minting a vm-collector PAT
	// (ADR-0015). The store persists it on the api_tokens row;
	// nullable for every other token kind.
	BoundCloudAccountID *uuid.UUID
}

APITokenInsert carries the persistable fields for a new minted token. The plaintext itself is never persisted �� only `Prefix` (cleartext) and `Hash` (argon2id).

type APITokenListFilter added in v1.10.0

type APITokenListFilter struct {
	Name *string
}

APITokenListFilter is the predicate set accepted by ListAPITokens.

type ApiToken

type ApiToken struct {
	CreatedAt       *time.Time          `json:"created_at,omitempty"`
	CreatedByUserId *openapi_types.UUID `json:"created_by_user_id,omitempty"`
	ExpiresAt       *time.Time          `json:"expires_at,omitempty"`
	Id              *openapi_types.UUID `json:"id,omitempty"`
	LastUsedAt      *time.Time          `json:"last_used_at,omitempty"`

	// Name Human-chosen label (e.g., `"ci-release-pipeline"`).
	Name string `json:"name"`

	// Prefix First 8 characters of the plaintext token. Displayed alongside
	// the token name so operators can identify which token is in use
	// without revealing the full value.
	Prefix    *string    `json:"prefix,omitempty"`
	RevokedAt *time.Time `json:"revoked_at,omitempty"`
	Scopes    []string   `json:"scopes"`
}

ApiToken Metadata for a machine token. The plaintext is never in this response — it's only returned once by `createApiToken`.

type ApiTokenCreate

type ApiTokenCreate struct {
	// ExpiresAt Optional expiry. If absent, the token is valid until revoked.
	ExpiresAt *time.Time `json:"expires_at,omitempty"`
	Name      string     `json:"name"`

	// Scopes Scopes to grant. Admin scope cannot be granted to tokens —
	// admin-only endpoints are session-only for accountability.
	Scopes []ApiTokenCreateScopes `json:"scopes"`
}

ApiTokenCreate Payload to mint a new machine token.

type ApiTokenCreateScopes

type ApiTokenCreateScopes string

ApiTokenCreateScopes defines model for ApiTokenCreate.Scopes.

const (
	Delete ApiTokenCreateScopes = "delete"
	Read   ApiTokenCreateScopes = "read"
	Write  ApiTokenCreateScopes = "write"
)

Defines values for ApiTokenCreateScopes.

func (ApiTokenCreateScopes) Valid

func (e ApiTokenCreateScopes) Valid() bool

Valid indicates whether the value is a known member of the ApiTokenCreateScopes enum.

type ApiTokenList

type ApiTokenList struct {
	Items      []ApiToken `json:"items"`
	NextCursor *string    `json:"next_cursor,omitempty"`
}

ApiTokenList Paged list of tokens.

type ApiTokenMint

type ApiTokenMint struct {
	CreatedAt       *time.Time          `json:"created_at,omitempty"`
	CreatedByUserId *openapi_types.UUID `json:"created_by_user_id,omitempty"`
	ExpiresAt       *time.Time          `json:"expires_at,omitempty"`
	Id              *openapi_types.UUID `json:"id,omitempty"`
	LastUsedAt      *time.Time          `json:"last_used_at,omitempty"`

	// Name Human-chosen label (e.g., `"ci-release-pipeline"`).
	Name string `json:"name"`

	// Prefix First 8 characters of the plaintext token. Displayed alongside
	// the token name so operators can identify which token is in use
	// without revealing the full value.
	Prefix    *string    `json:"prefix,omitempty"`
	RevokedAt *time.Time `json:"revoked_at,omitempty"`
	Scopes    []string   `json:"scopes"`

	// Token Plaintext token, format `lv_pat_<8chars>_<random>`.
	// Presented exactly once. Store in a secrets manager; do
	// not commit to source control.
	Token string `json:"token"`
}

ApiTokenMint defines model for ApiTokenMint.

type Application added in v0.28.0

type Application struct {
	ID                 uuid.UUID  `json:"id"`
	Name               string     `json:"name"`
	DisplayName        *string    `json:"display_name,omitempty"`
	Description        *string    `json:"description,omitempty"`
	ApplicationBlockID *uuid.UUID `json:"application_block_id,omitempty"`
	// Denormalised on list responses (ADR-0027).
	ApplicationBlockName *string `json:"application_block_name,omitempty"`

	Owner       *string           `json:"owner,omitempty"`
	Criticality *string           `json:"criticality,omitempty"`
	Notes       *string           `json:"notes,omitempty"`
	RunbookURL  *string           `json:"runbook_url,omitempty"`
	Annotations map[string]string `json:"annotations"`

	SecDisponibilite   *int    `json:"sec_disponibilite,omitempty"`
	SecIntegrite       *int    `json:"sec_integrite,omitempty"`
	SecConfidentialite *int    `json:"sec_confidentialite,omitempty"`
	SecTracabilite     *int    `json:"sec_tracabilite,omitempty"`
	SecNotes           *string `json:"sec_notes,omitempty"`

	CreatedAt time.Time `json:"created_at"`
	UpdatedAt time.Time `json:"updated_at"`

	MemberCounts ApplicationMemberCounts `json:"member_counts"`
}

Application is the first-class entity introduced by ADR-0029.

type ApplicationBlock added in v0.28.0

type ApplicationBlock struct {
	ID          uuid.UUID         `json:"id"`
	Name        string            `json:"name"`
	DisplayName *string           `json:"display_name,omitempty"`
	Description *string           `json:"description,omitempty"`
	Owner       *string           `json:"owner,omitempty"`
	Notes       *string           `json:"notes,omitempty"`
	Annotations map[string]string `json:"annotations"`
	CreatedAt   time.Time         `json:"created_at"`
	UpdatedAt   time.Time         `json:"updated_at"`

	// Denormalised for list responses (ADR-0027 pattern).
	ApplicationCount int `json:"application_count,omitempty"`
}

ApplicationBlock is the SNC two-level grouping above Application (ADR-0029 §1). Operator-curated; never written by collectors.

type ApplicationBlockCreate added in v0.28.0

type ApplicationBlockCreate struct {
	Name        string             `json:"name"`
	DisplayName *string            `json:"display_name,omitempty"`
	Description *string            `json:"description,omitempty"`
	Owner       *string            `json:"owner,omitempty"`
	Notes       *string            `json:"notes,omitempty"`
	Annotations *map[string]string `json:"annotations,omitempty"`
}

ApplicationBlockCreate is the body for POST /v1/application-blocks.

type ApplicationBlockId added in v0.28.0

type ApplicationBlockId = openapi_types.UUID

ApplicationBlockId defines model for ApplicationBlockId.

type ApplicationBlockListFilter added in v0.28.0

type ApplicationBlockListFilter struct {
	Name  *string
	Owner *string
}

ApplicationBlockListFilter is the GET /v1/application-blocks query shape.

type ApplicationBlockPatch added in v0.28.0

type ApplicationBlockPatch struct {
	DisplayName *string            `json:"display_name,omitempty"`
	Description *string            `json:"description,omitempty"`
	Owner       *string            `json:"owner,omitempty"`
	Notes       *string            `json:"notes,omitempty"`
	Annotations *map[string]string `json:"annotations,omitempty"`
}

ApplicationBlockPatch is the merge-patch body for PATCH /v1/application-blocks/{id}.

type ApplicationCreate added in v0.28.0

type ApplicationCreate struct {
	Name                 string             `json:"name"`
	DisplayName          *string            `json:"display_name,omitempty"`
	Description          *string            `json:"description,omitempty"`
	ApplicationBlockID   *uuid.UUID         `json:"application_block_id,omitempty"`
	ApplicationBlockName *string            `json:"application_block_name,omitempty"`
	Owner                *string            `json:"owner,omitempty"`
	Criticality          *string            `json:"criticality,omitempty"`
	Notes                *string            `json:"notes,omitempty"`
	RunbookURL           *string            `json:"runbook_url,omitempty"`
	Annotations          *map[string]string `json:"annotations,omitempty"`
	SecDisponibilite     *int               `json:"sec_disponibilite,omitempty"`
	SecIntegrite         *int               `json:"sec_integrite,omitempty"`
	SecConfidentialite   *int               `json:"sec_confidentialite,omitempty"`
	SecTracabilite       *int               `json:"sec_tracabilite,omitempty"`
	SecNotes             *string            `json:"sec_notes,omitempty"`
}

ApplicationCreate is the body for POST /v1/applications.

type ApplicationEOLRow added in v0.28.0

type ApplicationEOLRow struct {
	// Cycle Release cycle from endoflife.date, when known (eol rows only).
	Cycle *string `json:"cycle,omitempty"`

	// EolStatus Lifecycle status. `eol` / `approaching_eol` / `supported`
	// come from the endoflife.date enricher on VMs (signal=eol rows).
	// Always `unknown` on signal=freshness rows.
	EolStatus ApplicationEOLRowEolStatus `json:"eol_status"`

	// EvaluatedAt When the underlying signal was last evaluated (RFC 3339).
	EvaluatedAt *string `json:"evaluated_at,omitempty"`

	// Freshness Version-distance freshness bucket for workload container images
	// (signal=freshness rows). `up_to_date` (same minor or patch-only
	// delta), `outdated` (one minor behind), `far_behind` (two or more
	// minors behind or any major gap), `unknown` (not enriched).
	// Absent on signal=eol rows.
	Freshness *ApplicationEOLRowFreshness `json:"freshness,omitempty"`

	// LatestAvailable Newest published version / tag known for the product.
	LatestAvailable *string `json:"latest_available,omitempty"`

	// Product Normalised product key (kebab-case) or container name.
	Product string `json:"product"`

	// Signal Discriminator for the lifecycle signal kind.
	// `eol` rows come from VM endoflife.date annotations;
	// `freshness` rows come from workload image-versions enrichment.
	Signal ApplicationEOLRowSignal `json:"signal"`

	// Sources Member assets contributing this product's lifecycle signal.
	Sources []ApplicationEOLSource `json:"sources"`
}

ApplicationEOLRow One product rolled up across every member that exposes a lifecycle signal for it. `sources` names the contributing assets (workloads via image-versions enrichment, linked VMs, and matching VM-application entries).

`signal` discriminates the nature of the row:

  • `eol` — at least one VM endoflife.date annotation contributed; `eol_status` and (when available) `cycle` are meaningful.
  • `freshness` — workload image-versions enrichment only; `freshness` is meaningful, `eol_status` is always `unknown`, `cycle` is absent.

type ApplicationEOLRowEolStatus added in v0.28.0

type ApplicationEOLRowEolStatus string

ApplicationEOLRowEolStatus Lifecycle status. `eol` / `approaching_eol` / `supported` come from the endoflife.date enricher on VMs (signal=eol rows). Always `unknown` on signal=freshness rows.

const (
	ApplicationEOLRowEolStatusApproachingEol ApplicationEOLRowEolStatus = "approaching_eol"
	ApplicationEOLRowEolStatusEol            ApplicationEOLRowEolStatus = "eol"
	ApplicationEOLRowEolStatusSupported      ApplicationEOLRowEolStatus = "supported"
	ApplicationEOLRowEolStatusUnknown        ApplicationEOLRowEolStatus = "unknown"
)

Defines values for ApplicationEOLRowEolStatus.

func (ApplicationEOLRowEolStatus) Valid added in v0.28.0

func (e ApplicationEOLRowEolStatus) Valid() bool

Valid indicates whether the value is a known member of the ApplicationEOLRowEolStatus enum.

type ApplicationEOLRowFreshness added in v1.9.0

type ApplicationEOLRowFreshness string

ApplicationEOLRowFreshness Version-distance freshness bucket for workload container images (signal=freshness rows). `up_to_date` (same minor or patch-only delta), `outdated` (one minor behind), `far_behind` (two or more minors behind or any major gap), `unknown` (not enriched). Absent on signal=eol rows.

const (
	ApplicationEOLRowFreshnessFarBehind ApplicationEOLRowFreshness = "far_behind"
	ApplicationEOLRowFreshnessOutdated  ApplicationEOLRowFreshness = "outdated"
	ApplicationEOLRowFreshnessUnknown   ApplicationEOLRowFreshness = "unknown"
	ApplicationEOLRowFreshnessUpToDate  ApplicationEOLRowFreshness = "up_to_date"
)

Defines values for ApplicationEOLRowFreshness.

func (ApplicationEOLRowFreshness) Valid added in v1.9.0

func (e ApplicationEOLRowFreshness) Valid() bool

Valid indicates whether the value is a known member of the ApplicationEOLRowFreshness enum.

type ApplicationEOLRowSignal added in v1.9.0

type ApplicationEOLRowSignal string

ApplicationEOLRowSignal Discriminator for the lifecycle signal kind. `eol` rows come from VM endoflife.date annotations; `freshness` rows come from workload image-versions enrichment.

const (
	ApplicationEOLRowSignalEol       ApplicationEOLRowSignal = "eol"
	ApplicationEOLRowSignalFreshness ApplicationEOLRowSignal = "freshness"
)

Defines values for ApplicationEOLRowSignal.

func (ApplicationEOLRowSignal) Valid added in v1.9.0

func (e ApplicationEOLRowSignal) Valid() bool

Valid indicates whether the value is a known member of the ApplicationEOLRowSignal enum.

type ApplicationEOLSource added in v0.28.0

type ApplicationEOLSource struct {
	// Id Asset identifier. A UUID for workloads / VMs; a composite
	// `<vm-uuid>#<product>` for VM-application entries.
	Id   string                   `json:"id"`
	Kind ApplicationEOLSourceKind `json:"kind"`
	Name string                   `json:"name"`
}

ApplicationEOLSource defines model for ApplicationEOLSource.

type ApplicationEOLSourceKind added in v0.28.0

type ApplicationEOLSourceKind string

ApplicationEOLSourceKind defines model for ApplicationEOLSource.Kind.

const (
	ApplicationEOLSourceKindVirtualMachine ApplicationEOLSourceKind = "virtual_machine"
	ApplicationEOLSourceKindVmApplication  ApplicationEOLSourceKind = "vm_application"
	ApplicationEOLSourceKindWorkload       ApplicationEOLSourceKind = "workload"
)

Defines values for ApplicationEOLSourceKind.

func (ApplicationEOLSourceKind) Valid added in v0.28.0

func (e ApplicationEOLSourceKind) Valid() bool

Valid indicates whether the value is a known member of the ApplicationEOLSourceKind enum.

type ApplicationExtractStore added in v0.28.0

type ApplicationExtractStore interface {
	ListApplications(ctx context.Context, filter ApplicationListFilter, page ListPage) ([]Application, string, error)
}

ApplicationExtractStore is the narrow slice of Store the application extract handlers consume. Kept separate from ExtractStore because the applications extract only needs the one paginated list call.

type ApplicationId added in v0.28.0

type ApplicationId = openapi_types.UUID

ApplicationId defines model for ApplicationId.

type ApplicationListFilter added in v0.28.0

type ApplicationListFilter struct {
	Name                 *string // case-insensitive substring on name + display_name
	ApplicationBlockID   *uuid.UUID
	ApplicationBlockName *string
	Criticality          *string
	HasDICT              *bool
	DICTMin              *int // MAX(sec_*) >= N
}

ApplicationListFilter is the GET /v1/applications query shape.

type ApplicationMember added in v0.28.0

type ApplicationMember struct {
	Kind     ApplicationMemberKind `json:"kind"`
	ID       string                `json:"id"` // UUID for workload/VM; "<vm_id>#<product>#<name>" for vm_application
	Name     string                `json:"name"`
	Parent   *ApplicationMemberRef `json:"parent,omitempty"`
	Linked   time.Time             `json:"linked_at"`
	LinkedBy string                `json:"linked_by"`
}

ApplicationMember is a single row from GET /v1/applications/{id}/members.

type ApplicationMemberCounts added in v0.28.0

type ApplicationMemberCounts struct {
	Workloads       int `json:"workloads"`
	VirtualMachines int `json:"virtual_machines"`
	VMApplications  int `json:"vm_applications"`
}

ApplicationMemberCounts is the small summary shipped with every application GET / list row.

type ApplicationMemberKind added in v0.28.0

type ApplicationMemberKind string

ApplicationMemberKind enumerates the member types of an Application.

const (
	ApplicationMemberKindWorkload       ApplicationMemberKind = "workload"
	ApplicationMemberKindVirtualMachine ApplicationMemberKind = "virtual_machine"
	ApplicationMemberKindVMApplication  ApplicationMemberKind = "vm_application"
)

ApplicationMemberKind values surfaced by GET /v1/applications/{id}/members.

type ApplicationMemberRef added in v0.28.0

type ApplicationMemberRef struct {
	Kind string `json:"kind"`
	ID   string `json:"id"`
	Name string `json:"name"`
}

ApplicationMemberRef points back to the parent entity of an ApplicationMember row (e.g. the workload's namespace, the VM that owns a vm_application). nil on top-level members.

type ApplicationPatch added in v0.28.0

type ApplicationPatch struct {
	DisplayName          *string            `json:"display_name,omitempty"`
	Description          *string            `json:"description,omitempty"`
	ApplicationBlockID   *uuid.UUID         `json:"application_block_id,omitempty"`
	ApplicationBlockName *string            `json:"application_block_name,omitempty"`
	Owner                *string            `json:"owner,omitempty"`
	Criticality          *string            `json:"criticality,omitempty"`
	Notes                *string            `json:"notes,omitempty"`
	RunbookURL           *string            `json:"runbook_url,omitempty"`
	Annotations          *map[string]string `json:"annotations,omitempty"`
	SecDisponibilite     *int               `json:"sec_disponibilite,omitempty"`
	SecIntegrite         *int               `json:"sec_integrite,omitempty"`
	SecConfidentialite   *int               `json:"sec_confidentialite,omitempty"`
	SecTracabilite       *int               `json:"sec_tracabilite,omitempty"`
	SecNotes             *string            `json:"sec_notes,omitempty"`
}

ApplicationPatch is the merge-patch body for PATCH /v1/applications/{id}. nil means "leave alone" on every field. Unlinking from a block is done by deleting the application or by re-PATCHing with a different application_block_id (the v1 surface does not expose an explicit "set block to null" path).

type ApplicationStore added in v1.6.2

type ApplicationStore interface {
	// Application blocks (ADR-0029).
	CreateApplicationBlock(ctx context.Context, in ApplicationBlockCreate) (ApplicationBlock, error)
	GetApplicationBlock(ctx context.Context, id uuid.UUID) (ApplicationBlock, error)
	GetApplicationBlockByName(ctx context.Context, name string) (ApplicationBlock, error)
	ListApplicationBlocks(
		ctx context.Context,
		filter ApplicationBlockListFilter,
		page ListPage,
	) (items []ApplicationBlock, nextCursor string, err error)
	UpdateApplicationBlock(ctx context.Context, id uuid.UUID, in ApplicationBlockPatch) (ApplicationBlock, error)
	DeleteApplicationBlock(ctx context.Context, id uuid.UUID) error

	// Applications (ADR-0029).
	CreateApplication(ctx context.Context, in ApplicationCreate) (Application, error)
	GetApplication(ctx context.Context, id uuid.UUID) (Application, error)
	// GetApplicationsByIDs bulk-fetches applications by id in a single query,
	// returned keyed by id. Unknown ids are silently omitted from the map
	// (no error). Used by the effective-DICT decoration on workload + VM
	// list responses to avoid an N+1 (ADR-0029 §6).
	GetApplicationsByIDs(ctx context.Context, ids []uuid.UUID) (map[uuid.UUID]Application, error)
	GetApplicationByName(ctx context.Context, name string) (Application, error)
	ListApplications(ctx context.Context, filter ApplicationListFilter, page ListPage) (items []Application, nextCursor string, err error)
	UpdateApplication(ctx context.Context, id uuid.UUID, in ApplicationPatch) (Application, error)
	DeleteApplication(ctx context.Context, id uuid.UUID) error
	ListApplicationMembers(
		ctx context.Context,
		id uuid.UUID,
		kind string,
		limit int,
		cursor string,
	) (items []ApplicationMember, nextCursor string, err error)
	// DICTCoverageCounts returns the number of workloads in each
	// effective-DICT source bucket (application | workload | none), feeding
	// the longue_vue_dict_coverage gauge (ADR-0029 §6).
	DICTCoverageCounts(ctx context.Context) (application, workload, none int, err error)
}

ApplicationStore covers the operator-curated applicative layer (ADR-0029): application blocks and applications, including the effective-DICT helpers.

type AuditEvent

type AuditEvent struct {
	// Action Dot-separated verb such as `user.create`, `cluster.update`,
	// `auth.login.success`, `auth.login.failure`.
	Action string `json:"action"`

	// ActorId Null for unauthenticated requests (e.g. failed logins).
	ActorId       *openapi_types.UUID `json:"actor_id,omitempty"`
	ActorKind     AuditEventActorKind `json:"actor_kind"`
	ActorRole     *string             `json:"actor_role,omitempty"`
	ActorUsername *string             `json:"actor_username,omitempty"`

	// Details Action-specific payload. Always an object when present.
	Details    *map[string]interface{} `json:"details,omitempty"`
	HttpMethod string                  `json:"http_method"`
	HttpPath   string                  `json:"http_path"`
	HttpStatus int                     `json:"http_status"`
	Id         openapi_types.UUID      `json:"id"`
	OccurredAt time.Time               `json:"occurred_at"`

	// ResourceId Stringified id of the target — may not be a UUID for all kinds.
	ResourceId *string `json:"resource_id,omitempty"`

	// ResourceType Kind of the target entity (e.g. `cluster`, `user`, `api_token`).
	ResourceType *string `json:"resource_type,omitempty"`

	// Source Which listener served the request. `api` is longue-vue's public
	// listener (humans, admins, trusted-zone collectors). `ingest_gw`
	// is the mTLS-only ingest listener fronted by the DMZ gateway
	// (ADR-0016). `system` is for synthetic events emitted by longue-vue
	// itself, not driven by an HTTP request.
	Source    *AuditEventSource `json:"source,omitempty"`
	SourceIp  *string           `json:"source_ip,omitempty"`
	UserAgent *string           `json:"user_agent,omitempty"`
}

AuditEvent One recorded API action. Written by the audit middleware after the wrapped handler completes; never updated in place.

type AuditEventActorKind

type AuditEventActorKind string

AuditEventActorKind defines model for AuditEvent.ActorKind.

const (
	AuditEventActorKindAnonymous AuditEventActorKind = "anonymous"
	AuditEventActorKindSystem    AuditEventActorKind = "system"
	AuditEventActorKindToken     AuditEventActorKind = "token"
	AuditEventActorKindUser      AuditEventActorKind = "user"
)

Defines values for AuditEventActorKind.

func (AuditEventActorKind) Valid

func (e AuditEventActorKind) Valid() bool

Valid indicates whether the value is a known member of the AuditEventActorKind enum.

type AuditEventFilter

type AuditEventFilter struct {
	ActorID      *uuid.UUID
	ResourceType *string
	ResourceID   *string
	Action       *string
	// Source filters by listener — "api", "ingest_gw", or "system"
	// (ADR-0016 §11). Nil = any source.
	Source *string
	Since  *time.Time
	Until  *time.Time
}

AuditEventFilter collects the optional server-side filters. Nil fields are ignored; set fields are AND-combined.

type AuditEventInsert

type AuditEventInsert struct {
	ID            uuid.UUID
	OccurredAt    time.Time
	ActorID       *uuid.UUID
	ActorKind     string // "user" | "token" | "anonymous" | "system"
	ActorUsername string
	ActorRole     string
	Action        string // dot-separated verb, e.g. "user.create", "cluster.update"
	ResourceType  string // kind name, e.g. "cluster", "user", "api_token"
	ResourceID    string // stringified id — UUID for most kinds, session public_id, token id, …
	HTTPMethod    string
	HTTPPath      string
	HTTPStatus    int
	// Source identifies which listener served the request:
	//   "api"       — the public listener serving humans, admins, and trusted-zone collectors
	//   "ingest_gw" — the mTLS-only ingest listener fronted by the DMZ gateway (ADR-0016)
	//   "system"    — synthetic events emitted by longue-vue itself, not driven by a request
	// Empty string is treated as "api" for backwards compatibility with rows
	// inserted before ADR-0016 added this column.
	Source    string
	SourceIP  string
	UserAgent string
	Details   map[string]any // JSONB payload, nil-friendly
}

AuditEventInsert is the payload the middleware hands the store. All fields are snapshot values at the moment the request completed — audit rows are immutable, so nothing references the caller's live identity after insertion.

type AuditEventList

type AuditEventList struct {
	Items      []AuditEvent `json:"items"`
	NextCursor *string      `json:"next_cursor,omitempty"`
}

AuditEventList Paged list of audit events, newest first.

type AuditEventSource

type AuditEventSource string

AuditEventSource Which listener served the request. `api` is longue-vue's public listener (humans, admins, trusted-zone collectors). `ingest_gw` is the mTLS-only ingest listener fronted by the DMZ gateway (ADR-0016). `system` is for synthetic events emitted by longue-vue itself, not driven by an HTTP request.

const (
	AuditEventSourceApi      AuditEventSource = "api"
	AuditEventSourceIngestGw AuditEventSource = "ingest_gw"
	AuditEventSourceSystem   AuditEventSource = "system"
)

Defines values for AuditEventSource.

func (AuditEventSource) Valid

func (e AuditEventSource) Valid() bool

Valid indicates whether the value is a known member of the AuditEventSource enum.

type AuditRecorder

type AuditRecorder interface {
	InsertAuditEvent(ctx context.Context, in AuditEventInsert) error
}

AuditRecorder is the narrow slice of Store the middleware needs. Exposed as its own interface so tests don't need a full Store fake just to assert on audit rows.

type AuditStore added in v1.6.2

type AuditStore interface {
	// InsertAuditEvent appends one row to audit_events. Called from the
	// audit middleware after the wrapped handler has produced a status.
	// Never returns ErrConflict — id collisions are caller bugs.
	InsertAuditEvent(ctx context.Context, in AuditEventInsert) error

	// ListAuditEvents returns audit events paged by opaque cursor. filter
	// fields are AND-combined; nil fields are ignored. page.Sort selects
	// the sort column (default: occurred_at DESC); ErrInvalidSort is
	// returned for unknown keys and ErrInvalidCursor for stale/mismatched
	// cursors.
	ListAuditEvents(ctx context.Context, filter AuditEventFilter, page ListPage) (items []AuditEvent, nextCursor string, err error)
}

AuditStore covers the append-only audit_events table (ADR-0010).

type AuthConfig

type AuthConfig struct {
	Oidc struct {
		Enabled bool `json:"enabled"`

		// Label Button label on the login page, e.g. "Sign in with
		// Okta". Controlled by `LONGUE_VUE_OIDC_LABEL`.
		Label *string `json:"label,omitempty"`
	} `json:"oidc"`
}

AuthConfig Pre-login auth configuration needed by the UI. Intentionally readable without auth so the login page can render the OIDC button before the user has a session.

type AuthStore added in v1.6.2

type AuthStore interface {
	// CountActiveAdmins returns the number of `admin`-role users without a
	// `disabled_at` timestamp. Used by the first-install bootstrap check.
	CountActiveAdmins(ctx context.Context) (int, error)

	// CountActiveUnlockedAdmins returns the number of admins with
	// disabled_at IS NULL AND locked_at IS NULL.
	CountActiveUnlockedAdmins(ctx context.Context) (int, error)

	// PickRescueTarget returns the most-recently-active admin row.
	// Used by the boot-time rescue when CountActiveUnlockedAdmins == 0.
	// ORDER BY last_login_at DESC NULLS LAST, created_at ASC, LIMIT 1.
	PickRescueTarget(ctx context.Context) (User, error)

	// RescueAdmin atomically resets the rescue target: sets the new
	// password hash, clears locked_at, zeroes failed_login_count, sets
	// disabled_at = NULL, forces must_change_password = true, deletes
	// all of the user's sessions.
	RescueAdmin(ctx context.Context, id uuid.UUID, hash string) error

	// CreateUser inserts a new human user. Returns ErrConflict on
	// case-insensitive username collision.
	CreateUser(ctx context.Context, in UserInsert) (User, error)

	// GetUser fetches by id. ErrNotFound if absent.
	GetUser(ctx context.Context, id uuid.UUID) (User, error)

	// GetUserByUsername looks up by case-insensitive username — the login
	// path. Returns ErrNotFound when no such user exists or the account
	// is disabled, to prevent username enumeration via timing differences
	// (callers always do an argon2 verify regardless).
	GetUserByUsername(ctx context.Context, username string) (UserWithSecret, error)

	// ListUsers returns a page of users (admin view), sorted and filtered per ListPage/UserListFilter.
	ListUsers(ctx context.Context, filter UserListFilter, page ListPage) (items []User, nextCursor string, err error)

	// UpdateUser applies merge-patch on role / disabled / must_change_password.
	// Password changes go through SetUserPassword because they need the
	// hashed form, not plaintext.
	UpdateUser(ctx context.Context, id uuid.UUID, in UserPatch) (User, error)

	// UpdateUserGuarded is the transactional wrapper around UpdateUser
	// that enforces the last-admin invariant atomically. If the patch
	// would demote (role != admin) or disable an active admin and no
	// other active admin exists, it returns ErrLastAdmin without
	// mutating the row. Implementations MUST hold a row-level lock on
	// the candidate-admin set across the count + update so two
	// concurrent demotions cannot both observe `n=2` and commit.
	UpdateUserGuarded(ctx context.Context, id uuid.UUID, in UserPatch) (User, error)

	// SetUserPassword stores a new argon2id hash, toggling the
	// must_change_password flag as specified. On success also deletes every
	// active session for the user so a password change effectively logs
	// out other tabs/devices.
	SetUserPassword(ctx context.Context, id uuid.UUID, hash string, mustChange bool) error

	// TouchUserLogin refreshes last_login_at — called on successful login.
	TouchUserLogin(ctx context.Context, id uuid.UUID, now time.Time) error

	// IncrementFailedLogin bumps users.failed_login_count by one. If the
	// new count is >= threshold and the account was not already locked,
	// sets locked_at = now() in the same statement and returns
	// (locked=true). Idempotent on already-locked accounts: returns
	// (locked=false) and leaves the row untouched.
	//
	// No last-admin guard; the lockout fires uniformly. Recovery is via
	// the boot-time admin-rescue hook (cmd/longue-vue/main.go).
	IncrementFailedLogin(ctx context.Context, id uuid.UUID, threshold int) (locked bool, err error)

	// ResetFailedLogin sets failed_login_count = 0 and locked_at = NULL.
	// Called on a successful password verification. Safe when already
	// at zero (UPDATE is a no-op on the row).
	ResetFailedLogin(ctx context.Context, id uuid.UUID) error

	// DeleteUser removes a user. ON DELETE CASCADE sweeps their sessions
	// and identities; api_tokens they minted are retained (ON DELETE
	// RESTRICT) so CI pipelines don't silently break on admin churn.
	DeleteUser(ctx context.Context, id uuid.UUID) error

	// DeleteUserGuarded is the transactional wrapper around DeleteUser
	// that enforces the last-admin invariant atomically (audit finding
	// H1). Returns ErrLastAdmin when the target is the only currently
	// active admin. Implementations MUST hold a row-level lock on the
	// active-admin set across the count + delete.
	DeleteUserGuarded(ctx context.Context, id uuid.UUID) error

	// CreateSession inserts a new session row.
	CreateSession(ctx context.Context, in SessionInsert) error

	// GetActiveSession, TouchSession — the auth.Store methods, declared
	// here so a single PG implementation satisfies both interfaces.
	GetActiveSession(ctx context.Context, id string) (auth.Session, error)
	TouchSession(ctx context.Context, id string, now time.Time, newExpiry time.Time) error

	// GetUserForAuth — auth.Store lookup: lightweight view the middleware
	// needs after a session resolves.
	GetUserForAuth(ctx context.Context, id uuid.UUID) (auth.User, error)

	// DeleteSession revokes a single session by its cookie-value id.
	// Used by the logout handler which reads the cookie from ctx.
	DeleteSession(ctx context.Context, id string) error

	// DeleteSessionByPublicID revokes by the UUID public handle. Used
	// by the admin revoke endpoint so cookie values never leave the DB.
	DeleteSessionByPublicID(ctx context.Context, publicID uuid.UUID) error

	// DeleteSessionsForUser revokes all active sessions for a user. Called
	// when the user is disabled or changes their password.
	DeleteSessionsForUser(ctx context.Context, userID uuid.UUID) error

	// ListSessions returns a page of active sessions with denormalised
	// username for admin display.
	ListSessions(ctx context.Context, filter SessionListFilter, page ListPage) (items []Session, nextCursor string, err error)

	// CreateAPIToken inserts a new token row. `hash` is argon2id of the
	// full plaintext; `prefix` is the first 8 chars of the plaintext
	// stored in the clear for O(1) lookup.
	CreateAPIToken(ctx context.Context, in APITokenInsert) (ApiToken, error)

	// GetActiveTokenByPrefix, TouchToken — auth.Store lookup path.
	GetActiveTokenByPrefix(ctx context.Context, prefix string) (auth.APIToken, error)
	TouchToken(ctx context.Context, id uuid.UUID, now time.Time) error

	// ListAPITokens (admin view, metadata only — plaintext is never in
	// responses except at creation).
	ListAPITokens(ctx context.Context, filter APITokenListFilter, page ListPage) (items []ApiToken, nextCursor string, err error)

	// RevokeAPIToken sets revoked_at. Idempotent: revoking an
	// already-revoked token returns nil.
	RevokeAPIToken(ctx context.Context, id uuid.UUID, now time.Time) error

	// GetUserByIdentity returns the user linked to (issuer, subject) via
	// the user_identities table, or ErrNotFound when no identity row is
	// present — i.e., the IdP user has never logged in before. Disabled
	// users are treated as NotFound to match local-login semantics.
	GetUserByIdentity(ctx context.Context, issuer, subject string) (User, error)

	// CreateUserWithIdentity inserts a user and its OIDC identity row in
	// one transaction. On username collision the caller is expected to
	// pick a new one and retry.
	CreateUserWithIdentity(ctx context.Context, in UserInsert, ident UserIdentityInsert) (User, error)

	// TouchUserIdentity refreshes last_seen_at on the identity row.
	TouchUserIdentity(ctx context.Context, userID uuid.UUID, issuer, subject string, now time.Time) error

	// CreateOidcAuthState persists the in-flight auth-code state.
	CreateOidcAuthState(ctx context.Context, in OidcAuthStateInsert) error

	// ConsumeOidcAuthState atomically reads and deletes the row keyed on
	// state, returning the code_verifier + nonce. Rejects expired rows
	// with ErrNotFound. One-shot by design.
	ConsumeOidcAuthState(ctx context.Context, state string) (codeVerifier, nonce string, err error)
}

AuthStore covers the auth substrate (ADR-0007): users, sessions, API tokens, and the one-shot OIDC state rows. The auth package also defines a narrower `auth.Store` interface with just the lookup methods the middleware needs. The PG store satisfies both; see `internal/auth/middleware.go` for the contract.

type BadRequest

type BadRequest = Problem

BadRequest RFC 7807 problem details.

type BadRequestApplicationProblemPlusJSONResponse

type BadRequestApplicationProblemPlusJSONResponse Problem

type CascadeCounts

type CascadeCounts struct {
	Namespaces             int `json:"namespaces"`
	Nodes                  int `json:"nodes"`
	Pods                   int `json:"pods"`
	Workloads              int `json:"workloads"`
	Services               int `json:"services"`
	Ingresses              int `json:"ingresses"`
	PersistentVolumes      int `json:"persistent_volumes"`
	PersistentVolumeClaims int `json:"persistent_volume_claims"`
}

CascadeCounts holds the number of child resources that will be removed when a cluster is deleted via ON DELETE CASCADE. Used by the DeleteCluster handler to enrich the audit event with a pre-deletion impact snapshot.

type ChangePassword204Response

type ChangePassword204Response struct {
}

func (ChangePassword204Response) VisitChangePasswordResponse

func (response ChangePassword204Response) VisitChangePasswordResponse(w http.ResponseWriter) error

type ChangePassword400ApplicationProblemPlusJSONResponse

type ChangePassword400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (ChangePassword400ApplicationProblemPlusJSONResponse) VisitChangePasswordResponse

func (response ChangePassword400ApplicationProblemPlusJSONResponse) VisitChangePasswordResponse(w http.ResponseWriter) error

type ChangePassword401ApplicationProblemPlusJSONResponse

type ChangePassword401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (ChangePassword401ApplicationProblemPlusJSONResponse) VisitChangePasswordResponse

func (response ChangePassword401ApplicationProblemPlusJSONResponse) VisitChangePasswordResponse(w http.ResponseWriter) error

type ChangePassword403ApplicationProblemPlusJSONResponse

type ChangePassword403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (ChangePassword403ApplicationProblemPlusJSONResponse) VisitChangePasswordResponse

func (response ChangePassword403ApplicationProblemPlusJSONResponse) VisitChangePasswordResponse(w http.ResponseWriter) error

type ChangePasswordJSONRequestBody

type ChangePasswordJSONRequestBody = ChangePasswordRequest

ChangePasswordJSONRequestBody defines body for ChangePassword for application/json ContentType.

type ChangePasswordRequest

type ChangePasswordRequest struct {
	CurrentPassword string `json:"current_password"`

	// NewPassword Minimum 12 characters per NIST 800-63B guidance. No other
	// composition rules — a long passphrase is acceptable and
	// preferred over short complex strings.
	NewPassword string `json:"new_password"`
}

ChangePasswordRequest Current password + new password.

type ChangePasswordRequestObject

type ChangePasswordRequestObject struct {
	Body *ChangePasswordJSONRequestBody
}

type ChangePasswordResponseObject

type ChangePasswordResponseObject interface {
	VisitChangePasswordResponse(w http.ResponseWriter) error
}

type CloudAccount

type CloudAccount struct {
	ID          uuid.UUID         `json:"id"`
	Provider    string            `json:"provider"`
	Name        string            `json:"name"`
	Region      string            `json:"region"`
	Status      string            `json:"status"`
	AccessKey   *string           `json:"access_key,omitempty"`
	LastSeenAt  *time.Time        `json:"last_seen_at,omitempty"`
	LastError   *string           `json:"last_error,omitempty"`
	LastErrorAt *time.Time        `json:"last_error_at,omitempty"`
	Owner       *string           `json:"owner,omitempty"`
	Criticality *string           `json:"criticality,omitempty"`
	Notes       *string           `json:"notes,omitempty"`
	RunbookURL  *string           `json:"runbook_url,omitempty"`
	Annotations map[string]string `json:"annotations,omitempty"`
	CreatedAt   time.Time         `json:"created_at"`
	UpdatedAt   time.Time         `json:"updated_at"`
	DisabledAt  *time.Time        `json:"disabled_at,omitempty"`
}

CloudAccount is the persisted view of a cloud-provider account registered in longue-vue. The plaintext SK is intentionally absent — it lives only in the encrypted column and is only ever returned by GetCloudAccountCredentials, which decrypts it on the way out.

type CloudAccountListFilter added in v1.10.0

type CloudAccountListFilter struct {
	Name *string
}

CloudAccountListFilter is the filter for ListCloudAccounts. Name is a case-insensitive substring / anchored-glob match on the account name (uniform name= semantics, spec 2026-07-10).

type CloudAccountPatch

type CloudAccountPatch struct {
	Name        *string
	Region      *string
	Owner       *string
	Criticality *string
	Notes       *string
	RunbookURL  *string
	Annotations *map[string]string
	Status      *string
	LastSeenAt  *time.Time
	LastError   *string
	LastErrorAt *time.Time
}

CloudAccountPatch is the merge-patch view for UpdateCloudAccount. Nil fields are left untouched. Status / LastSeenAt / LastError / LastErrorAt are admin-only fields here; collector heartbeats go through UpdateCloudAccountStatus which gates allowed transitions.

type CloudAccountStore added in v1.6.2

type CloudAccountStore interface {
	// UpsertCloudAccount idempotently registers a cloud account by
	// (provider, name). New rows are created in status='pending_credentials'.
	UpsertCloudAccount(ctx context.Context, in CloudAccountUpsert) (CloudAccount, error)

	// GetCloudAccount fetches by id. ErrNotFound when absent.
	GetCloudAccount(ctx context.Context, id uuid.UUID) (CloudAccount, error)

	// GetCloudAccountByName fetches by (provider, name). ErrNotFound when absent.
	GetCloudAccountByName(ctx context.Context, provider, name string) (CloudAccount, error)

	// GetCloudAccountByNameAny fetches by name across every provider
	// in a single query. Used by credential-fetch handlers so a
	// caller-by-name lookup doesn't fan out to one SQL round-trip per
	// supported provider. Returns ErrNotFound when no row matches.
	GetCloudAccountByNameAny(ctx context.Context, name string) (CloudAccount, error)

	// ListCloudAccounts returns a cursor-paginated page of cloud accounts,
	// optionally filtered by CloudAccountListFilter.
	ListCloudAccounts(ctx context.Context, filter CloudAccountListFilter, page ListPage) (items []CloudAccount, nextCursor string, err error)

	// UpdateCloudAccount applies merge-patch on curated metadata + name.
	// Status transitions to/from `disabled` and `pending_credentials` are
	// rejected here — see DisableCloudAccount / EnableCloudAccount and
	// SetCloudAccountCredentials. Status field on the patch is allowed
	// only between `active` and `error`.
	UpdateCloudAccount(ctx context.Context, id uuid.UUID, in CloudAccountPatch) (CloudAccount, error)

	// SetCloudAccountCredentials writes AK plaintext + SK ciphertext+nonce+kid
	// and transitions status to `active`. ErrNotFound if the account is missing.
	SetCloudAccountCredentials(ctx context.Context, id uuid.UUID, accessKey string, encSK secrets.Ciphertext) (CloudAccount, error)

	// GetCloudAccountCredentials returns AK + SK ciphertext for callers
	// (the handler decrypts). Returns ErrNotFound when status =
	// `pending_credentials` or the row is absent. Returns ErrConflict
	// when status = `disabled` (caller maps to 403).
	GetCloudAccountCredentials(ctx context.Context, id uuid.UUID) (accessKey string, encSK secrets.Ciphertext, err error)

	// UpdateCloudAccountStatus is the collector heartbeat path. Only
	// allows transitions between `active` and `error`; rejects to/from
	// `disabled` or `pending_credentials`.
	UpdateCloudAccountStatus(ctx context.Context, id uuid.UUID, status string, lastSeenAt *time.Time, lastError *string) error

	// DisableCloudAccount sets disabled_at and status='disabled'.
	DisableCloudAccount(ctx context.Context, id uuid.UUID) error

	// EnableCloudAccount clears disabled_at and resets status (active if
	// credentials are present, otherwise pending_credentials).
	EnableCloudAccount(ctx context.Context, id uuid.UUID) error

	// DeleteCloudAccount removes a cloud account (cascades to VMs and tokens).
	DeleteCloudAccount(ctx context.Context, id uuid.UUID) error

	// CountCloudAccountsWithSecrets is used at startup to decide whether
	// missing master-key configuration is fatal (see ADR-0015 §4).
	CountCloudAccountsWithSecrets(ctx context.Context) (int, error)
}

CloudAccountStore covers cloud accounts (ADR-0015), including the encrypted-credential paths.

type CloudAccountUpsert

type CloudAccountUpsert struct {
	Provider string
	Name     string
	Region   string
}

CloudAccountUpsert carries the fields used by UpsertCloudAccount (idempotent first-contact registration). Curated metadata is set separately via UpdateCloudAccount.

type Cluster

type Cluster struct {
	// Annotations Free-form k/v for metadata not worth its own column. Values
	// are strings. Collector writes never touch this field.
	Annotations *map[string]string `json:"annotations,omitempty"`

	// ApiEndpoint Kubernetes API server URL (informational).
	ApiEndpoint *string    `json:"api_endpoint,omitempty"`
	CreatedAt   *time.Time `json:"created_at,omitempty"`

	// Criticality Free-form tier label. Common values: `critical`, `high`,
	// `medium`, `low`. Not enum-enforced so operators can slot in
	// their own taxonomy (P0/P1/…).
	Criticality *string `json:"criticality,omitempty"`

	// DisplayName Human-friendly label, free-form.
	DisplayName *string `json:"display_name,omitempty"`

	// Environment Free-form environment tag (e.g., dev, staging, prod).
	Environment *string             `json:"environment,omitempty"`
	Id          *openapi_types.UUID `json:"id,omitempty"`

	// KubernetesVersion Cluster API server version reported by Kubernetes (e.g. "1.29.5").
	KubernetesVersion *string `json:"kubernetes_version,omitempty"`

	// Labels Arbitrary user-supplied string key/value labels.
	Labels *map[string]string `json:"labels,omitempty"`

	// LastSeenAt Collector heartbeat: refreshed on every successful collector
	// tick for this cluster (in-process pull, or push mode via
	// POST /v1/clusters through the ingest gateway). Also set on
	// creation.
	LastSeenAt *time.Time `json:"last_seen_at,omitempty"`

	// Layer Always `infrastructure_logical` for Cluster. Set by the server.
	Layer *Layer `json:"layer,omitempty"`
	Name  string `json:"name"`

	// Notes Long-form prose. Any markdown is rendered client-side.
	Notes *string `json:"notes,omitempty"`

	// Owner Free-form handle for the team / on-call that owns this
	// cluster. Surfaced on the detail page so incident responders
	// know who to wake up.
	Owner *string `json:"owner,omitempty"`

	// Provider Underlying Kubernetes distribution or hosting provider.
	// Open-ended; common values: gke, eks, aks, openshift, rke, kubeadm, onprem, other.
	Provider *string `json:"provider,omitempty"`
	Region   *string `json:"region,omitempty"`

	// RunbookUrl Link to the owning team's runbook for this cluster.
	RunbookUrl *string `json:"runbook_url,omitempty"`

	// Stale Derived at read time: true when `last_seen_at` is older
	// than the `cluster_stale_after_days` admin setting. Always
	// false when the feature is disabled (threshold 0). Set by
	// the server; never persisted.
	Stale     *bool      `json:"stale,omitempty"`
	UpdatedAt *time.Time `json:"updated_at,omitempty"`
}

Cluster defines model for Cluster.

type ClusterCreate

type ClusterCreate struct {
	// Annotations Free-form k/v for metadata not worth its own column. Values
	// are strings. Collector writes never touch this field.
	Annotations *map[string]string `json:"annotations,omitempty"`

	// ApiEndpoint Kubernetes API server URL (informational).
	ApiEndpoint *string `json:"api_endpoint,omitempty"`

	// Criticality Free-form tier label. Common values: `critical`, `high`,
	// `medium`, `low`. Not enum-enforced so operators can slot in
	// their own taxonomy (P0/P1/…).
	Criticality *string `json:"criticality,omitempty"`

	// DisplayName Human-friendly label, free-form.
	DisplayName *string `json:"display_name,omitempty"`

	// Environment Free-form environment tag (e.g., dev, staging, prod).
	Environment *string `json:"environment,omitempty"`

	// KubernetesVersion Cluster API server version reported by Kubernetes (e.g. "1.29.5").
	KubernetesVersion *string `json:"kubernetes_version,omitempty"`

	// Labels Arbitrary user-supplied string key/value labels.
	Labels *map[string]string `json:"labels,omitempty"`

	// Name Stable slug-like identifier, unique across the CMDB.
	// Immutable after creation.
	Name string `json:"name"`

	// Notes Long-form prose. Any markdown is rendered client-side.
	Notes *string `json:"notes,omitempty"`

	// Owner Free-form handle for the team / on-call that owns this
	// cluster. Surfaced on the detail page so incident responders
	// know who to wake up.
	Owner *string `json:"owner,omitempty"`

	// Provider Underlying Kubernetes distribution or hosting provider.
	// Open-ended; common values: gke, eks, aks, openshift, rke, kubeadm, onprem, other.
	Provider *string `json:"provider,omitempty"`
	Region   *string `json:"region,omitempty"`

	// RunbookUrl Link to the owning team's runbook for this cluster.
	RunbookUrl *string `json:"runbook_url,omitempty"`
}

ClusterCreate defines model for ClusterCreate.

type ClusterId

type ClusterId = openapi_types.UUID

ClusterId defines model for ClusterId.

type ClusterList

type ClusterList struct {
	Items []Cluster `json:"items"`

	// NextCursor Opaque cursor to pass as `?cursor=` to fetch the next page.
	// Absent or null when no more pages remain.
	NextCursor *string `json:"next_cursor,omitempty"`
}

ClusterList Paged list of clusters.

type ClusterListFilter added in v1.10.0

type ClusterListFilter struct {
	Name              *string
	IncludeTerminated bool
	// Stale filters on the derived staleness state: true keeps only
	// clusters whose last_seen_at is strictly older than StaleCutoff,
	// false keeps only fresh ones. StaleCutoff must be set whenever
	// Stale is non-nil; handlers compute it from the
	// cluster_stale_after_days setting and leave Stale nil when the
	// feature is disabled.
	Stale       *bool
	StaleCutoff time.Time
}

ClusterListFilter — uniform list filter for clusters. Name matches case-insensitively over BOTH name and display_name (substring, or anchored glob when the term contains `*`).

type ClusterMutable

type ClusterMutable struct {
	// Annotations Free-form k/v for metadata not worth its own column. Values
	// are strings. Collector writes never touch this field.
	Annotations *map[string]string `json:"annotations,omitempty"`

	// ApiEndpoint Kubernetes API server URL (informational).
	ApiEndpoint *string `json:"api_endpoint,omitempty"`

	// Criticality Free-form tier label. Common values: `critical`, `high`,
	// `medium`, `low`. Not enum-enforced so operators can slot in
	// their own taxonomy (P0/P1/…).
	Criticality *string `json:"criticality,omitempty"`

	// DisplayName Human-friendly label, free-form.
	DisplayName *string `json:"display_name,omitempty"`

	// Environment Free-form environment tag (e.g., dev, staging, prod).
	Environment *string `json:"environment,omitempty"`

	// KubernetesVersion Cluster API server version reported by Kubernetes (e.g. "1.29.5").
	KubernetesVersion *string `json:"kubernetes_version,omitempty"`

	// Labels Arbitrary user-supplied string key/value labels.
	Labels *map[string]string `json:"labels,omitempty"`

	// Notes Long-form prose. Any markdown is rendered client-side.
	Notes *string `json:"notes,omitempty"`

	// Owner Free-form handle for the team / on-call that owns this
	// cluster. Surfaced on the detail page so incident responders
	// know who to wake up.
	Owner *string `json:"owner,omitempty"`

	// Provider Underlying Kubernetes distribution or hosting provider.
	// Open-ended; common values: gke, eks, aks, openshift, rke, kubeadm, onprem, other.
	Provider *string `json:"provider,omitempty"`
	Region   *string `json:"region,omitempty"`

	// RunbookUrl Link to the owning team's runbook for this cluster.
	RunbookUrl *string `json:"runbook_url,omitempty"`
}

ClusterMutable Fields on a Cluster that clients may set and later update.

type ClusterPolicyCreate added in v1.13.0

type ClusterPolicyCreate struct {
	ClusterID       uuid.UUID       `json:"cluster_id"`
	NamespaceID     *uuid.UUID      `json:"namespace_id,omitempty"`
	Name            string          `json:"name"`
	ResourceType    string          `json:"resource_type"`
	Scope           string          `json:"scope"`
	Description     *string         `json:"description,omitempty"`
	Category        *string         `json:"category,omitempty"`
	Severity        *string         `json:"severity,omitempty"`
	Action          *string         `json:"action,omitempty"`
	FailurePolicy   *string         `json:"failure_policy,omitempty"`
	Background      *bool           `json:"background,omitempty"`
	RuleTypes       []string        `json:"rule_types,omitempty"`
	RulesCount      *int            `json:"rules_count,omitempty"`
	TargetResources []string        `json:"target_resources,omitempty"`
	KeyExclusions   []string        `json:"key_exclusions,omitempty"`
	Ready           *bool           `json:"ready,omitempty"`
	Annotations     json.RawMessage `json:"annotations,omitempty"`
	SpecRaw         json.RawMessage `json:"spec_raw"`
}

ClusterPolicyCreate is the request body for POST /v1/cluster-policies. Only the fields required for creation are exposed; server-generated fields (id, reconcile_seen_at, source) are set by the handler.

type ClusterPolicyListFilter added in v1.13.0

type ClusterPolicyListFilter struct {
	ClusterID     *uuid.UUID
	NamespaceID   *uuid.UUID
	Name          *string
	ResourceType  *string
	Action        *string
	Severity      *string
	FailurePolicy *string
	Category      *string
}

ClusterPolicyListFilter — nil fields are ignored; set fields AND-combine.

type ClusterPolicyRow added in v1.13.0

type ClusterPolicyRow struct {
	ID              uuid.UUID       `json:"id"`
	ClusterID       uuid.UUID       `json:"cluster_id"`
	NamespaceID     *uuid.UUID      `json:"namespace_id,omitempty"`
	Name            string          `json:"name"`
	ResourceType    string          `json:"resource_type"`
	Scope           string          `json:"scope"`
	Description     *string         `json:"description,omitempty"`
	Category        *string         `json:"category,omitempty"`
	Severity        *string         `json:"severity,omitempty"`
	Action          *string         `json:"action,omitempty"`
	FailurePolicy   *string         `json:"failure_policy,omitempty"`
	Background      *bool           `json:"background,omitempty"`
	RuleTypes       []string        `json:"rule_types,omitempty"`
	RulesCount      *int            `json:"rules_count,omitempty"`
	TargetResources []string        `json:"target_resources,omitempty"`
	KeyExclusions   []string        `json:"key_exclusions,omitempty"`
	Ready           *bool           `json:"ready,omitempty"`
	Annotations     json.RawMessage `json:"annotations,omitempty"`
	SpecRaw         json.RawMessage `json:"spec_raw"`
	Source          string          `json:"source"`
	ReconcileSeenAt time.Time       `json:"reconcile_seen_at"`
}

ClusterPolicyRow is one row from the cluster_policies table — a collected Kyverno ClusterPolicy (namespace_id=NULL, scope="cluster") or namespaced Policy (namespace_id set, scope="namespace"). ADR-0043.

type ClusterStore added in v1.6.2

type ClusterStore interface {
	// EnsureCluster reconciles a cluster row keyed by name with one of three
	// outcomes:
	//   - CREATE: no row exists, a new one is inserted and created=true.
	//   - NO-OP: a live row exists, it is returned unchanged with created=false.
	//   - RESTORE: a soft-deleted row exists (terminated_at IS NOT NULL); its
	//     terminated_at is cleared, a change_type='restore' history row is
	//     written, and created=false is returned.
	//
	// The request body is otherwise ignored on hit — callers wanting to update
	// fields on an existing cluster must follow up with UpdateCluster.
	//
	// EnsureCluster never returns ErrConflict; concurrent inserts of the same
	// name are serialised at the database via INSERT ... ON CONFLICT DO
	// NOTHING, falling back to a SELECT for the losing writer. Lightweight
	// in-memory implementations that do not track terminated_at may safely
	// skip the RESTORE branch and treat any existing row as NO-OP.
	EnsureCluster(ctx context.Context, in ClusterCreate) (cluster Cluster, created bool, err error)

	// GetCluster fetches a cluster by id. Returns ErrNotFound if absent.
	GetCluster(ctx context.Context, id uuid.UUID) (Cluster, error)

	// GetClusterByName fetches a cluster by its unique slug-like name.
	// Returns ErrNotFound when no cluster carries that name.
	GetClusterByName(ctx context.Context, name string) (Cluster, error)

	// ListClusters returns up to page.Limit clusters after the given cursor,
	// filtered by filter, plus the cursor for the next page (empty when exhausted).
	ListClusters(ctx context.Context, filter ClusterListFilter, page ListPage) (items []Cluster, nextCursor string, err error)

	// UpdateCluster applies the merge-patch fields set in in. Returns
	// ErrNotFound if the cluster does not exist.
	UpdateCluster(ctx context.Context, id uuid.UUID, in ClusterUpdate) (Cluster, error)

	// DeleteCluster removes a cluster by id. Returns ErrNotFound if absent.
	DeleteCluster(ctx context.Context, id uuid.UUID) error

	// SoftDeleteCluster marks the cluster and its live children
	// (namespaces, nodes, workloads) as terminated in a single transaction.
	// See ADR-0021 §IMP-007. Idempotent on already-terminated rows; returns
	// ErrNotFound when the cluster does not exist.
	SoftDeleteCluster(ctx context.Context, id uuid.UUID) error

	// CountClusterChildren counts child resources that will be cascade-deleted
	// when the given cluster is removed. Returns ErrNotFound if the cluster
	// does not exist. Used to build the pre-deletion audit snapshot (ADR-0010).
	CountClusterChildren(ctx context.Context, clusterID uuid.UUID) (CascadeCounts, error)
}

ClusterStore covers cluster CRUD, the idempotent EnsureCluster, and the cascade soft-delete helpers.

type ClusterUpdate

type ClusterUpdate = ClusterMutable

ClusterUpdate Fields on a Cluster that clients may set and later update.

type Conflict

type Conflict = Problem

Conflict RFC 7807 problem details.

type ConflictApplicationProblemPlusJSONResponse

type ConflictApplicationProblemPlusJSONResponse Problem

type ContainerFreshnessFilter added in v1.9.0

type ContainerFreshnessFilter struct {
	// Freshness, when non-nil, restricts rows to that freshness tier
	// (including the package-local "unknown" tier).
	Freshness *ContainerVersionInfoFreshness
	// Cluster, when non-empty, restricts rows to the named cluster (exact).
	Cluster string
	// ImageRepo, when non-nil, restricts rows to containers whose image
	// string case-insensitively contains the value (substring).
	ImageRepo *string
	// Namespace, when non-nil, restricts rows to the named namespace (exact).
	Namespace *string
	// Kind, when non-nil, restricts rows to workloads of that Kubernetes
	// controller kind (exact match against Workload.Kind).
	Kind *string
}

ContainerFreshnessFilter controls which rows SummarizeAndFilterContainerFreshness returns. Zero value applies no filtering. Summary counts always reflect the full unfiltered set regardless of which filters are set.

type ContainerFreshnessRow added in v1.9.0

type ContainerFreshnessRow struct {
	WorkloadName  string                        `json:"workload_name"`
	ClusterName   string                        `json:"cluster_name"`
	NamespaceName string                        `json:"namespace_name"`
	ContainerName string                        `json:"container_name"`
	Image         string                        `json:"image"`
	Freshness     ContainerVersionInfoFreshness `json:"freshness"`
	LatestTag     string                        `json:"latest_tag"`
}

ContainerFreshnessRow is one deployed-container entry, flattened from a Workload for tabular display or export. Every container with a non-empty name and image produces a row; unenriched containers carry Freshness=unknown.

func PageContainerFreshness added in v1.9.0

func PageContainerFreshness(rows []ContainerFreshnessRow, limit int, cursor string) (page []ContainerFreshnessRow, next string)

PageContainerFreshness returns a window of rows starting at cursor (empty = first page) with at most limit items, plus the cursor for the next page (empty when there are no more items). The cursor is an opaque string encoding the next-start index.

type ContainerFreshnessSummary added in v1.9.0

type ContainerFreshnessSummary struct {
	Total     int `json:"total"`
	UpToDate  int `json:"up_to_date"`
	Outdated  int `json:"outdated"`
	FarBehind int `json:"far_behind"`
	Unknown   int `json:"unknown"`
}

ContainerFreshnessSummary holds per-tier counts across the full (unfiltered) set of deployed containers for a given workload list.

type ContainerList

type ContainerList = []map[string]interface{}

ContainerList Containers associated with the resource. For Pods this reflects the live runtime (name, image, image_id from containerStatuses, init flag); for Workloads it's the pod template's declared containers (name, image, init). Opaque in v1: each entry's shape is additive, so new collector-extracted fields don't require a spec bump.

type ContainerVersionInfo

type ContainerVersionInfo struct {
	// Freshness Version-distance freshness of the deployed tag vs the latest registry tag for the same variant: 'up_to_date' (same minor or only patch behind), 'outdated' (exactly one minor behind), 'far_behind' (two or more minors behind, or any major gap). Absent when the image is not enriched. This is NOT an EOL/support signal — endoflife.date status lives only on clusters/nodes/VMs.
	Freshness     *ContainerVersionInfoFreshness `json:"freshness,omitempty"`
	IsBehind      *bool                          `json:"is_behind,omitempty"`
	LastCheckedAt *time.Time                     `json:"last_checked_at,omitempty"`
	LatestTag     *string                        `json:"latest_tag,omitempty"`

	// OriginError Classified resolver failure (missing_annotation, ambiguous_annotation, auth_error, fetch_error, chain_too_deep, replica_target_missing).
	OriginError *string `json:"origin_error,omitempty"`

	// OriginImageRepo Resolved internet origin repo (e.g. ghcr.io/foo/bar) when the image was routed through a mirror.
	OriginImageRepo *string `json:"origin_image_repo,omitempty"`

	// OriginStatus Absent on passthrough images. 'resolved' = origin found. 'unresolved' = mirror lookup failed; see origin_error.
	OriginStatus *ContainerVersionInfoOriginStatus `json:"origin_status,omitempty"`
}

ContainerVersionInfo defines model for ContainerVersionInfo.

type ContainerVersionInfoFreshness added in v1.9.0

type ContainerVersionInfoFreshness string

ContainerVersionInfoFreshness Version-distance freshness of the deployed tag vs the latest registry tag for the same variant: 'up_to_date' (same minor or only patch behind), 'outdated' (exactly one minor behind), 'far_behind' (two or more minors behind, or any major gap). Absent when the image is not enriched. This is NOT an EOL/support signal — endoflife.date status lives only on clusters/nodes/VMs.

const (
	FarBehind ContainerVersionInfoFreshness = "far_behind"
	Outdated  ContainerVersionInfoFreshness = "outdated"
	UpToDate  ContainerVersionInfoFreshness = "up_to_date"
)

Defines values for ContainerVersionInfoFreshness.

const (
	ContainerVersionInfoFreshnessUpToDate  ContainerVersionInfoFreshness = "up_to_date"
	ContainerVersionInfoFreshnessOutdated  ContainerVersionInfoFreshness = "outdated"
	ContainerVersionInfoFreshnessFarBehind ContainerVersionInfoFreshness = "far_behind"
)

ContainerVersionInfoFreshness* aliases bridge the oapi-codegen naming shift: when a second schema property named "freshness" exists, codegen emits short names (FarBehind/Outdated/UpToDate) instead of the fully-qualified prefixed form (ContainerVersionInfoFreshnessFarBehind/…). Hand-defining the prefixed constants here keeps the rest of the package compiling regardless of which codegen form is emitted.

const ContainerVersionInfoFreshnessUnknown ContainerVersionInfoFreshness = "unknown"

ContainerVersionInfoFreshnessUnknown is a package-local freshness tier for deployed containers that carry no version enrichment (non-parseable tag, registry outside the allowlist, or not yet processed). It is intentionally NOT a member of the generated OpenAPI enum (which is [up_to_date, outdated, far_behind] — see ContainerVersionInfo.Freshness): the wire contract only ever omits the field for unenriched containers. This constant exists purely so the fleet-level freshness view can render a row for every deployed container rather than silently dropping unenriched ones.

func FreshnessOf added in v1.9.0

func FreshnessOf(cur, latest containerVersion) ContainerVersionInfoFreshness

FreshnessOf maps the minor-version distance between the deployed tag (cur) and the latest registry tag (latest) onto the freshness scale. Patch differences are ignored; any major gap is far_behind. This is a pure version-distance signal — NOT an endoflife.date/support status.

func (ContainerVersionInfoFreshness) Valid added in v1.9.0

Valid indicates whether the value is a known member of the ContainerVersionInfoFreshness enum.

type ContainerVersionInfoOriginStatus added in v0.27.0

type ContainerVersionInfoOriginStatus string

ContainerVersionInfoOriginStatus Absent on passthrough images. 'resolved' = origin found. 'unresolved' = mirror lookup failed; see origin_error.

const (
	Resolved   ContainerVersionInfoOriginStatus = "resolved"
	Unresolved ContainerVersionInfoOriginStatus = "unresolved"
)

Defines values for ContainerVersionInfoOriginStatus.

func (ContainerVersionInfoOriginStatus) Valid added in v0.27.0

Valid indicates whether the value is a known member of the ContainerVersionInfoOriginStatus enum.

type ContainersVersions

type ContainersVersions map[string]ContainerVersionInfo

ContainersVersions maps container.name -> ContainerVersionInfo. Keys are absent when the image is not enriched (non-parseable tag, registry outside allowlist, or not yet processed). ContainerVersionInfo is defined by the generated API types (api.gen.go).

func EnrichContainersVersions

func EnrichContainersVersions(ctx context.Context, s containerVersionLookup, containers []map[string]any) ContainersVersions

EnrichContainersVersions joins each container's image string against the image_versions store.

type CreateApiToken201JSONResponse

type CreateApiToken201JSONResponse ApiTokenMint

func (CreateApiToken201JSONResponse) VisitCreateApiTokenResponse

func (response CreateApiToken201JSONResponse) VisitCreateApiTokenResponse(w http.ResponseWriter) error

type CreateApiToken400ApplicationProblemPlusJSONResponse

type CreateApiToken400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (CreateApiToken400ApplicationProblemPlusJSONResponse) VisitCreateApiTokenResponse

func (response CreateApiToken400ApplicationProblemPlusJSONResponse) VisitCreateApiTokenResponse(w http.ResponseWriter) error

type CreateApiToken401ApplicationProblemPlusJSONResponse

type CreateApiToken401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (CreateApiToken401ApplicationProblemPlusJSONResponse) VisitCreateApiTokenResponse

func (response CreateApiToken401ApplicationProblemPlusJSONResponse) VisitCreateApiTokenResponse(w http.ResponseWriter) error

type CreateApiToken403ApplicationProblemPlusJSONResponse

type CreateApiToken403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (CreateApiToken403ApplicationProblemPlusJSONResponse) VisitCreateApiTokenResponse

func (response CreateApiToken403ApplicationProblemPlusJSONResponse) VisitCreateApiTokenResponse(w http.ResponseWriter) error

type CreateApiTokenJSONRequestBody

type CreateApiTokenJSONRequestBody = ApiTokenCreate

CreateApiTokenJSONRequestBody defines body for CreateApiToken for application/json ContentType.

type CreateApiTokenRequestObject

type CreateApiTokenRequestObject struct {
	Body *CreateApiTokenJSONRequestBody
}

type CreateApiTokenResponseObject

type CreateApiTokenResponseObject interface {
	VisitCreateApiTokenResponse(w http.ResponseWriter) error
}

type CreateCluster200JSONResponse

type CreateCluster200JSONResponse struct {
	Body    Cluster
	Headers CreateCluster200ResponseHeaders
}

func (CreateCluster200JSONResponse) VisitCreateClusterResponse

func (response CreateCluster200JSONResponse) VisitCreateClusterResponse(w http.ResponseWriter) error

type CreateCluster200ResponseHeaders

type CreateCluster200ResponseHeaders struct {
	Location *string
}

type CreateCluster201JSONResponse

type CreateCluster201JSONResponse struct {
	Body    Cluster
	Headers CreateCluster201ResponseHeaders
}

func (CreateCluster201JSONResponse) VisitCreateClusterResponse

func (response CreateCluster201JSONResponse) VisitCreateClusterResponse(w http.ResponseWriter) error

type CreateCluster201ResponseHeaders

type CreateCluster201ResponseHeaders struct {
	Location *string
}

type CreateCluster400ApplicationProblemPlusJSONResponse

type CreateCluster400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (CreateCluster400ApplicationProblemPlusJSONResponse) VisitCreateClusterResponse

func (response CreateCluster400ApplicationProblemPlusJSONResponse) VisitCreateClusterResponse(w http.ResponseWriter) error

type CreateCluster401ApplicationProblemPlusJSONResponse

type CreateCluster401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (CreateCluster401ApplicationProblemPlusJSONResponse) VisitCreateClusterResponse

func (response CreateCluster401ApplicationProblemPlusJSONResponse) VisitCreateClusterResponse(w http.ResponseWriter) error

type CreateCluster403ApplicationProblemPlusJSONResponse

type CreateCluster403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (CreateCluster403ApplicationProblemPlusJSONResponse) VisitCreateClusterResponse

func (response CreateCluster403ApplicationProblemPlusJSONResponse) VisitCreateClusterResponse(w http.ResponseWriter) error

type CreateClusterJSONRequestBody

type CreateClusterJSONRequestBody = ClusterCreate

CreateClusterJSONRequestBody defines body for CreateCluster for application/json ContentType.

type CreateClusterRequestObject

type CreateClusterRequestObject struct {
	Body *CreateClusterJSONRequestBody
}

type CreateClusterResponseObject

type CreateClusterResponseObject interface {
	VisitCreateClusterResponse(w http.ResponseWriter) error
}

type CreateImageOriginMapping201JSONResponse added in v0.30.0

type CreateImageOriginMapping201JSONResponse ImageOriginMapping

func (CreateImageOriginMapping201JSONResponse) VisitCreateImageOriginMappingResponse added in v0.30.0

func (response CreateImageOriginMapping201JSONResponse) VisitCreateImageOriginMappingResponse(w http.ResponseWriter) error

type CreateImageOriginMapping400ApplicationProblemPlusJSONResponse added in v0.30.0

type CreateImageOriginMapping400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (CreateImageOriginMapping400ApplicationProblemPlusJSONResponse) VisitCreateImageOriginMappingResponse added in v0.30.0

func (response CreateImageOriginMapping400ApplicationProblemPlusJSONResponse) VisitCreateImageOriginMappingResponse(w http.ResponseWriter) error

type CreateImageOriginMapping401ApplicationProblemPlusJSONResponse added in v0.30.0

type CreateImageOriginMapping401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (CreateImageOriginMapping401ApplicationProblemPlusJSONResponse) VisitCreateImageOriginMappingResponse added in v0.30.0

func (response CreateImageOriginMapping401ApplicationProblemPlusJSONResponse) VisitCreateImageOriginMappingResponse(w http.ResponseWriter) error

type CreateImageOriginMapping403ApplicationProblemPlusJSONResponse added in v0.30.0

type CreateImageOriginMapping403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (CreateImageOriginMapping403ApplicationProblemPlusJSONResponse) VisitCreateImageOriginMappingResponse added in v0.30.0

func (response CreateImageOriginMapping403ApplicationProblemPlusJSONResponse) VisitCreateImageOriginMappingResponse(w http.ResponseWriter) error

type CreateImageOriginMapping409ApplicationProblemPlusJSONResponse added in v0.30.0

type CreateImageOriginMapping409ApplicationProblemPlusJSONResponse struct {
	ConflictApplicationProblemPlusJSONResponse
}

func (CreateImageOriginMapping409ApplicationProblemPlusJSONResponse) VisitCreateImageOriginMappingResponse added in v0.30.0

func (response CreateImageOriginMapping409ApplicationProblemPlusJSONResponse) VisitCreateImageOriginMappingResponse(w http.ResponseWriter) error

type CreateImageOriginMappingJSONRequestBody added in v0.30.0

type CreateImageOriginMappingJSONRequestBody = ImageOriginMappingCreate

CreateImageOriginMappingJSONRequestBody defines body for CreateImageOriginMapping for application/json ContentType.

type CreateImageOriginMappingRequestObject added in v0.30.0

type CreateImageOriginMappingRequestObject struct {
	Body *CreateImageOriginMappingJSONRequestBody
}

type CreateImageOriginMappingResponseObject added in v0.30.0

type CreateImageOriginMappingResponseObject interface {
	VisitCreateImageOriginMappingResponse(w http.ResponseWriter) error
}

type CreateImageRegistry201JSONResponse

type CreateImageRegistry201JSONResponse ImageRegistry

func (CreateImageRegistry201JSONResponse) VisitCreateImageRegistryResponse

func (response CreateImageRegistry201JSONResponse) VisitCreateImageRegistryResponse(w http.ResponseWriter) error

type CreateImageRegistry400ApplicationProblemPlusJSONResponse

type CreateImageRegistry400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (CreateImageRegistry400ApplicationProblemPlusJSONResponse) VisitCreateImageRegistryResponse

func (response CreateImageRegistry400ApplicationProblemPlusJSONResponse) VisitCreateImageRegistryResponse(w http.ResponseWriter) error

type CreateImageRegistry401ApplicationProblemPlusJSONResponse

type CreateImageRegistry401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (CreateImageRegistry401ApplicationProblemPlusJSONResponse) VisitCreateImageRegistryResponse

func (response CreateImageRegistry401ApplicationProblemPlusJSONResponse) VisitCreateImageRegistryResponse(w http.ResponseWriter) error

type CreateImageRegistry403ApplicationProblemPlusJSONResponse

type CreateImageRegistry403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (CreateImageRegistry403ApplicationProblemPlusJSONResponse) VisitCreateImageRegistryResponse

func (response CreateImageRegistry403ApplicationProblemPlusJSONResponse) VisitCreateImageRegistryResponse(w http.ResponseWriter) error

type CreateImageRegistry409ApplicationProblemPlusJSONResponse

type CreateImageRegistry409ApplicationProblemPlusJSONResponse struct {
	ConflictApplicationProblemPlusJSONResponse
}

func (CreateImageRegistry409ApplicationProblemPlusJSONResponse) VisitCreateImageRegistryResponse

func (response CreateImageRegistry409ApplicationProblemPlusJSONResponse) VisitCreateImageRegistryResponse(w http.ResponseWriter) error

type CreateImageRegistryJSONRequestBody

type CreateImageRegistryJSONRequestBody = ImageRegistryUpsert

CreateImageRegistryJSONRequestBody defines body for CreateImageRegistry for application/json ContentType.

type CreateImageRegistryRequestObject

type CreateImageRegistryRequestObject struct {
	Body *CreateImageRegistryJSONRequestBody
}

type CreateImageRegistryResponseObject

type CreateImageRegistryResponseObject interface {
	VisitCreateImageRegistryResponse(w http.ResponseWriter) error
}

type CreateIngress201JSONResponse

type CreateIngress201JSONResponse struct {
	Body    Ingress
	Headers CreateIngress201ResponseHeaders
}

func (CreateIngress201JSONResponse) VisitCreateIngressResponse

func (response CreateIngress201JSONResponse) VisitCreateIngressResponse(w http.ResponseWriter) error

type CreateIngress201ResponseHeaders

type CreateIngress201ResponseHeaders struct {
	Location *string
}

type CreateIngress400ApplicationProblemPlusJSONResponse

type CreateIngress400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (CreateIngress400ApplicationProblemPlusJSONResponse) VisitCreateIngressResponse

func (response CreateIngress400ApplicationProblemPlusJSONResponse) VisitCreateIngressResponse(w http.ResponseWriter) error

type CreateIngress401ApplicationProblemPlusJSONResponse

type CreateIngress401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (CreateIngress401ApplicationProblemPlusJSONResponse) VisitCreateIngressResponse

func (response CreateIngress401ApplicationProblemPlusJSONResponse) VisitCreateIngressResponse(w http.ResponseWriter) error

type CreateIngress403ApplicationProblemPlusJSONResponse

type CreateIngress403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (CreateIngress403ApplicationProblemPlusJSONResponse) VisitCreateIngressResponse

func (response CreateIngress403ApplicationProblemPlusJSONResponse) VisitCreateIngressResponse(w http.ResponseWriter) error

type CreateIngress404ApplicationProblemPlusJSONResponse

type CreateIngress404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (CreateIngress404ApplicationProblemPlusJSONResponse) VisitCreateIngressResponse

func (response CreateIngress404ApplicationProblemPlusJSONResponse) VisitCreateIngressResponse(w http.ResponseWriter) error

type CreateIngress409ApplicationProblemPlusJSONResponse

type CreateIngress409ApplicationProblemPlusJSONResponse struct {
	ConflictApplicationProblemPlusJSONResponse
}

func (CreateIngress409ApplicationProblemPlusJSONResponse) VisitCreateIngressResponse

func (response CreateIngress409ApplicationProblemPlusJSONResponse) VisitCreateIngressResponse(w http.ResponseWriter) error

type CreateIngressJSONRequestBody

type CreateIngressJSONRequestBody = IngressCreate

CreateIngressJSONRequestBody defines body for CreateIngress for application/json ContentType.

type CreateIngressRequestObject

type CreateIngressRequestObject struct {
	Body *CreateIngressJSONRequestBody
}

type CreateIngressResponseObject

type CreateIngressResponseObject interface {
	VisitCreateIngressResponse(w http.ResponseWriter) error
}

type CreateNamespace201JSONResponse

type CreateNamespace201JSONResponse struct {
	Body    Namespace
	Headers CreateNamespace201ResponseHeaders
}

func (CreateNamespace201JSONResponse) VisitCreateNamespaceResponse

func (response CreateNamespace201JSONResponse) VisitCreateNamespaceResponse(w http.ResponseWriter) error

type CreateNamespace201ResponseHeaders

type CreateNamespace201ResponseHeaders struct {
	Location *string
}

type CreateNamespace400ApplicationProblemPlusJSONResponse

type CreateNamespace400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (CreateNamespace400ApplicationProblemPlusJSONResponse) VisitCreateNamespaceResponse

func (response CreateNamespace400ApplicationProblemPlusJSONResponse) VisitCreateNamespaceResponse(w http.ResponseWriter) error

type CreateNamespace401ApplicationProblemPlusJSONResponse

type CreateNamespace401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (CreateNamespace401ApplicationProblemPlusJSONResponse) VisitCreateNamespaceResponse

func (response CreateNamespace401ApplicationProblemPlusJSONResponse) VisitCreateNamespaceResponse(w http.ResponseWriter) error

type CreateNamespace403ApplicationProblemPlusJSONResponse

type CreateNamespace403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (CreateNamespace403ApplicationProblemPlusJSONResponse) VisitCreateNamespaceResponse

func (response CreateNamespace403ApplicationProblemPlusJSONResponse) VisitCreateNamespaceResponse(w http.ResponseWriter) error

type CreateNamespace404ApplicationProblemPlusJSONResponse

type CreateNamespace404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (CreateNamespace404ApplicationProblemPlusJSONResponse) VisitCreateNamespaceResponse

func (response CreateNamespace404ApplicationProblemPlusJSONResponse) VisitCreateNamespaceResponse(w http.ResponseWriter) error

type CreateNamespace409ApplicationProblemPlusJSONResponse

type CreateNamespace409ApplicationProblemPlusJSONResponse struct {
	ConflictApplicationProblemPlusJSONResponse
}

func (CreateNamespace409ApplicationProblemPlusJSONResponse) VisitCreateNamespaceResponse

func (response CreateNamespace409ApplicationProblemPlusJSONResponse) VisitCreateNamespaceResponse(w http.ResponseWriter) error

type CreateNamespaceJSONRequestBody

type CreateNamespaceJSONRequestBody = NamespaceCreate

CreateNamespaceJSONRequestBody defines body for CreateNamespace for application/json ContentType.

type CreateNamespaceRequestObject

type CreateNamespaceRequestObject struct {
	Body *CreateNamespaceJSONRequestBody
}

type CreateNamespaceResponseObject

type CreateNamespaceResponseObject interface {
	VisitCreateNamespaceResponse(w http.ResponseWriter) error
}

type CreateNetworkPolicy200JSONResponse added in v1.4.0

type CreateNetworkPolicy200JSONResponse NetworkPolicy

func (CreateNetworkPolicy200JSONResponse) VisitCreateNetworkPolicyResponse added in v1.4.0

func (response CreateNetworkPolicy200JSONResponse) VisitCreateNetworkPolicyResponse(w http.ResponseWriter) error

type CreateNetworkPolicy201JSONResponse added in v1.4.0

type CreateNetworkPolicy201JSONResponse NetworkPolicy

func (CreateNetworkPolicy201JSONResponse) VisitCreateNetworkPolicyResponse added in v1.4.0

func (response CreateNetworkPolicy201JSONResponse) VisitCreateNetworkPolicyResponse(w http.ResponseWriter) error

type CreateNetworkPolicy400ApplicationProblemPlusJSONResponse added in v1.4.0

type CreateNetworkPolicy400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (CreateNetworkPolicy400ApplicationProblemPlusJSONResponse) VisitCreateNetworkPolicyResponse added in v1.4.0

func (response CreateNetworkPolicy400ApplicationProblemPlusJSONResponse) VisitCreateNetworkPolicyResponse(w http.ResponseWriter) error

type CreateNetworkPolicy401ApplicationProblemPlusJSONResponse added in v1.4.0

type CreateNetworkPolicy401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (CreateNetworkPolicy401ApplicationProblemPlusJSONResponse) VisitCreateNetworkPolicyResponse added in v1.4.0

func (response CreateNetworkPolicy401ApplicationProblemPlusJSONResponse) VisitCreateNetworkPolicyResponse(w http.ResponseWriter) error

type CreateNetworkPolicy403ApplicationProblemPlusJSONResponse added in v1.4.0

type CreateNetworkPolicy403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (CreateNetworkPolicy403ApplicationProblemPlusJSONResponse) VisitCreateNetworkPolicyResponse added in v1.4.0

func (response CreateNetworkPolicy403ApplicationProblemPlusJSONResponse) VisitCreateNetworkPolicyResponse(w http.ResponseWriter) error

type CreateNetworkPolicy409ApplicationProblemPlusJSONResponse added in v1.4.0

type CreateNetworkPolicy409ApplicationProblemPlusJSONResponse struct {
	ConflictApplicationProblemPlusJSONResponse
}

func (CreateNetworkPolicy409ApplicationProblemPlusJSONResponse) VisitCreateNetworkPolicyResponse added in v1.4.0

func (response CreateNetworkPolicy409ApplicationProblemPlusJSONResponse) VisitCreateNetworkPolicyResponse(w http.ResponseWriter) error

type CreateNetworkPolicyJSONRequestBody added in v1.4.0

type CreateNetworkPolicyJSONRequestBody = NetworkPolicyCreate

CreateNetworkPolicyJSONRequestBody defines body for CreateNetworkPolicy for application/json ContentType.

type CreateNetworkPolicyRequestObject added in v1.4.0

type CreateNetworkPolicyRequestObject struct {
	Body *CreateNetworkPolicyJSONRequestBody
}

type CreateNetworkPolicyResponseObject added in v1.4.0

type CreateNetworkPolicyResponseObject interface {
	VisitCreateNetworkPolicyResponse(w http.ResponseWriter) error
}

type CreateNode201JSONResponse

type CreateNode201JSONResponse struct {
	Body    Node
	Headers CreateNode201ResponseHeaders
}

func (CreateNode201JSONResponse) VisitCreateNodeResponse

func (response CreateNode201JSONResponse) VisitCreateNodeResponse(w http.ResponseWriter) error

type CreateNode201ResponseHeaders

type CreateNode201ResponseHeaders struct {
	Location *string
}

type CreateNode400ApplicationProblemPlusJSONResponse

type CreateNode400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (CreateNode400ApplicationProblemPlusJSONResponse) VisitCreateNodeResponse

func (response CreateNode400ApplicationProblemPlusJSONResponse) VisitCreateNodeResponse(w http.ResponseWriter) error

type CreateNode401ApplicationProblemPlusJSONResponse

type CreateNode401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (CreateNode401ApplicationProblemPlusJSONResponse) VisitCreateNodeResponse

func (response CreateNode401ApplicationProblemPlusJSONResponse) VisitCreateNodeResponse(w http.ResponseWriter) error

type CreateNode403ApplicationProblemPlusJSONResponse

type CreateNode403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (CreateNode403ApplicationProblemPlusJSONResponse) VisitCreateNodeResponse

func (response CreateNode403ApplicationProblemPlusJSONResponse) VisitCreateNodeResponse(w http.ResponseWriter) error

type CreateNode404ApplicationProblemPlusJSONResponse

type CreateNode404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (CreateNode404ApplicationProblemPlusJSONResponse) VisitCreateNodeResponse

func (response CreateNode404ApplicationProblemPlusJSONResponse) VisitCreateNodeResponse(w http.ResponseWriter) error

type CreateNode409ApplicationProblemPlusJSONResponse

type CreateNode409ApplicationProblemPlusJSONResponse struct {
	ConflictApplicationProblemPlusJSONResponse
}

func (CreateNode409ApplicationProblemPlusJSONResponse) VisitCreateNodeResponse

func (response CreateNode409ApplicationProblemPlusJSONResponse) VisitCreateNodeResponse(w http.ResponseWriter) error

type CreateNodeJSONRequestBody

type CreateNodeJSONRequestBody = NodeCreate

CreateNodeJSONRequestBody defines body for CreateNode for application/json ContentType.

type CreateNodeRequestObject

type CreateNodeRequestObject struct {
	Body *CreateNodeJSONRequestBody
}

type CreateNodeResponseObject

type CreateNodeResponseObject interface {
	VisitCreateNodeResponse(w http.ResponseWriter) error
}

type CreatePersistentVolume201JSONResponse

type CreatePersistentVolume201JSONResponse struct {
	Body    PersistentVolume
	Headers CreatePersistentVolume201ResponseHeaders
}

func (CreatePersistentVolume201JSONResponse) VisitCreatePersistentVolumeResponse

func (response CreatePersistentVolume201JSONResponse) VisitCreatePersistentVolumeResponse(w http.ResponseWriter) error

type CreatePersistentVolume201ResponseHeaders

type CreatePersistentVolume201ResponseHeaders struct {
	Location *string
}

type CreatePersistentVolume400ApplicationProblemPlusJSONResponse

type CreatePersistentVolume400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (CreatePersistentVolume400ApplicationProblemPlusJSONResponse) VisitCreatePersistentVolumeResponse

func (response CreatePersistentVolume400ApplicationProblemPlusJSONResponse) VisitCreatePersistentVolumeResponse(w http.ResponseWriter) error

type CreatePersistentVolume401ApplicationProblemPlusJSONResponse

type CreatePersistentVolume401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (CreatePersistentVolume401ApplicationProblemPlusJSONResponse) VisitCreatePersistentVolumeResponse

func (response CreatePersistentVolume401ApplicationProblemPlusJSONResponse) VisitCreatePersistentVolumeResponse(w http.ResponseWriter) error

type CreatePersistentVolume403ApplicationProblemPlusJSONResponse

type CreatePersistentVolume403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (CreatePersistentVolume403ApplicationProblemPlusJSONResponse) VisitCreatePersistentVolumeResponse

func (response CreatePersistentVolume403ApplicationProblemPlusJSONResponse) VisitCreatePersistentVolumeResponse(w http.ResponseWriter) error

type CreatePersistentVolume404ApplicationProblemPlusJSONResponse

type CreatePersistentVolume404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (CreatePersistentVolume404ApplicationProblemPlusJSONResponse) VisitCreatePersistentVolumeResponse

func (response CreatePersistentVolume404ApplicationProblemPlusJSONResponse) VisitCreatePersistentVolumeResponse(w http.ResponseWriter) error

type CreatePersistentVolume409ApplicationProblemPlusJSONResponse

type CreatePersistentVolume409ApplicationProblemPlusJSONResponse struct {
	ConflictApplicationProblemPlusJSONResponse
}

func (CreatePersistentVolume409ApplicationProblemPlusJSONResponse) VisitCreatePersistentVolumeResponse

func (response CreatePersistentVolume409ApplicationProblemPlusJSONResponse) VisitCreatePersistentVolumeResponse(w http.ResponseWriter) error

type CreatePersistentVolumeClaim201JSONResponse

type CreatePersistentVolumeClaim201JSONResponse struct {
	Body    PersistentVolumeClaim
	Headers CreatePersistentVolumeClaim201ResponseHeaders
}

func (CreatePersistentVolumeClaim201JSONResponse) VisitCreatePersistentVolumeClaimResponse

func (response CreatePersistentVolumeClaim201JSONResponse) VisitCreatePersistentVolumeClaimResponse(w http.ResponseWriter) error

type CreatePersistentVolumeClaim201ResponseHeaders

type CreatePersistentVolumeClaim201ResponseHeaders struct {
	Location *string
}

type CreatePersistentVolumeClaim400ApplicationProblemPlusJSONResponse

type CreatePersistentVolumeClaim400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (CreatePersistentVolumeClaim400ApplicationProblemPlusJSONResponse) VisitCreatePersistentVolumeClaimResponse

func (response CreatePersistentVolumeClaim400ApplicationProblemPlusJSONResponse) VisitCreatePersistentVolumeClaimResponse(w http.ResponseWriter) error

type CreatePersistentVolumeClaim401ApplicationProblemPlusJSONResponse

type CreatePersistentVolumeClaim401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (CreatePersistentVolumeClaim401ApplicationProblemPlusJSONResponse) VisitCreatePersistentVolumeClaimResponse

func (response CreatePersistentVolumeClaim401ApplicationProblemPlusJSONResponse) VisitCreatePersistentVolumeClaimResponse(w http.ResponseWriter) error

type CreatePersistentVolumeClaim403ApplicationProblemPlusJSONResponse

type CreatePersistentVolumeClaim403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (CreatePersistentVolumeClaim403ApplicationProblemPlusJSONResponse) VisitCreatePersistentVolumeClaimResponse

func (response CreatePersistentVolumeClaim403ApplicationProblemPlusJSONResponse) VisitCreatePersistentVolumeClaimResponse(w http.ResponseWriter) error

type CreatePersistentVolumeClaim404ApplicationProblemPlusJSONResponse

type CreatePersistentVolumeClaim404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (CreatePersistentVolumeClaim404ApplicationProblemPlusJSONResponse) VisitCreatePersistentVolumeClaimResponse

func (response CreatePersistentVolumeClaim404ApplicationProblemPlusJSONResponse) VisitCreatePersistentVolumeClaimResponse(w http.ResponseWriter) error

type CreatePersistentVolumeClaim409ApplicationProblemPlusJSONResponse

type CreatePersistentVolumeClaim409ApplicationProblemPlusJSONResponse struct {
	ConflictApplicationProblemPlusJSONResponse
}

func (CreatePersistentVolumeClaim409ApplicationProblemPlusJSONResponse) VisitCreatePersistentVolumeClaimResponse

func (response CreatePersistentVolumeClaim409ApplicationProblemPlusJSONResponse) VisitCreatePersistentVolumeClaimResponse(w http.ResponseWriter) error

type CreatePersistentVolumeClaimJSONRequestBody

type CreatePersistentVolumeClaimJSONRequestBody = PersistentVolumeClaimCreate

CreatePersistentVolumeClaimJSONRequestBody defines body for CreatePersistentVolumeClaim for application/json ContentType.

type CreatePersistentVolumeClaimRequestObject

type CreatePersistentVolumeClaimRequestObject struct {
	Body *CreatePersistentVolumeClaimJSONRequestBody
}

type CreatePersistentVolumeClaimResponseObject

type CreatePersistentVolumeClaimResponseObject interface {
	VisitCreatePersistentVolumeClaimResponse(w http.ResponseWriter) error
}

type CreatePersistentVolumeJSONRequestBody

type CreatePersistentVolumeJSONRequestBody = PersistentVolumeCreate

CreatePersistentVolumeJSONRequestBody defines body for CreatePersistentVolume for application/json ContentType.

type CreatePersistentVolumeRequestObject

type CreatePersistentVolumeRequestObject struct {
	Body *CreatePersistentVolumeJSONRequestBody
}

type CreatePersistentVolumeResponseObject

type CreatePersistentVolumeResponseObject interface {
	VisitCreatePersistentVolumeResponse(w http.ResponseWriter) error
}

type CreatePod201JSONResponse

type CreatePod201JSONResponse struct {
	Body    Pod
	Headers CreatePod201ResponseHeaders
}

func (CreatePod201JSONResponse) VisitCreatePodResponse

func (response CreatePod201JSONResponse) VisitCreatePodResponse(w http.ResponseWriter) error

type CreatePod201ResponseHeaders

type CreatePod201ResponseHeaders struct {
	Location *string
}

type CreatePod400ApplicationProblemPlusJSONResponse

type CreatePod400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (CreatePod400ApplicationProblemPlusJSONResponse) VisitCreatePodResponse

func (response CreatePod400ApplicationProblemPlusJSONResponse) VisitCreatePodResponse(w http.ResponseWriter) error

type CreatePod401ApplicationProblemPlusJSONResponse

type CreatePod401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (CreatePod401ApplicationProblemPlusJSONResponse) VisitCreatePodResponse

func (response CreatePod401ApplicationProblemPlusJSONResponse) VisitCreatePodResponse(w http.ResponseWriter) error

type CreatePod403ApplicationProblemPlusJSONResponse

type CreatePod403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (CreatePod403ApplicationProblemPlusJSONResponse) VisitCreatePodResponse

func (response CreatePod403ApplicationProblemPlusJSONResponse) VisitCreatePodResponse(w http.ResponseWriter) error

type CreatePod404ApplicationProblemPlusJSONResponse

type CreatePod404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (CreatePod404ApplicationProblemPlusJSONResponse) VisitCreatePodResponse

func (response CreatePod404ApplicationProblemPlusJSONResponse) VisitCreatePodResponse(w http.ResponseWriter) error

type CreatePod409ApplicationProblemPlusJSONResponse

type CreatePod409ApplicationProblemPlusJSONResponse struct {
	ConflictApplicationProblemPlusJSONResponse
}

func (CreatePod409ApplicationProblemPlusJSONResponse) VisitCreatePodResponse

func (response CreatePod409ApplicationProblemPlusJSONResponse) VisitCreatePodResponse(w http.ResponseWriter) error

type CreatePodJSONRequestBody

type CreatePodJSONRequestBody = PodCreate

CreatePodJSONRequestBody defines body for CreatePod for application/json ContentType.

type CreatePodRequestObject

type CreatePodRequestObject struct {
	Body *CreatePodJSONRequestBody
}

type CreatePodResponseObject

type CreatePodResponseObject interface {
	VisitCreatePodResponse(w http.ResponseWriter) error
}

type CreateService201JSONResponse

type CreateService201JSONResponse struct {
	Body    Service
	Headers CreateService201ResponseHeaders
}

func (CreateService201JSONResponse) VisitCreateServiceResponse

func (response CreateService201JSONResponse) VisitCreateServiceResponse(w http.ResponseWriter) error

type CreateService201ResponseHeaders

type CreateService201ResponseHeaders struct {
	Location *string
}

type CreateService400ApplicationProblemPlusJSONResponse

type CreateService400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (CreateService400ApplicationProblemPlusJSONResponse) VisitCreateServiceResponse

func (response CreateService400ApplicationProblemPlusJSONResponse) VisitCreateServiceResponse(w http.ResponseWriter) error

type CreateService401ApplicationProblemPlusJSONResponse

type CreateService401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (CreateService401ApplicationProblemPlusJSONResponse) VisitCreateServiceResponse

func (response CreateService401ApplicationProblemPlusJSONResponse) VisitCreateServiceResponse(w http.ResponseWriter) error

type CreateService403ApplicationProblemPlusJSONResponse

type CreateService403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (CreateService403ApplicationProblemPlusJSONResponse) VisitCreateServiceResponse

func (response CreateService403ApplicationProblemPlusJSONResponse) VisitCreateServiceResponse(w http.ResponseWriter) error

type CreateService404ApplicationProblemPlusJSONResponse

type CreateService404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (CreateService404ApplicationProblemPlusJSONResponse) VisitCreateServiceResponse

func (response CreateService404ApplicationProblemPlusJSONResponse) VisitCreateServiceResponse(w http.ResponseWriter) error

type CreateService409ApplicationProblemPlusJSONResponse

type CreateService409ApplicationProblemPlusJSONResponse struct {
	ConflictApplicationProblemPlusJSONResponse
}

func (CreateService409ApplicationProblemPlusJSONResponse) VisitCreateServiceResponse

func (response CreateService409ApplicationProblemPlusJSONResponse) VisitCreateServiceResponse(w http.ResponseWriter) error

type CreateServiceJSONRequestBody

type CreateServiceJSONRequestBody = ServiceCreate

CreateServiceJSONRequestBody defines body for CreateService for application/json ContentType.

type CreateServiceRequestObject

type CreateServiceRequestObject struct {
	Body *CreateServiceJSONRequestBody
}

type CreateServiceResponseObject

type CreateServiceResponseObject interface {
	VisitCreateServiceResponse(w http.ResponseWriter) error
}

type CreateUser201JSONResponse

type CreateUser201JSONResponse User

func (CreateUser201JSONResponse) VisitCreateUserResponse

func (response CreateUser201JSONResponse) VisitCreateUserResponse(w http.ResponseWriter) error

type CreateUser400ApplicationProblemPlusJSONResponse

type CreateUser400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (CreateUser400ApplicationProblemPlusJSONResponse) VisitCreateUserResponse

func (response CreateUser400ApplicationProblemPlusJSONResponse) VisitCreateUserResponse(w http.ResponseWriter) error

type CreateUser401ApplicationProblemPlusJSONResponse

type CreateUser401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (CreateUser401ApplicationProblemPlusJSONResponse) VisitCreateUserResponse

func (response CreateUser401ApplicationProblemPlusJSONResponse) VisitCreateUserResponse(w http.ResponseWriter) error

type CreateUser403ApplicationProblemPlusJSONResponse

type CreateUser403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (CreateUser403ApplicationProblemPlusJSONResponse) VisitCreateUserResponse

func (response CreateUser403ApplicationProblemPlusJSONResponse) VisitCreateUserResponse(w http.ResponseWriter) error

type CreateUser409ApplicationProblemPlusJSONResponse

type CreateUser409ApplicationProblemPlusJSONResponse struct {
	ConflictApplicationProblemPlusJSONResponse
}

func (CreateUser409ApplicationProblemPlusJSONResponse) VisitCreateUserResponse

func (response CreateUser409ApplicationProblemPlusJSONResponse) VisitCreateUserResponse(w http.ResponseWriter) error

type CreateUserJSONRequestBody

type CreateUserJSONRequestBody = UserCreate

CreateUserJSONRequestBody defines body for CreateUser for application/json ContentType.

type CreateUserRequestObject

type CreateUserRequestObject struct {
	Body *CreateUserJSONRequestBody
}

type CreateUserResponseObject

type CreateUserResponseObject interface {
	VisitCreateUserResponse(w http.ResponseWriter) error
}

type CreateWorkload201JSONResponse

type CreateWorkload201JSONResponse struct {
	Body    Workload
	Headers CreateWorkload201ResponseHeaders
}

func (CreateWorkload201JSONResponse) VisitCreateWorkloadResponse

func (response CreateWorkload201JSONResponse) VisitCreateWorkloadResponse(w http.ResponseWriter) error

type CreateWorkload201ResponseHeaders

type CreateWorkload201ResponseHeaders struct {
	Location *string
}

type CreateWorkload400ApplicationProblemPlusJSONResponse

type CreateWorkload400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (CreateWorkload400ApplicationProblemPlusJSONResponse) VisitCreateWorkloadResponse

func (response CreateWorkload400ApplicationProblemPlusJSONResponse) VisitCreateWorkloadResponse(w http.ResponseWriter) error

type CreateWorkload401ApplicationProblemPlusJSONResponse

type CreateWorkload401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (CreateWorkload401ApplicationProblemPlusJSONResponse) VisitCreateWorkloadResponse

func (response CreateWorkload401ApplicationProblemPlusJSONResponse) VisitCreateWorkloadResponse(w http.ResponseWriter) error

type CreateWorkload403ApplicationProblemPlusJSONResponse

type CreateWorkload403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (CreateWorkload403ApplicationProblemPlusJSONResponse) VisitCreateWorkloadResponse

func (response CreateWorkload403ApplicationProblemPlusJSONResponse) VisitCreateWorkloadResponse(w http.ResponseWriter) error

type CreateWorkload404ApplicationProblemPlusJSONResponse

type CreateWorkload404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (CreateWorkload404ApplicationProblemPlusJSONResponse) VisitCreateWorkloadResponse

func (response CreateWorkload404ApplicationProblemPlusJSONResponse) VisitCreateWorkloadResponse(w http.ResponseWriter) error

type CreateWorkload409ApplicationProblemPlusJSONResponse

type CreateWorkload409ApplicationProblemPlusJSONResponse struct {
	ConflictApplicationProblemPlusJSONResponse
}

func (CreateWorkload409ApplicationProblemPlusJSONResponse) VisitCreateWorkloadResponse

func (response CreateWorkload409ApplicationProblemPlusJSONResponse) VisitCreateWorkloadResponse(w http.ResponseWriter) error

type CreateWorkloadJSONRequestBody

type CreateWorkloadJSONRequestBody = WorkloadCreate

CreateWorkloadJSONRequestBody defines body for CreateWorkload for application/json ContentType.

type CreateWorkloadRequestObject

type CreateWorkloadRequestObject struct {
	Body *CreateWorkloadJSONRequestBody
}

type CreateWorkloadResponseObject

type CreateWorkloadResponseObject interface {
	VisitCreateWorkloadResponse(w http.ResponseWriter) error
}

type Cursor

type Cursor = string

Cursor defines model for Cursor.

type DICTSource added in v0.28.0

type DICTSource string

DICTSource names where an entity's effective DICT classification came from. See ADR-0029 §6 for the precedence rules.

const (
	// DICTSourceApplication — the value was inherited from the linked
	// Application's DICT (the highest-precedence source).
	DICTSourceApplication DICTSource = "application"
	// DICTSourceWorkload — the value came from the workload's own DICT
	// columns (fallback when the entity is unlinked or the linked
	// application carries no DICT axis).
	DICTSourceWorkload DICTSource = "workload"
	// DICTSourceNamespace — symmetric fallback for namespace-scoped
	// inheritance.
	DICTSourceNamespace DICTSource = "namespace"
	// DICTSourceNone — neither the linked application nor the entity itself
	// carries any DICT axis.
	DICTSourceNone DICTSource = "none"
)

type DeleteCluster204Response

type DeleteCluster204Response struct {
}

func (DeleteCluster204Response) VisitDeleteClusterResponse

func (response DeleteCluster204Response) VisitDeleteClusterResponse(w http.ResponseWriter) error

type DeleteCluster401ApplicationProblemPlusJSONResponse

type DeleteCluster401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (DeleteCluster401ApplicationProblemPlusJSONResponse) VisitDeleteClusterResponse

func (response DeleteCluster401ApplicationProblemPlusJSONResponse) VisitDeleteClusterResponse(w http.ResponseWriter) error

type DeleteCluster403ApplicationProblemPlusJSONResponse

type DeleteCluster403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (DeleteCluster403ApplicationProblemPlusJSONResponse) VisitDeleteClusterResponse

func (response DeleteCluster403ApplicationProblemPlusJSONResponse) VisitDeleteClusterResponse(w http.ResponseWriter) error

type DeleteCluster404ApplicationProblemPlusJSONResponse

type DeleteCluster404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (DeleteCluster404ApplicationProblemPlusJSONResponse) VisitDeleteClusterResponse

func (response DeleteCluster404ApplicationProblemPlusJSONResponse) VisitDeleteClusterResponse(w http.ResponseWriter) error

type DeleteClusterRequestObject

type DeleteClusterRequestObject struct {
	Id ClusterId `json:"id"`
}

type DeleteClusterResponseObject

type DeleteClusterResponseObject interface {
	VisitDeleteClusterResponse(w http.ResponseWriter) error
}

type DeleteImageOriginMapping204Response added in v0.30.0

type DeleteImageOriginMapping204Response struct {
}

func (DeleteImageOriginMapping204Response) VisitDeleteImageOriginMappingResponse added in v0.30.0

func (response DeleteImageOriginMapping204Response) VisitDeleteImageOriginMappingResponse(w http.ResponseWriter) error

type DeleteImageOriginMapping401ApplicationProblemPlusJSONResponse added in v0.30.0

type DeleteImageOriginMapping401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (DeleteImageOriginMapping401ApplicationProblemPlusJSONResponse) VisitDeleteImageOriginMappingResponse added in v0.30.0

func (response DeleteImageOriginMapping401ApplicationProblemPlusJSONResponse) VisitDeleteImageOriginMappingResponse(w http.ResponseWriter) error

type DeleteImageOriginMapping403ApplicationProblemPlusJSONResponse added in v0.30.0

type DeleteImageOriginMapping403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (DeleteImageOriginMapping403ApplicationProblemPlusJSONResponse) VisitDeleteImageOriginMappingResponse added in v0.30.0

func (response DeleteImageOriginMapping403ApplicationProblemPlusJSONResponse) VisitDeleteImageOriginMappingResponse(w http.ResponseWriter) error

type DeleteImageOriginMapping404ApplicationProblemPlusJSONResponse added in v0.30.0

type DeleteImageOriginMapping404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (DeleteImageOriginMapping404ApplicationProblemPlusJSONResponse) VisitDeleteImageOriginMappingResponse added in v0.30.0

func (response DeleteImageOriginMapping404ApplicationProblemPlusJSONResponse) VisitDeleteImageOriginMappingResponse(w http.ResponseWriter) error

type DeleteImageOriginMappingRequestObject added in v0.30.0

type DeleteImageOriginMappingRequestObject struct {
	ImageName string `json:"image_name"`
}

type DeleteImageOriginMappingResponseObject added in v0.30.0

type DeleteImageOriginMappingResponseObject interface {
	VisitDeleteImageOriginMappingResponse(w http.ResponseWriter) error
}

type DeleteImageRegistry204Response

type DeleteImageRegistry204Response struct {
}

func (DeleteImageRegistry204Response) VisitDeleteImageRegistryResponse

func (response DeleteImageRegistry204Response) VisitDeleteImageRegistryResponse(w http.ResponseWriter) error

type DeleteImageRegistry401ApplicationProblemPlusJSONResponse

type DeleteImageRegistry401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (DeleteImageRegistry401ApplicationProblemPlusJSONResponse) VisitDeleteImageRegistryResponse

func (response DeleteImageRegistry401ApplicationProblemPlusJSONResponse) VisitDeleteImageRegistryResponse(w http.ResponseWriter) error

type DeleteImageRegistry403ApplicationProblemPlusJSONResponse

type DeleteImageRegistry403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (DeleteImageRegistry403ApplicationProblemPlusJSONResponse) VisitDeleteImageRegistryResponse

func (response DeleteImageRegistry403ApplicationProblemPlusJSONResponse) VisitDeleteImageRegistryResponse(w http.ResponseWriter) error

type DeleteImageRegistry404ApplicationProblemPlusJSONResponse

type DeleteImageRegistry404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (DeleteImageRegistry404ApplicationProblemPlusJSONResponse) VisitDeleteImageRegistryResponse

func (response DeleteImageRegistry404ApplicationProblemPlusJSONResponse) VisitDeleteImageRegistryResponse(w http.ResponseWriter) error

type DeleteImageRegistryRequestObject

type DeleteImageRegistryRequestObject struct {
	Hostname   string `json:"hostname"`
	PathPrefix string `json:"path_prefix"`
}

type DeleteImageRegistryResponseObject

type DeleteImageRegistryResponseObject interface {
	VisitDeleteImageRegistryResponse(w http.ResponseWriter) error
}

type DeleteIngress204Response

type DeleteIngress204Response struct {
}

func (DeleteIngress204Response) VisitDeleteIngressResponse

func (response DeleteIngress204Response) VisitDeleteIngressResponse(w http.ResponseWriter) error

type DeleteIngress401ApplicationProblemPlusJSONResponse

type DeleteIngress401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (DeleteIngress401ApplicationProblemPlusJSONResponse) VisitDeleteIngressResponse

func (response DeleteIngress401ApplicationProblemPlusJSONResponse) VisitDeleteIngressResponse(w http.ResponseWriter) error

type DeleteIngress403ApplicationProblemPlusJSONResponse

type DeleteIngress403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (DeleteIngress403ApplicationProblemPlusJSONResponse) VisitDeleteIngressResponse

func (response DeleteIngress403ApplicationProblemPlusJSONResponse) VisitDeleteIngressResponse(w http.ResponseWriter) error

type DeleteIngress404ApplicationProblemPlusJSONResponse

type DeleteIngress404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (DeleteIngress404ApplicationProblemPlusJSONResponse) VisitDeleteIngressResponse

func (response DeleteIngress404ApplicationProblemPlusJSONResponse) VisitDeleteIngressResponse(w http.ResponseWriter) error

type DeleteIngressRequestObject

type DeleteIngressRequestObject struct {
	Id IngressId `json:"id"`
}

type DeleteIngressResponseObject

type DeleteIngressResponseObject interface {
	VisitDeleteIngressResponse(w http.ResponseWriter) error
}

type DeleteNamespace204Response

type DeleteNamespace204Response struct {
}

func (DeleteNamespace204Response) VisitDeleteNamespaceResponse

func (response DeleteNamespace204Response) VisitDeleteNamespaceResponse(w http.ResponseWriter) error

type DeleteNamespace401ApplicationProblemPlusJSONResponse

type DeleteNamespace401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (DeleteNamespace401ApplicationProblemPlusJSONResponse) VisitDeleteNamespaceResponse

func (response DeleteNamespace401ApplicationProblemPlusJSONResponse) VisitDeleteNamespaceResponse(w http.ResponseWriter) error

type DeleteNamespace403ApplicationProblemPlusJSONResponse

type DeleteNamespace403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (DeleteNamespace403ApplicationProblemPlusJSONResponse) VisitDeleteNamespaceResponse

func (response DeleteNamespace403ApplicationProblemPlusJSONResponse) VisitDeleteNamespaceResponse(w http.ResponseWriter) error

type DeleteNamespace404ApplicationProblemPlusJSONResponse

type DeleteNamespace404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (DeleteNamespace404ApplicationProblemPlusJSONResponse) VisitDeleteNamespaceResponse

func (response DeleteNamespace404ApplicationProblemPlusJSONResponse) VisitDeleteNamespaceResponse(w http.ResponseWriter) error

type DeleteNamespaceRequestObject

type DeleteNamespaceRequestObject struct {
	Id NamespaceId `json:"id"`
}

type DeleteNamespaceResponseObject

type DeleteNamespaceResponseObject interface {
	VisitDeleteNamespaceResponse(w http.ResponseWriter) error
}

type DeleteNode204Response

type DeleteNode204Response struct {
}

func (DeleteNode204Response) VisitDeleteNodeResponse

func (response DeleteNode204Response) VisitDeleteNodeResponse(w http.ResponseWriter) error

type DeleteNode401ApplicationProblemPlusJSONResponse

type DeleteNode401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (DeleteNode401ApplicationProblemPlusJSONResponse) VisitDeleteNodeResponse

func (response DeleteNode401ApplicationProblemPlusJSONResponse) VisitDeleteNodeResponse(w http.ResponseWriter) error

type DeleteNode403ApplicationProblemPlusJSONResponse

type DeleteNode403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (DeleteNode403ApplicationProblemPlusJSONResponse) VisitDeleteNodeResponse

func (response DeleteNode403ApplicationProblemPlusJSONResponse) VisitDeleteNodeResponse(w http.ResponseWriter) error

type DeleteNode404ApplicationProblemPlusJSONResponse

type DeleteNode404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (DeleteNode404ApplicationProblemPlusJSONResponse) VisitDeleteNodeResponse

func (response DeleteNode404ApplicationProblemPlusJSONResponse) VisitDeleteNodeResponse(w http.ResponseWriter) error

type DeleteNodeRequestObject

type DeleteNodeRequestObject struct {
	Id NodeId `json:"id"`
}

type DeleteNodeResponseObject

type DeleteNodeResponseObject interface {
	VisitDeleteNodeResponse(w http.ResponseWriter) error
}

type DeletePersistentVolume204Response

type DeletePersistentVolume204Response struct {
}

func (DeletePersistentVolume204Response) VisitDeletePersistentVolumeResponse

func (response DeletePersistentVolume204Response) VisitDeletePersistentVolumeResponse(w http.ResponseWriter) error

type DeletePersistentVolume401ApplicationProblemPlusJSONResponse

type DeletePersistentVolume401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (DeletePersistentVolume401ApplicationProblemPlusJSONResponse) VisitDeletePersistentVolumeResponse

func (response DeletePersistentVolume401ApplicationProblemPlusJSONResponse) VisitDeletePersistentVolumeResponse(w http.ResponseWriter) error

type DeletePersistentVolume403ApplicationProblemPlusJSONResponse

type DeletePersistentVolume403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (DeletePersistentVolume403ApplicationProblemPlusJSONResponse) VisitDeletePersistentVolumeResponse

func (response DeletePersistentVolume403ApplicationProblemPlusJSONResponse) VisitDeletePersistentVolumeResponse(w http.ResponseWriter) error

type DeletePersistentVolume404ApplicationProblemPlusJSONResponse

type DeletePersistentVolume404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (DeletePersistentVolume404ApplicationProblemPlusJSONResponse) VisitDeletePersistentVolumeResponse

func (response DeletePersistentVolume404ApplicationProblemPlusJSONResponse) VisitDeletePersistentVolumeResponse(w http.ResponseWriter) error

type DeletePersistentVolumeClaim204Response

type DeletePersistentVolumeClaim204Response struct {
}

func (DeletePersistentVolumeClaim204Response) VisitDeletePersistentVolumeClaimResponse

func (response DeletePersistentVolumeClaim204Response) VisitDeletePersistentVolumeClaimResponse(w http.ResponseWriter) error

type DeletePersistentVolumeClaim401ApplicationProblemPlusJSONResponse

type DeletePersistentVolumeClaim401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (DeletePersistentVolumeClaim401ApplicationProblemPlusJSONResponse) VisitDeletePersistentVolumeClaimResponse

func (response DeletePersistentVolumeClaim401ApplicationProblemPlusJSONResponse) VisitDeletePersistentVolumeClaimResponse(w http.ResponseWriter) error

type DeletePersistentVolumeClaim403ApplicationProblemPlusJSONResponse

type DeletePersistentVolumeClaim403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (DeletePersistentVolumeClaim403ApplicationProblemPlusJSONResponse) VisitDeletePersistentVolumeClaimResponse

func (response DeletePersistentVolumeClaim403ApplicationProblemPlusJSONResponse) VisitDeletePersistentVolumeClaimResponse(w http.ResponseWriter) error

type DeletePersistentVolumeClaim404ApplicationProblemPlusJSONResponse

type DeletePersistentVolumeClaim404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (DeletePersistentVolumeClaim404ApplicationProblemPlusJSONResponse) VisitDeletePersistentVolumeClaimResponse

func (response DeletePersistentVolumeClaim404ApplicationProblemPlusJSONResponse) VisitDeletePersistentVolumeClaimResponse(w http.ResponseWriter) error

type DeletePersistentVolumeClaimRequestObject

type DeletePersistentVolumeClaimRequestObject struct {
	Id PersistentVolumeClaimId `json:"id"`
}

type DeletePersistentVolumeClaimResponseObject

type DeletePersistentVolumeClaimResponseObject interface {
	VisitDeletePersistentVolumeClaimResponse(w http.ResponseWriter) error
}

type DeletePersistentVolumeRequestObject

type DeletePersistentVolumeRequestObject struct {
	Id PersistentVolumeId `json:"id"`
}

type DeletePersistentVolumeResponseObject

type DeletePersistentVolumeResponseObject interface {
	VisitDeletePersistentVolumeResponse(w http.ResponseWriter) error
}

type DeletePod204Response

type DeletePod204Response struct {
}

func (DeletePod204Response) VisitDeletePodResponse

func (response DeletePod204Response) VisitDeletePodResponse(w http.ResponseWriter) error

type DeletePod401ApplicationProblemPlusJSONResponse

type DeletePod401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (DeletePod401ApplicationProblemPlusJSONResponse) VisitDeletePodResponse

func (response DeletePod401ApplicationProblemPlusJSONResponse) VisitDeletePodResponse(w http.ResponseWriter) error

type DeletePod403ApplicationProblemPlusJSONResponse

type DeletePod403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (DeletePod403ApplicationProblemPlusJSONResponse) VisitDeletePodResponse

func (response DeletePod403ApplicationProblemPlusJSONResponse) VisitDeletePodResponse(w http.ResponseWriter) error

type DeletePod404ApplicationProblemPlusJSONResponse

type DeletePod404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (DeletePod404ApplicationProblemPlusJSONResponse) VisitDeletePodResponse

func (response DeletePod404ApplicationProblemPlusJSONResponse) VisitDeletePodResponse(w http.ResponseWriter) error

type DeletePodRequestObject

type DeletePodRequestObject struct {
	Id PodId `json:"id"`
}

type DeletePodResponseObject

type DeletePodResponseObject interface {
	VisitDeletePodResponse(w http.ResponseWriter) error
}

type DeleteService204Response

type DeleteService204Response struct {
}

func (DeleteService204Response) VisitDeleteServiceResponse

func (response DeleteService204Response) VisitDeleteServiceResponse(w http.ResponseWriter) error

type DeleteService401ApplicationProblemPlusJSONResponse

type DeleteService401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (DeleteService401ApplicationProblemPlusJSONResponse) VisitDeleteServiceResponse

func (response DeleteService401ApplicationProblemPlusJSONResponse) VisitDeleteServiceResponse(w http.ResponseWriter) error

type DeleteService403ApplicationProblemPlusJSONResponse

type DeleteService403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (DeleteService403ApplicationProblemPlusJSONResponse) VisitDeleteServiceResponse

func (response DeleteService403ApplicationProblemPlusJSONResponse) VisitDeleteServiceResponse(w http.ResponseWriter) error

type DeleteService404ApplicationProblemPlusJSONResponse

type DeleteService404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (DeleteService404ApplicationProblemPlusJSONResponse) VisitDeleteServiceResponse

func (response DeleteService404ApplicationProblemPlusJSONResponse) VisitDeleteServiceResponse(w http.ResponseWriter) error

type DeleteServiceRequestObject

type DeleteServiceRequestObject struct {
	Id ServiceId `json:"id"`
}

type DeleteServiceResponseObject

type DeleteServiceResponseObject interface {
	VisitDeleteServiceResponse(w http.ResponseWriter) error
}

type DeleteUser204Response

type DeleteUser204Response struct {
}

func (DeleteUser204Response) VisitDeleteUserResponse

func (response DeleteUser204Response) VisitDeleteUserResponse(w http.ResponseWriter) error

type DeleteUser401ApplicationProblemPlusJSONResponse

type DeleteUser401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (DeleteUser401ApplicationProblemPlusJSONResponse) VisitDeleteUserResponse

func (response DeleteUser401ApplicationProblemPlusJSONResponse) VisitDeleteUserResponse(w http.ResponseWriter) error

type DeleteUser403ApplicationProblemPlusJSONResponse

type DeleteUser403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (DeleteUser403ApplicationProblemPlusJSONResponse) VisitDeleteUserResponse

func (response DeleteUser403ApplicationProblemPlusJSONResponse) VisitDeleteUserResponse(w http.ResponseWriter) error

type DeleteUser404ApplicationProblemPlusJSONResponse

type DeleteUser404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (DeleteUser404ApplicationProblemPlusJSONResponse) VisitDeleteUserResponse

func (response DeleteUser404ApplicationProblemPlusJSONResponse) VisitDeleteUserResponse(w http.ResponseWriter) error

type DeleteUser409ApplicationProblemPlusJSONResponse

type DeleteUser409ApplicationProblemPlusJSONResponse struct {
	ConflictApplicationProblemPlusJSONResponse
}

func (DeleteUser409ApplicationProblemPlusJSONResponse) VisitDeleteUserResponse

func (response DeleteUser409ApplicationProblemPlusJSONResponse) VisitDeleteUserResponse(w http.ResponseWriter) error

type DeleteUserRequestObject

type DeleteUserRequestObject struct {
	Id UserId `json:"id"`
}

type DeleteUserResponseObject

type DeleteUserResponseObject interface {
	VisitDeleteUserResponse(w http.ResponseWriter) error
}

type DeleteWorkload204Response

type DeleteWorkload204Response struct {
}

func (DeleteWorkload204Response) VisitDeleteWorkloadResponse

func (response DeleteWorkload204Response) VisitDeleteWorkloadResponse(w http.ResponseWriter) error

type DeleteWorkload401ApplicationProblemPlusJSONResponse

type DeleteWorkload401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (DeleteWorkload401ApplicationProblemPlusJSONResponse) VisitDeleteWorkloadResponse

func (response DeleteWorkload401ApplicationProblemPlusJSONResponse) VisitDeleteWorkloadResponse(w http.ResponseWriter) error

type DeleteWorkload403ApplicationProblemPlusJSONResponse

type DeleteWorkload403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (DeleteWorkload403ApplicationProblemPlusJSONResponse) VisitDeleteWorkloadResponse

func (response DeleteWorkload403ApplicationProblemPlusJSONResponse) VisitDeleteWorkloadResponse(w http.ResponseWriter) error

type DeleteWorkload404ApplicationProblemPlusJSONResponse

type DeleteWorkload404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (DeleteWorkload404ApplicationProblemPlusJSONResponse) VisitDeleteWorkloadResponse

func (response DeleteWorkload404ApplicationProblemPlusJSONResponse) VisitDeleteWorkloadResponse(w http.ResponseWriter) error

type DeleteWorkloadRequestObject

type DeleteWorkloadRequestObject struct {
	Id WorkloadId `json:"id"`
}

type DeleteWorkloadResponseObject

type DeleteWorkloadResponseObject interface {
	VisitDeleteWorkloadResponse(w http.ResponseWriter) error
}

type EffectiveDICT added in v0.28.0

type EffectiveDICT struct {
	Disponibilite   *int       `json:"disponibilite,omitempty"`
	Integrite       *int       `json:"integrite,omitempty"`
	Confidentialite *int       `json:"confidentialite,omitempty"`
	Tracabilite     *int       `json:"tracabilite,omitempty"`
	Notes           *string    `json:"notes,omitempty"`
	Source          DICTSource `json:"source"`
}

EffectiveDICT is the read-only inherited classification shipped on workload + VM responses (ADR-0029 §6). It is computed at read time and is never accepted on PATCH/POST bodies.

This struct is hand-written and excluded from oapi-codegen (see api/openapi/oapi-codegen.yaml) so the generated `Workload.EffectiveDict` field references it without codegen emitting a parallel struct.

func ComputeEffectiveDICT added in v0.28.0

func ComputeEffectiveDICT(
	fbD, fbI, fbC, fbT *int, fbNotes *string, fallbackSource DICTSource,
	linkedApp *Application,
) EffectiveDICT

ComputeEffectiveDICT computes inherited classification per ADR-0029 §6. The `fb*` args are the entity's own DICT axes (workload/namespace); pass all-nil for VMs, which have no DICT columns of their own. `fallbackSource` is DICTSourceWorkload or DICTSourceNamespace. `linkedApp` may be nil (unlinked).

Precedence:

  1. linked AND the application has any axis set → application's DICT.
  2. else the entity's own DICT has any axis set → fallbackSource.
  3. else → none.

type EndpointGroup added in v1.2.0

type EndpointGroup struct {
	ID        uuid.UUID  `json:"id"`
	Name      string     `json:"name"`
	Notes     string     `json:"notes,omitempty"`
	CIDRs     []string   `json:"cidrs"`
	CreatedBy *uuid.UUID `json:"created_by,omitempty"`
	CreatedAt time.Time  `json:"created_at"`
	UpdatedAt time.Time  `json:"updated_at"`
}

EndpointGroup is an operator-curated, named set of CIDRs referenced by flow references and used by the flow-matrix synthesizer to match perimeter peers.

type EndpointGroupInput added in v1.2.0

type EndpointGroupInput struct {
	Name  string   `json:"name"`
	Notes string   `json:"notes"`
	CIDRs []string `json:"cidrs"`
}

EndpointGroupInput is the create/update payload for an EndpointGroup.

type EnricherTrigger

type EnricherTrigger interface {
	Trigger() bool
	IsRunning() bool
}

EnricherTrigger abstracts the methods used by HandleRefreshImageVersions. Defined here so handlers don't pull in the imageversions package types directly.

type EolExtractRow added in v0.22.0

type EolExtractRow struct {
	CheckedAt       *string                 `json:"checked_at,omitempty"`
	Cluster         *string                 `json:"cluster,omitempty"`
	Cycle           string                  `json:"cycle"`
	EntityId        string                  `json:"entity_id"`
	EntityName      string                  `json:"entity_name"`
	EntityType      EolExtractRowEntityType `json:"entity_type"`
	EolDate         *string                 `json:"eol_date,omitempty"`
	Latest          *string                 `json:"latest,omitempty"`
	LatestAvailable *string                 `json:"latest_available,omitempty"`
	Product         string                  `json:"product"`
	Status          EolExtractRowStatus     `json:"status"`
	Support         *string                 `json:"support,omitempty"`
}

EolExtractRow defines model for EolExtractRow.

type EolExtractRowEntityType added in v0.22.0

type EolExtractRowEntityType string

EolExtractRowEntityType defines model for EolExtractRow.EntityType.

const (
	EolExtractRowEntityTypeCluster  EolExtractRowEntityType = "cluster"
	EolExtractRowEntityTypeNode     EolExtractRowEntityType = "node"
	EolExtractRowEntityTypeVm       EolExtractRowEntityType = "vm"
	EolExtractRowEntityTypeWorkload EolExtractRowEntityType = "workload"
)

Defines values for EolExtractRowEntityType.

func (EolExtractRowEntityType) Valid added in v0.22.0

func (e EolExtractRowEntityType) Valid() bool

Valid indicates whether the value is a known member of the EolExtractRowEntityType enum.

type EolExtractRowStatus added in v0.22.0

type EolExtractRowStatus string

EolExtractRowStatus defines model for EolExtractRow.Status.

const (
	EolExtractRowStatusApproachingEol EolExtractRowStatus = "approaching_eol"
	EolExtractRowStatusEol            EolExtractRowStatus = "eol"
	EolExtractRowStatusSupported      EolExtractRowStatus = "supported"
	EolExtractRowStatusUnknown        EolExtractRowStatus = "unknown"
)

Defines values for EolExtractRowStatus.

func (EolExtractRowStatus) Valid added in v0.22.0

func (e EolExtractRowStatus) Valid() bool

Valid indicates whether the value is a known member of the EolExtractRowStatus enum.

type ExtractStore added in v0.22.0

type ExtractStore interface {
	ListClusters(ctx context.Context, filter ClusterListFilter, page ListPage) ([]Cluster, string, error)
	ListNodes(ctx context.Context, filter NodeListFilter, page ListPage) ([]Node, string, error)
	ListNamespaces(ctx context.Context, filter NamespaceListFilter, page ListPage) ([]Namespace, string, error)
	ListWorkloads(ctx context.Context, filter WorkloadListFilter, page ListPage) ([]Workload, string, error)
	ListPods(ctx context.Context, filter PodListFilter, page ListPage) ([]Pod, string, error)
	ListVirtualMachines(ctx context.Context, filter VirtualMachineListFilter, page ListPage) ([]VirtualMachine, string, error)
	ListCloudAccounts(ctx context.Context, filter CloudAccountListFilter, page ListPage) ([]CloudAccount, string, error)

	// Container-version enrichment surface (used to attach EOL status to
	// workload images for the EOL extract).
	GetImageOriginResolution(ctx context.Context, mirrorImageRepo, variant string) (ImageOriginResolution, error)
	GetImageVersionsByRepo(ctx context.Context, imageRepo string) ([]ImageVersionRow, error)
}

ExtractStore is the narrow slice of Store the extract handlers consume.

type FlowReference added in v1.2.0

type FlowReference struct {
	ID            uuid.UUID  `json:"id"`
	ClusterID     uuid.UUID  `json:"cluster_id"`
	Layer         string     `json:"layer"`
	Direction     string     `json:"direction"`
	SrcKind       string     `json:"src_kind"`
	SrcRef        string     `json:"src_ref"`
	DstKind       string     `json:"dst_kind"`
	DstRef        string     `json:"dst_ref"`
	Protocol      string     `json:"protocol"`
	FromPort      *int       `json:"from_port,omitempty"`
	ToPort        *int       `json:"to_port,omitempty"`
	Justification string     `json:"justification"`
	CreatedBy     *uuid.UUID `json:"created_by,omitempty"`
	CreatedAt     time.Time  `json:"created_at"`
	UpdatedAt     time.Time  `json:"updated_at"`
}

FlowReference is one operator-declared row of the reference flow matrix for a cluster: an expected perimeter or internal flow the synthesizer matches discovered rules against.

type FlowReferenceInput added in v1.2.0

type FlowReferenceInput struct {
	Layer         string `json:"layer" yaml:"layer"`
	Direction     string `json:"direction" yaml:"direction"`
	SrcKind       string `json:"src_kind" yaml:"src_kind"`
	SrcRef        string `json:"src_ref" yaml:"src_ref"`
	DstKind       string `json:"dst_kind" yaml:"dst_kind"`
	DstRef        string `json:"dst_ref" yaml:"dst_ref"`
	Protocol      string `json:"protocol" yaml:"protocol"`
	FromPort      *int   `json:"from_port,omitempty" yaml:"from_port,omitempty"`
	ToPort        *int   `json:"to_port,omitempty" yaml:"to_port,omitempty"`
	Justification string `json:"justification" yaml:"justification"`
}

FlowReferenceInput is the create/update payload for a FlowReference.

func (FlowReferenceInput) Validate added in v1.2.0

func (in FlowReferenceInput) Validate() error

Validate enforces the layer/endpoint_group invariants and the required justification for a FlowReferenceInput. Errors wrap ErrConflict. The value receiver is intentional (read-only check on inline-constructed inputs).

type FlowStore added in v1.6.2

type FlowStore interface {
	ListEndpointGroups(ctx context.Context) ([]EndpointGroup, error)
	GetEndpointGroup(ctx context.Context, id uuid.UUID) (EndpointGroup, error)
	CreateEndpointGroup(ctx context.Context, in EndpointGroupInput, createdBy *uuid.UUID) (EndpointGroup, error)
	UpdateEndpointGroup(ctx context.Context, id uuid.UUID, in EndpointGroupInput) (EndpointGroup, error)
	DeleteEndpointGroup(ctx context.Context, id uuid.UUID) error

	ListFlowReferences(ctx context.Context, clusterID uuid.UUID) ([]FlowReference, error)
	CreateFlowReference(ctx context.Context, clusterID uuid.UUID, in FlowReferenceInput, createdBy *uuid.UUID) (FlowReference, error)
	UpdateFlowReference(ctx context.Context, id uuid.UUID, in FlowReferenceInput) (FlowReference, error)
	DeleteFlowReference(ctx context.Context, id uuid.UUID) error
	ReplaceFlowReferences(ctx context.Context, clusterID uuid.UUID, ins []FlowReferenceInput, createdBy *uuid.UUID) ([]FlowReference, error)

	// RecordFlowDriftSeen marks (cluster, flowKey) as seen now and returns true
	// when it was NOT seen within `within` (caller should then emit an audit
	// event). Atomic upsert so concurrent reads emit at most once per window.
	RecordFlowDriftSeen(ctx context.Context, clusterID uuid.UUID, flowKey string, within time.Duration) (bool, error)
	// ListClustersWithFlowReferences returns cluster ids having >=1 reference row.
	ListClustersWithFlowReferences(ctx context.Context) ([]uuid.UUID, error)
}

FlowStore covers the flow-matrix curation tables (R2): endpoint groups, per-cluster flow references, and drift-detection bookkeeping.

type Forbidden

type Forbidden = Problem

Forbidden RFC 7807 problem details.

type ForbiddenApplicationProblemPlusJSONResponse

type ForbiddenApplicationProblemPlusJSONResponse Problem

type GetAuthConfig200JSONResponse

type GetAuthConfig200JSONResponse AuthConfig

func (GetAuthConfig200JSONResponse) VisitGetAuthConfigResponse

func (response GetAuthConfig200JSONResponse) VisitGetAuthConfigResponse(w http.ResponseWriter) error

type GetAuthConfigRequestObject

type GetAuthConfigRequestObject struct {
}

type GetAuthConfigResponseObject

type GetAuthConfigResponseObject interface {
	VisitGetAuthConfigResponse(w http.ResponseWriter) error
}

type GetCluster200JSONResponse

type GetCluster200JSONResponse Cluster

func (GetCluster200JSONResponse) VisitGetClusterResponse

func (response GetCluster200JSONResponse) VisitGetClusterResponse(w http.ResponseWriter) error

type GetCluster401ApplicationProblemPlusJSONResponse

type GetCluster401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (GetCluster401ApplicationProblemPlusJSONResponse) VisitGetClusterResponse

func (response GetCluster401ApplicationProblemPlusJSONResponse) VisitGetClusterResponse(w http.ResponseWriter) error

type GetCluster403ApplicationProblemPlusJSONResponse

type GetCluster403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (GetCluster403ApplicationProblemPlusJSONResponse) VisitGetClusterResponse

func (response GetCluster403ApplicationProblemPlusJSONResponse) VisitGetClusterResponse(w http.ResponseWriter) error

type GetCluster404ApplicationProblemPlusJSONResponse

type GetCluster404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (GetCluster404ApplicationProblemPlusJSONResponse) VisitGetClusterResponse

func (response GetCluster404ApplicationProblemPlusJSONResponse) VisitGetClusterResponse(w http.ResponseWriter) error

type GetClusterRequestObject

type GetClusterRequestObject struct {
	Id ClusterId `json:"id"`
}

type GetClusterResponseObject

type GetClusterResponseObject interface {
	VisitGetClusterResponse(w http.ResponseWriter) error
}

type GetHealthz200JSONResponse

type GetHealthz200JSONResponse Health

func (GetHealthz200JSONResponse) VisitGetHealthzResponse

func (response GetHealthz200JSONResponse) VisitGetHealthzResponse(w http.ResponseWriter) error

type GetHealthzRequestObject

type GetHealthzRequestObject struct {
}

type GetHealthzResponseObject

type GetHealthzResponseObject interface {
	VisitGetHealthzResponse(w http.ResponseWriter) error
}

type GetImageOriginMapping200JSONResponse added in v0.30.0

type GetImageOriginMapping200JSONResponse ImageOriginMapping

func (GetImageOriginMapping200JSONResponse) VisitGetImageOriginMappingResponse added in v0.30.0

func (response GetImageOriginMapping200JSONResponse) VisitGetImageOriginMappingResponse(w http.ResponseWriter) error

type GetImageOriginMapping401ApplicationProblemPlusJSONResponse added in v0.30.0

type GetImageOriginMapping401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (GetImageOriginMapping401ApplicationProblemPlusJSONResponse) VisitGetImageOriginMappingResponse added in v0.30.0

func (response GetImageOriginMapping401ApplicationProblemPlusJSONResponse) VisitGetImageOriginMappingResponse(w http.ResponseWriter) error

type GetImageOriginMapping403ApplicationProblemPlusJSONResponse added in v0.30.0

type GetImageOriginMapping403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (GetImageOriginMapping403ApplicationProblemPlusJSONResponse) VisitGetImageOriginMappingResponse added in v0.30.0

func (response GetImageOriginMapping403ApplicationProblemPlusJSONResponse) VisitGetImageOriginMappingResponse(w http.ResponseWriter) error

type GetImageOriginMapping404ApplicationProblemPlusJSONResponse added in v0.30.0

type GetImageOriginMapping404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (GetImageOriginMapping404ApplicationProblemPlusJSONResponse) VisitGetImageOriginMappingResponse added in v0.30.0

func (response GetImageOriginMapping404ApplicationProblemPlusJSONResponse) VisitGetImageOriginMappingResponse(w http.ResponseWriter) error

type GetImageOriginMappingRequestObject added in v0.30.0

type GetImageOriginMappingRequestObject struct {
	ImageName string `json:"image_name"`
}

type GetImageOriginMappingResponseObject added in v0.30.0

type GetImageOriginMappingResponseObject interface {
	VisitGetImageOriginMappingResponse(w http.ResponseWriter) error
}

type GetImageVersion200JSONResponse

type GetImageVersion200JSONResponse ImageVersion

func (GetImageVersion200JSONResponse) VisitGetImageVersionResponse

func (response GetImageVersion200JSONResponse) VisitGetImageVersionResponse(w http.ResponseWriter) error

type GetImageVersion401ApplicationProblemPlusJSONResponse

type GetImageVersion401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (GetImageVersion401ApplicationProblemPlusJSONResponse) VisitGetImageVersionResponse

func (response GetImageVersion401ApplicationProblemPlusJSONResponse) VisitGetImageVersionResponse(w http.ResponseWriter) error

type GetImageVersion403ApplicationProblemPlusJSONResponse

type GetImageVersion403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (GetImageVersion403ApplicationProblemPlusJSONResponse) VisitGetImageVersionResponse

func (response GetImageVersion403ApplicationProblemPlusJSONResponse) VisitGetImageVersionResponse(w http.ResponseWriter) error

type GetImageVersion404ApplicationProblemPlusJSONResponse

type GetImageVersion404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (GetImageVersion404ApplicationProblemPlusJSONResponse) VisitGetImageVersionResponse

func (response GetImageVersion404ApplicationProblemPlusJSONResponse) VisitGetImageVersionResponse(w http.ResponseWriter) error

type GetImageVersionRequestObject

type GetImageVersionRequestObject struct {
	ImageRepo string `json:"image_repo"`
}

type GetImageVersionResponseObject

type GetImageVersionResponseObject interface {
	VisitGetImageVersionResponse(w http.ResponseWriter) error
}

type GetIngress200JSONResponse

type GetIngress200JSONResponse Ingress

func (GetIngress200JSONResponse) VisitGetIngressResponse

func (response GetIngress200JSONResponse) VisitGetIngressResponse(w http.ResponseWriter) error

type GetIngress401ApplicationProblemPlusJSONResponse

type GetIngress401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (GetIngress401ApplicationProblemPlusJSONResponse) VisitGetIngressResponse

func (response GetIngress401ApplicationProblemPlusJSONResponse) VisitGetIngressResponse(w http.ResponseWriter) error

type GetIngress403ApplicationProblemPlusJSONResponse

type GetIngress403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (GetIngress403ApplicationProblemPlusJSONResponse) VisitGetIngressResponse

func (response GetIngress403ApplicationProblemPlusJSONResponse) VisitGetIngressResponse(w http.ResponseWriter) error

type GetIngress404ApplicationProblemPlusJSONResponse

type GetIngress404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (GetIngress404ApplicationProblemPlusJSONResponse) VisitGetIngressResponse

func (response GetIngress404ApplicationProblemPlusJSONResponse) VisitGetIngressResponse(w http.ResponseWriter) error

type GetIngressRequestObject

type GetIngressRequestObject struct {
	Id IngressId `json:"id"`
}

type GetIngressResponseObject

type GetIngressResponseObject interface {
	VisitGetIngressResponse(w http.ResponseWriter) error
}

type GetMe200JSONResponse

type GetMe200JSONResponse Me

func (GetMe200JSONResponse) VisitGetMeResponse

func (response GetMe200JSONResponse) VisitGetMeResponse(w http.ResponseWriter) error

type GetMe401ApplicationProblemPlusJSONResponse

type GetMe401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (GetMe401ApplicationProblemPlusJSONResponse) VisitGetMeResponse

type GetMeRequestObject

type GetMeRequestObject struct {
}

type GetMeResponseObject

type GetMeResponseObject interface {
	VisitGetMeResponse(w http.ResponseWriter) error
}

type GetNamespace200JSONResponse

type GetNamespace200JSONResponse Namespace

func (GetNamespace200JSONResponse) VisitGetNamespaceResponse

func (response GetNamespace200JSONResponse) VisitGetNamespaceResponse(w http.ResponseWriter) error

type GetNamespace401ApplicationProblemPlusJSONResponse

type GetNamespace401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (GetNamespace401ApplicationProblemPlusJSONResponse) VisitGetNamespaceResponse

func (response GetNamespace401ApplicationProblemPlusJSONResponse) VisitGetNamespaceResponse(w http.ResponseWriter) error

type GetNamespace403ApplicationProblemPlusJSONResponse

type GetNamespace403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (GetNamespace403ApplicationProblemPlusJSONResponse) VisitGetNamespaceResponse

func (response GetNamespace403ApplicationProblemPlusJSONResponse) VisitGetNamespaceResponse(w http.ResponseWriter) error

type GetNamespace404ApplicationProblemPlusJSONResponse

type GetNamespace404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (GetNamespace404ApplicationProblemPlusJSONResponse) VisitGetNamespaceResponse

func (response GetNamespace404ApplicationProblemPlusJSONResponse) VisitGetNamespaceResponse(w http.ResponseWriter) error

type GetNamespaceRequestObject

type GetNamespaceRequestObject struct {
	Id NamespaceId `json:"id"`
}

type GetNamespaceResponseObject

type GetNamespaceResponseObject interface {
	VisitGetNamespaceResponse(w http.ResponseWriter) error
}

type GetNode200JSONResponse

type GetNode200JSONResponse Node

func (GetNode200JSONResponse) VisitGetNodeResponse

func (response GetNode200JSONResponse) VisitGetNodeResponse(w http.ResponseWriter) error

type GetNode401ApplicationProblemPlusJSONResponse

type GetNode401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (GetNode401ApplicationProblemPlusJSONResponse) VisitGetNodeResponse

func (response GetNode401ApplicationProblemPlusJSONResponse) VisitGetNodeResponse(w http.ResponseWriter) error

type GetNode403ApplicationProblemPlusJSONResponse

type GetNode403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (GetNode403ApplicationProblemPlusJSONResponse) VisitGetNodeResponse

func (response GetNode403ApplicationProblemPlusJSONResponse) VisitGetNodeResponse(w http.ResponseWriter) error

type GetNode404ApplicationProblemPlusJSONResponse

type GetNode404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (GetNode404ApplicationProblemPlusJSONResponse) VisitGetNodeResponse

func (response GetNode404ApplicationProblemPlusJSONResponse) VisitGetNodeResponse(w http.ResponseWriter) error

type GetNodeRequestObject

type GetNodeRequestObject struct {
	Id NodeId `json:"id"`
}

type GetNodeResponseObject

type GetNodeResponseObject interface {
	VisitGetNodeResponse(w http.ResponseWriter) error
}

type GetPersistentVolume200JSONResponse

type GetPersistentVolume200JSONResponse PersistentVolume

func (GetPersistentVolume200JSONResponse) VisitGetPersistentVolumeResponse

func (response GetPersistentVolume200JSONResponse) VisitGetPersistentVolumeResponse(w http.ResponseWriter) error

type GetPersistentVolume401ApplicationProblemPlusJSONResponse

type GetPersistentVolume401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (GetPersistentVolume401ApplicationProblemPlusJSONResponse) VisitGetPersistentVolumeResponse

func (response GetPersistentVolume401ApplicationProblemPlusJSONResponse) VisitGetPersistentVolumeResponse(w http.ResponseWriter) error

type GetPersistentVolume403ApplicationProblemPlusJSONResponse

type GetPersistentVolume403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (GetPersistentVolume403ApplicationProblemPlusJSONResponse) VisitGetPersistentVolumeResponse

func (response GetPersistentVolume403ApplicationProblemPlusJSONResponse) VisitGetPersistentVolumeResponse(w http.ResponseWriter) error

type GetPersistentVolume404ApplicationProblemPlusJSONResponse

type GetPersistentVolume404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (GetPersistentVolume404ApplicationProblemPlusJSONResponse) VisitGetPersistentVolumeResponse

func (response GetPersistentVolume404ApplicationProblemPlusJSONResponse) VisitGetPersistentVolumeResponse(w http.ResponseWriter) error

type GetPersistentVolumeClaim200JSONResponse

type GetPersistentVolumeClaim200JSONResponse PersistentVolumeClaim

func (GetPersistentVolumeClaim200JSONResponse) VisitGetPersistentVolumeClaimResponse

func (response GetPersistentVolumeClaim200JSONResponse) VisitGetPersistentVolumeClaimResponse(w http.ResponseWriter) error

type GetPersistentVolumeClaim401ApplicationProblemPlusJSONResponse

type GetPersistentVolumeClaim401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (GetPersistentVolumeClaim401ApplicationProblemPlusJSONResponse) VisitGetPersistentVolumeClaimResponse

func (response GetPersistentVolumeClaim401ApplicationProblemPlusJSONResponse) VisitGetPersistentVolumeClaimResponse(w http.ResponseWriter) error

type GetPersistentVolumeClaim403ApplicationProblemPlusJSONResponse

type GetPersistentVolumeClaim403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (GetPersistentVolumeClaim403ApplicationProblemPlusJSONResponse) VisitGetPersistentVolumeClaimResponse

func (response GetPersistentVolumeClaim403ApplicationProblemPlusJSONResponse) VisitGetPersistentVolumeClaimResponse(w http.ResponseWriter) error

type GetPersistentVolumeClaim404ApplicationProblemPlusJSONResponse

type GetPersistentVolumeClaim404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (GetPersistentVolumeClaim404ApplicationProblemPlusJSONResponse) VisitGetPersistentVolumeClaimResponse

func (response GetPersistentVolumeClaim404ApplicationProblemPlusJSONResponse) VisitGetPersistentVolumeClaimResponse(w http.ResponseWriter) error

type GetPersistentVolumeClaimRequestObject

type GetPersistentVolumeClaimRequestObject struct {
	Id PersistentVolumeClaimId `json:"id"`
}

type GetPersistentVolumeClaimResponseObject

type GetPersistentVolumeClaimResponseObject interface {
	VisitGetPersistentVolumeClaimResponse(w http.ResponseWriter) error
}

type GetPersistentVolumeRequestObject

type GetPersistentVolumeRequestObject struct {
	Id PersistentVolumeId `json:"id"`
}

type GetPersistentVolumeResponseObject

type GetPersistentVolumeResponseObject interface {
	VisitGetPersistentVolumeResponse(w http.ResponseWriter) error
}

type GetPod200JSONResponse

type GetPod200JSONResponse Pod

func (GetPod200JSONResponse) VisitGetPodResponse

func (response GetPod200JSONResponse) VisitGetPodResponse(w http.ResponseWriter) error

type GetPod401ApplicationProblemPlusJSONResponse

type GetPod401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (GetPod401ApplicationProblemPlusJSONResponse) VisitGetPodResponse

func (response GetPod401ApplicationProblemPlusJSONResponse) VisitGetPodResponse(w http.ResponseWriter) error

type GetPod403ApplicationProblemPlusJSONResponse

type GetPod403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (GetPod403ApplicationProblemPlusJSONResponse) VisitGetPodResponse

func (response GetPod403ApplicationProblemPlusJSONResponse) VisitGetPodResponse(w http.ResponseWriter) error

type GetPod404ApplicationProblemPlusJSONResponse

type GetPod404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (GetPod404ApplicationProblemPlusJSONResponse) VisitGetPodResponse

func (response GetPod404ApplicationProblemPlusJSONResponse) VisitGetPodResponse(w http.ResponseWriter) error

type GetPodEnrichedResponse

type GetPodEnrichedResponse struct {
	Pod                Pod
	ContainersVersions ContainersVersions
}

GetPodEnrichedResponse wraps the generated GetPod200JSONResponse and appends a containers_versions field to the JSON output without modifying the generated structs. It implements GetPodResponseObject.

func (GetPodEnrichedResponse) VisitGetPodResponse

func (r GetPodEnrichedResponse) VisitGetPodResponse(w http.ResponseWriter) error

VisitGetPodResponse writes the wrapped Pod plus the containers_versions sibling field as JSON to w.

type GetPodRequestObject

type GetPodRequestObject struct {
	Id PodId `json:"id"`
}

type GetPodResponseObject

type GetPodResponseObject interface {
	VisitGetPodResponse(w http.ResponseWriter) error
}

type GetReadyz200JSONResponse

type GetReadyz200JSONResponse Health

func (GetReadyz200JSONResponse) VisitGetReadyzResponse

func (response GetReadyz200JSONResponse) VisitGetReadyzResponse(w http.ResponseWriter) error

type GetReadyz503ApplicationProblemPlusJSONResponse

type GetReadyz503ApplicationProblemPlusJSONResponse Problem

func (GetReadyz503ApplicationProblemPlusJSONResponse) VisitGetReadyzResponse

func (response GetReadyz503ApplicationProblemPlusJSONResponse) VisitGetReadyzResponse(w http.ResponseWriter) error

type GetReadyzRequestObject

type GetReadyzRequestObject struct {
}

type GetReadyzResponseObject

type GetReadyzResponseObject interface {
	VisitGetReadyzResponse(w http.ResponseWriter) error
}

type GetService200JSONResponse

type GetService200JSONResponse Service

func (GetService200JSONResponse) VisitGetServiceResponse

func (response GetService200JSONResponse) VisitGetServiceResponse(w http.ResponseWriter) error

type GetService401ApplicationProblemPlusJSONResponse

type GetService401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (GetService401ApplicationProblemPlusJSONResponse) VisitGetServiceResponse

func (response GetService401ApplicationProblemPlusJSONResponse) VisitGetServiceResponse(w http.ResponseWriter) error

type GetService403ApplicationProblemPlusJSONResponse

type GetService403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (GetService403ApplicationProblemPlusJSONResponse) VisitGetServiceResponse

func (response GetService403ApplicationProblemPlusJSONResponse) VisitGetServiceResponse(w http.ResponseWriter) error

type GetService404ApplicationProblemPlusJSONResponse

type GetService404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (GetService404ApplicationProblemPlusJSONResponse) VisitGetServiceResponse

func (response GetService404ApplicationProblemPlusJSONResponse) VisitGetServiceResponse(w http.ResponseWriter) error

type GetServiceRequestObject

type GetServiceRequestObject struct {
	Id ServiceId `json:"id"`
}

type GetServiceResponseObject

type GetServiceResponseObject interface {
	VisitGetServiceResponse(w http.ResponseWriter) error
}

type GetUser200JSONResponse

type GetUser200JSONResponse User

func (GetUser200JSONResponse) VisitGetUserResponse

func (response GetUser200JSONResponse) VisitGetUserResponse(w http.ResponseWriter) error

type GetUser401ApplicationProblemPlusJSONResponse

type GetUser401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (GetUser401ApplicationProblemPlusJSONResponse) VisitGetUserResponse

func (response GetUser401ApplicationProblemPlusJSONResponse) VisitGetUserResponse(w http.ResponseWriter) error

type GetUser403ApplicationProblemPlusJSONResponse

type GetUser403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (GetUser403ApplicationProblemPlusJSONResponse) VisitGetUserResponse

func (response GetUser403ApplicationProblemPlusJSONResponse) VisitGetUserResponse(w http.ResponseWriter) error

type GetUser404ApplicationProblemPlusJSONResponse

type GetUser404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (GetUser404ApplicationProblemPlusJSONResponse) VisitGetUserResponse

func (response GetUser404ApplicationProblemPlusJSONResponse) VisitGetUserResponse(w http.ResponseWriter) error

type GetUserRequestObject

type GetUserRequestObject struct {
	Id UserId `json:"id"`
}

type GetUserResponseObject

type GetUserResponseObject interface {
	VisitGetUserResponse(w http.ResponseWriter) error
}

type GetWorkload200JSONResponse

type GetWorkload200JSONResponse Workload

func (GetWorkload200JSONResponse) VisitGetWorkloadResponse

func (response GetWorkload200JSONResponse) VisitGetWorkloadResponse(w http.ResponseWriter) error

type GetWorkload401ApplicationProblemPlusJSONResponse

type GetWorkload401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (GetWorkload401ApplicationProblemPlusJSONResponse) VisitGetWorkloadResponse

func (response GetWorkload401ApplicationProblemPlusJSONResponse) VisitGetWorkloadResponse(w http.ResponseWriter) error

type GetWorkload403ApplicationProblemPlusJSONResponse

type GetWorkload403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (GetWorkload403ApplicationProblemPlusJSONResponse) VisitGetWorkloadResponse

func (response GetWorkload403ApplicationProblemPlusJSONResponse) VisitGetWorkloadResponse(w http.ResponseWriter) error

type GetWorkload404ApplicationProblemPlusJSONResponse

type GetWorkload404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (GetWorkload404ApplicationProblemPlusJSONResponse) VisitGetWorkloadResponse

func (response GetWorkload404ApplicationProblemPlusJSONResponse) VisitGetWorkloadResponse(w http.ResponseWriter) error

type GetWorkloadEnrichedResponse

type GetWorkloadEnrichedResponse struct {
	Workload           Workload
	ContainersVersions ContainersVersions
}

GetWorkloadEnrichedResponse wraps the generated GetWorkload200JSONResponse and appends a containers_versions field to the JSON output without modifying the generated structs. It implements GetWorkloadResponseObject.

func (GetWorkloadEnrichedResponse) VisitGetWorkloadResponse

func (r GetWorkloadEnrichedResponse) VisitGetWorkloadResponse(w http.ResponseWriter) error

VisitGetWorkloadResponse writes the wrapped Workload plus the containers_versions sibling field as JSON to w.

type GetWorkloadRequestObject

type GetWorkloadRequestObject struct {
	Id WorkloadId `json:"id"`
}

type GetWorkloadResponseObject

type GetWorkloadResponseObject interface {
	VisitGetWorkloadResponse(w http.ResponseWriter) error
}

type Health

type Health struct {
	Status HealthStatus `json:"status"`

	// Version Build version of the running longue-vue.
	Version *string `json:"version,omitempty"`
}

Health defines model for Health.

type HealthStatus

type HealthStatus string

HealthStatus defines model for Health.Status.

const (
	Ok HealthStatus = "ok"
)

Defines values for HealthStatus.

func (HealthStatus) Valid

func (e HealthStatus) Valid() bool

Valid indicates whether the value is a known member of the HealthStatus enum.

type HistoryRow

type HistoryRow struct {
	HistoryID  string     `json:"history_id"`
	EntityID   string     `json:"entity_id"`
	ValidFrom  time.Time  `json:"valid_from"`
	ValidTo    *time.Time `json:"valid_to,omitempty"`
	ChangeType string     `json:"change_type"`
	ActorID    *string    `json:"actor_id,omitempty"`
	ActorKind  *string    `json:"actor_kind,omitempty"`
	// Diff is the JSON-Patch-shaped array of watched-field changes.
	// Populated for "update" rows; empty slice for other change types.
	Diff any `json:"diff"`
}

HistoryRow is a single entry from a <kind>_history table, returned by ListEntityHistory and surfaced through the GET /v1/{kind}/{id}/history endpoint. Diff is a JSON-Patch-shaped slice describing watched-field changes relative to the immediately prior row; empty for create/restore/soft_delete rows where there is no meaningful prior row.

type HistoryStore added in v1.6.2

type HistoryStore interface {
	// ListEntityHistory returns up to limit history rows for one entity,
	// newest-first. kind must be one of "clusters", "namespaces", "nodes",
	// "workloads". cursor is the opaque pagination token from a prior call
	// (empty = first page). nextCursor is empty when there are no further pages.
	ListEntityHistory(
		ctx context.Context,
		kind string,
		entityID uuid.UUID,
		limit int,
		cursor string,
	) (rows []HistoryRow, nextCursor string, err error)

	// GetEntityAsOf returns the entity's history row that was valid at time t
	// for the given kind and entityID. Returns ErrNotFound when no row covers t.
	GetEntityAsOf(ctx context.Context, kind string, entityID uuid.UUID, t time.Time) (map[string]any, error)

	// IsTimeTravelEnabled reports whether the time_travel_enabled setting is
	// currently true. Used by history handlers to return 503 when disabled.
	IsTimeTravelEnabled(ctx context.Context) (bool, error)
}

HistoryStore covers time-travel history reads (ADR-0021 Phase 3).

type ImageOriginMapping added in v0.30.0

type ImageOriginMapping struct {
	CreatedAt time.Time `json:"created_at"`
	CreatedBy *string   `json:"created_by,omitempty"`

	// ImageName Bare repository path that appears under the mirror's path_prefix (e.g. grafana/alloy)
	ImageName string  `json:"image_name"`
	Notes     *string `json:"notes,omitempty"`

	// PublicRegistry Hostname-only public registry (e.g. docker.io, ghcr.io, quay.io)
	PublicRegistry string    `json:"public_registry"`
	UpdatedAt      time.Time `json:"updated_at"`
	UpdatedBy      *string   `json:"updated_by,omitempty"`
}

ImageOriginMapping defines model for ImageOriginMapping.

type ImageOriginMappingCreate added in v0.30.0

type ImageOriginMappingCreate struct {
	ImageName      string  `json:"image_name"`
	Notes          *string `json:"notes,omitempty"`
	PublicRegistry string  `json:"public_registry"`
}

ImageOriginMappingCreate defines model for ImageOriginMappingCreate.

type ImageOriginMappingList added in v0.30.0

type ImageOriginMappingList struct {
	Items      []ImageOriginMapping `json:"items"`
	NextCursor *string              `json:"next_cursor,omitempty"`
}

ImageOriginMappingList defines model for ImageOriginMappingList.

type ImageOriginMappingPatch added in v0.30.0

type ImageOriginMappingPatch struct {
	// Notes Empty string clears the column
	Notes          *string `json:"notes,omitempty"`
	PublicRegistry *string `json:"public_registry,omitempty"`
}

ImageOriginMappingPatch defines model for ImageOriginMappingPatch.

type ImageOriginResolution added in v0.27.0

type ImageOriginResolution struct {
	MirrorImageRepo string     `json:"mirror_image_repo"`
	Variant         string     `json:"variant"`
	OriginImageRepo *string    `json:"origin_image_repo,omitempty"`
	ViaHostname     *string    `json:"via_hostname,omitempty"`
	ResolvedAt      time.Time  `json:"resolved_at"`
	LastError       *string    `json:"last_error,omitempty"`
	LastErrorAt     *time.Time `json:"last_error_at,omitempty"`
}

ImageOriginResolution is the persisted outcome of one mirror-origin resolution attempt, keyed by the pod-ref's (image_repo, variant) — NOT the resolved origin repo. Success rows have origin_image_repo and via_hostname populated; failure rows have last_error populated and origin_image_repo NULL.

type ImageOriginResolutionUpsert added in v0.27.0

type ImageOriginResolutionUpsert struct {
	MirrorImageRepo string
	Variant         string
	OriginImageRepo *string
	ViaHostname     *string
	ResolvedAt      time.Time
	LastError       *string
	LastErrorAt     *time.Time
}

ImageOriginResolutionUpsert is the input shape for UpsertImageOriginResolution.

type ImageRegistry

type ImageRegistry struct {
	// AuthConfigured True iff an encrypted auth token is stored (token itself is never returned)
	AuthConfigured bool      `json:"auth_configured"`
	AuthUsername   *string   `json:"auth_username,omitempty"`
	CreatedAt      time.Time `json:"created_at"`
	Enabled        bool      `json:"enabled"`

	// Hostname Exact hostname or '*<suffix>' wildcard
	Hostname string `json:"hostname"`

	// IsMirror True if this row is a Harbor-style mirror needing resolution
	IsMirror bool    `json:"is_mirror"`
	Notes    *string `json:"notes,omitempty"`

	// PathPrefix Repo-path prefix (empty for non-mirror rows)
	PathPrefix      string  `json:"path_prefix"`
	RateLimitPerSec float32 `json:"rate_limit_per_sec"`

	// ReplicatesFromHostname When set, this is a replica mirror; the resolver swaps hostname to this value before fetching annotations from the upstream annotation mirror.
	ReplicatesFromHostname *string   `json:"replicates_from_hostname,omitempty"`
	UpdatedAt              time.Time `json:"updated_at"`
}

ImageRegistry defines model for ImageRegistry.

type ImageRegistryCredentials added in v0.24.0

type ImageRegistryCredentials struct {
	AuthToken    string `json:"auth_token"`
	AuthUsername string `json:"auth_username"`
}

ImageRegistryCredentials defines model for ImageRegistryCredentials.

type ImageRegistryPatch

type ImageRegistryPatch struct {
	// AuthToken Empty string clears the stored token; omit to leave unchanged
	AuthToken       *string  `json:"auth_token,omitempty"`
	AuthUsername    *string  `json:"auth_username,omitempty"`
	Enabled         *bool    `json:"enabled,omitempty"`
	IsMirror        *bool    `json:"is_mirror,omitempty"`
	Notes           *string  `json:"notes,omitempty"`
	RateLimitPerSec *float32 `json:"rate_limit_per_sec,omitempty"`

	// ReplicatesFromHostname Empty string clears the replica pointer; omit to leave unchanged.
	ReplicatesFromHostname *string `json:"replicates_from_hostname,omitempty"`
}

ImageRegistryPatch defines model for ImageRegistryPatch.

type ImageRegistryUpsert

type ImageRegistryUpsert struct {
	// AuthToken Robot-account token; never echoed in responses
	AuthToken       *string `json:"auth_token,omitempty"`
	AuthUsername    *string `json:"auth_username,omitempty"`
	Enabled         *bool   `json:"enabled,omitempty"`
	Hostname        string  `json:"hostname"`
	IsMirror        bool    `json:"is_mirror"`
	Notes           *string `json:"notes,omitempty"`
	PathPrefix      string  `json:"path_prefix"`
	RateLimitPerSec float32 `json:"rate_limit_per_sec"`

	// ReplicatesFromHostname Optional. Must reference an existing non-replica mirror row. Requires is_mirror=true.
	ReplicatesFromHostname *string `json:"replicates_from_hostname,omitempty"`
}

ImageRegistryUpsert defines model for ImageRegistryUpsert.

type ImageStore added in v1.6.2

type ImageStore interface {
	// Image registries
	ListImageRegistries(ctx context.Context) ([]ImageRegistry, error)
	GetImageRegistry(ctx context.Context, hostname, pathPrefix string) (ImageRegistry, error)
	CreateImageRegistry(ctx context.Context, in ImageRegistryUpsert) (ImageRegistry, error)
	UpdateImageRegistry(ctx context.Context, hostname, pathPrefix string, p ImageRegistryPatch) (ImageRegistry, error)
	DeleteImageRegistry(ctx context.Context, hostname, pathPrefix string) error
	FindMirrorForRef(ctx context.Context, hostname, imagePath string) (ImageRegistry, error)
	GetMirrorAuthToken(ctx context.Context, hostname, pathPrefix string) (string, error)

	// Image versions
	UpsertImageVersion(ctx context.Context, in ImageVersionUpsert) (ImageVersionRow, error)
	GetImageVersionsByRepo(ctx context.Context, imageRepo string) ([]ImageVersionRow, error)
	ListImageVersionsByRepo(ctx context.Context, p ImageVersionListParams) (items []ImageVersionRepoView, nextCursor string, err error)
	DeleteImageVersionsNotIn(ctx context.Context, keep [][2]string) (int64, error)
	DistinctImageRefs(ctx context.Context) ([]string, error)

	// Image origin resolutions (ADR-0026 extension)
	UpsertImageOriginResolution(ctx context.Context, in ImageOriginResolutionUpsert) (ImageOriginResolution, error)
	GetImageOriginResolution(ctx context.Context, mirrorImageRepo, variant string) (ImageOriginResolution, error)
	DeleteImageOriginResolutionsNotIn(ctx context.Context, keep [][2]string) (int64, error)

	// Image origin mappings (ADR-0030).
	ListImageOriginMappings(ctx context.Context, p StoreListImageOriginMappingsParams) (items []ImageOriginMapping, nextCursor string, err error)
	GetImageOriginMapping(ctx context.Context, imageName string) (ImageOriginMapping, error)
	CreateImageOriginMapping(ctx context.Context, in ImageOriginMappingCreate, createdBy string) (ImageOriginMapping, error)
	PatchImageOriginMapping(ctx context.Context, imageName string, p ImageOriginMappingPatch, updatedBy string) (ImageOriginMapping, error)
	DeleteImageOriginMapping(ctx context.Context, imageName string) error
	FindImageOrigin(ctx context.Context, imageName string) (publicRegistry string, err error)
}

ImageStore covers the image-versions subsystem: registries allowlist (ADR-0022), discovered versions, mirror-origin resolutions (ADR-0026), and manual origin mappings (ADR-0030).

type ImageVersion

type ImageVersion struct {
	ImageRepo string                `json:"image_repo"`
	Registry  string                `json:"registry"`
	Variants  []ImageVersionVariant `json:"variants"`
}

ImageVersion defines model for ImageVersion.

type ImageVersionList

type ImageVersionList struct {
	Items      []ImageVersion `json:"items"`
	NextCursor *string        `json:"next_cursor,omitempty"`
}

ImageVersionList defines model for ImageVersionList.

type ImageVersionListParams

type ImageVersionListParams struct {
	Limit         int
	Cursor        string
	Registry      string
	ImageRepoLike string // substring match, case-insensitive
	// Variant filters repos that have at least one row with this variant;
	// all variants for matching repos are still returned in the RepoView.
	// To filter at the row level instead, drill down via GetImageVersionsByRepo.
	Variant           string
	HasError          *bool
	LastCheckedBefore *time.Time
}

ImageVersionListParams collects the optional filters and pagination parameters for ListImageVersionsByRepo.

type ImageVersionRefreshResponse

type ImageVersionRefreshResponse struct {
	AlreadyRunning bool `json:"already_running"`
	Queued         bool `json:"queued"`
}

ImageVersionRefreshResponse defines model for ImageVersionRefreshResponse.

type ImageVersionRepoView

type ImageVersionRepoView struct {
	ImageRepo string            `json:"image_repo"`
	Registry  string            `json:"registry"`
	Variants  []ImageVersionRow `json:"variants"`
}

ImageVersionRepoView groups all variants of a single image_repo together, as returned by ListImageVersionsByRepo.

type ImageVersionRow

type ImageVersionRow struct {
	ImageRepo     string          `json:"image_repo"`
	Variant       string          `json:"variant"`
	Registry      string          `json:"registry"`
	LatestTag     *string         `json:"latest_tag,omitempty"`
	Annotation    json.RawMessage `json:"annotation"`
	Source        string          `json:"source"`
	LastCheckedAt time.Time       `json:"last_checked_at"`
	LastError     *string         `json:"last_error,omitempty"`
	LastErrorAt   *time.Time      `json:"last_error_at,omitempty"`
	CreatedAt     time.Time       `json:"created_at"`
}

ImageVersionRow is a row from image_versions — one (image_repo, variant) pair with its latest discovered tag and enrichment metadata. This is the flat DB-row representation; the grouped API response shape is ImageVersion (generated by oapi-codegen from the OpenAPI spec).

type ImageVersionUpsert

type ImageVersionUpsert struct {
	ImageRepo     string
	Variant       string
	Registry      string
	LatestTag     *string
	Annotation    json.RawMessage
	Source        string
	LastCheckedAt time.Time
	LastError     *string
	LastErrorAt   *time.Time
}

ImageVersionUpsert carries the fields for inserting or updating an image_versions row. (image_repo, variant) is the primary key.

type ImageVersionVariant

type ImageVersionVariant struct {
	Annotation    *map[string]interface{}   `json:"annotation,omitempty"`
	LastCheckedAt time.Time                 `json:"last_checked_at"`
	LastError     *string                   `json:"last_error,omitempty"`
	LastErrorAt   *time.Time                `json:"last_error_at,omitempty"`
	LatestTag     *string                   `json:"latest_tag,omitempty"`
	Source        ImageVersionVariantSource `json:"source"`

	// Variant Empty string for pure semver
	Variant string `json:"variant"`
}

ImageVersionVariant defines model for ImageVersionVariant.

type ImageVersionVariantSource

type ImageVersionVariantSource string

ImageVersionVariantSource defines model for ImageVersionVariant.Source.

const (
	Registry ImageVersionVariantSource = "registry"
)

Defines values for ImageVersionVariantSource.

func (ImageVersionVariantSource) Valid

func (e ImageVersionVariantSource) Valid() bool

Valid indicates whether the value is a known member of the ImageVersionVariantSource enum.

type IncludeTerminated

type IncludeTerminated = bool

IncludeTerminated defines model for IncludeTerminated.

type IngestMuxConfig

type IngestMuxConfig struct {
	// Server is the StrictServerInterface implementation (typically
	// *Server from internal/api).
	Server ServerInterface

	// AuthMiddleware resolves cookie → bearer → 401 and attaches the
	// Caller to the request context. Same instance used on the public
	// listener, applied here too so forwarded writes go through the
	// same scope checks. The verify endpoint itself is public — its
	// auth is the listener-level mTLS handshake.
	AuthMiddleware MiddlewareFunc

	// AuditMiddleware records non-GET requests with source="ingest_gw"
	// (ADR-0016 §11). Configured by the caller (typically
	// AuditMiddleware(pg, "ingest_gw", trustedProxies)).
	AuditMiddleware MiddlewareFunc

	// Cookie policy is unused on this listener (no cookies traverse the
	// DMZ) but kept here so the wiring matches the public listener's
	// AuthMiddleware shape and tests can swap implementations.
	CookiePolicy auth.SecureCookiePolicy
}

IngestMuxConfig wires the strict-server backend, the auth + audit middleware, and an optional 404 handler for the ingest listener. The auth middleware MUST be the same auth.Middleware longue-vue's public listener uses — longue-vue re-validates every forwarded token with the standard argon2id check; the gateway is never an auth authority.

type Ingress

type Ingress struct {
	// ClusterId Denormalized `namespaces.cluster_id`. Null on orphans. See ADR-0027.
	ClusterId *openapi_types.UUID `json:"cluster_id,omitempty"`

	// ClusterName Denormalized `clusters.name`. Null on orphans. See ADR-0027.
	ClusterName *string             `json:"cluster_name,omitempty"`
	CreatedAt   *time.Time          `json:"created_at,omitempty"`
	Id          *openapi_types.UUID `json:"id,omitempty"`

	// IngressClassName IngressClass name the controller binds to (e.g., "nginx", "traefik").
	IngressClassName *string `json:"ingress_class_name,omitempty"`

	// Labels Arbitrary user-supplied string key/value labels.
	Labels *map[string]string `json:"labels,omitempty"`

	// Layer Always `applicative` for Ingress. See ADR-0004.
	Layer *Layer `json:"layer,omitempty"`

	// LoadBalancer External load-balancer addresses, mirroring
	// `status.loadBalancer.ingress[]`. Each entry is
	// `{ip?, hostname?, ports?}`. Populated by whatever fulfilled
	// the Ingress — a cloud controller on managed clusters, or
	// MetalLB / Kube-VIP / a hardware load balancer on-prem. A
	// single entry is typical; multi-entry setups appear with
	// dual-stack (v4+v6) or redundant VIPs.
	LoadBalancer *[]map[string]interface{} `json:"load_balancer,omitempty"`
	Name         string                    `json:"name"`
	NamespaceId  openapi_types.UUID        `json:"namespace_id"`

	// NamespaceName Denormalized `namespaces.name`. Null on orphans. See ADR-0027.
	NamespaceName *string `json:"namespace_name,omitempty"`

	// Rules Ingress routing rules. Opaque in v1: each entry carries whatever the
	// collector chose to persist (host, path, path_type, backend service
	// name / port).
	Rules *[]map[string]interface{} `json:"rules,omitempty"`

	// Tls TLS configuration entries. Opaque in v1: each entry carries hosts
	// and the referenced Secret name.
	Tls       *[]map[string]interface{} `json:"tls,omitempty"`
	UpdatedAt *time.Time                `json:"updated_at,omitempty"`
}

Ingress defines model for Ingress.

type IngressCreate

type IngressCreate struct {
	// IngressClassName IngressClass name the controller binds to (e.g., "nginx", "traefik").
	IngressClassName *string `json:"ingress_class_name,omitempty"`

	// Labels Arbitrary user-supplied string key/value labels.
	Labels *map[string]string `json:"labels,omitempty"`

	// LoadBalancer External load-balancer addresses, mirroring
	// `status.loadBalancer.ingress[]`. Each entry is
	// `{ip?, hostname?, ports?}`. Populated by whatever fulfilled
	// the Ingress — a cloud controller on managed clusters, or
	// MetalLB / Kube-VIP / a hardware load balancer on-prem. A
	// single entry is typical; multi-entry setups appear with
	// dual-stack (v4+v6) or redundant VIPs.
	LoadBalancer *[]map[string]interface{} `json:"load_balancer,omitempty"`

	// Name Kubernetes ingress name (DNS-label style). Unique per namespace.
	// Immutable after creation.
	Name string `json:"name"`

	// NamespaceId Parent namespace id. Immutable after creation; the namespace
	// must already exist or the create returns 404.
	NamespaceId openapi_types.UUID `json:"namespace_id"`

	// Rules Ingress routing rules. Opaque in v1: each entry carries whatever the
	// collector chose to persist (host, path, path_type, backend service
	// name / port).
	Rules *[]map[string]interface{} `json:"rules,omitempty"`

	// Tls TLS configuration entries. Opaque in v1: each entry carries hosts
	// and the referenced Secret name.
	Tls *[]map[string]interface{} `json:"tls,omitempty"`
}

IngressCreate defines model for IngressCreate.

type IngressId

type IngressId = openapi_types.UUID

IngressId defines model for IngressId.

type IngressList

type IngressList struct {
	Items []Ingress `json:"items"`

	// NextCursor Opaque cursor to pass as `?cursor=` to fetch the next page.
	// Absent or null when no more pages remain.
	NextCursor *string `json:"next_cursor,omitempty"`
}

IngressList Paged list of ingresses.

type IngressListFilter added in v1.10.0

type IngressListFilter struct {
	NamespaceID *uuid.UUID
	Name        *string
}

IngressListFilter is the predicate set accepted by ListIngresses.

type IngressMutable

type IngressMutable struct {
	// IngressClassName IngressClass name the controller binds to (e.g., "nginx", "traefik").
	IngressClassName *string `json:"ingress_class_name,omitempty"`

	// Labels Arbitrary user-supplied string key/value labels.
	Labels *map[string]string `json:"labels,omitempty"`

	// LoadBalancer External load-balancer addresses, mirroring
	// `status.loadBalancer.ingress[]`. Each entry is
	// `{ip?, hostname?, ports?}`. Populated by whatever fulfilled
	// the Ingress — a cloud controller on managed clusters, or
	// MetalLB / Kube-VIP / a hardware load balancer on-prem. A
	// single entry is typical; multi-entry setups appear with
	// dual-stack (v4+v6) or redundant VIPs.
	LoadBalancer *[]map[string]interface{} `json:"load_balancer,omitempty"`

	// Rules Ingress routing rules. Opaque in v1: each entry carries whatever the
	// collector chose to persist (host, path, path_type, backend service
	// name / port).
	Rules *[]map[string]interface{} `json:"rules,omitempty"`

	// Tls TLS configuration entries. Opaque in v1: each entry carries hosts
	// and the referenced Secret name.
	Tls *[]map[string]interface{} `json:"tls,omitempty"`
}

IngressMutable Fields on an Ingress that clients may set and later update.

type IngressNamespaceIdFilter

type IngressNamespaceIdFilter = openapi_types.UUID

IngressNamespaceIdFilter defines model for IngressNamespaceIdFilter.

type IngressStore added in v1.6.2

type IngressStore interface {
	// CreateIngress inserts a new ingress.
	CreateIngress(ctx context.Context, in IngressCreate) (Ingress, error)

	// GetIngress fetches an ingress by id.
	GetIngress(ctx context.Context, id uuid.UUID) (Ingress, error)

	// ListIngresses returns a cursor-paginated page of ingresses, optionally
	// filtered by namespace and/or name. See IngressListFilter for the
	// accepted predicates.
	ListIngresses(ctx context.Context, filter IngressListFilter, page ListPage) (items []Ingress, nextCursor string, err error)

	// UpdateIngress applies merge-patch.
	UpdateIngress(ctx context.Context, id uuid.UUID, in IngressUpdate) (Ingress, error)

	// DeleteIngress removes by id.
	DeleteIngress(ctx context.Context, id uuid.UUID) error

	// UpsertIngress mirrors UpsertService; keyed on (namespace_id, name). The second
	// return value classifies the operation for audit filtering (ADR-0024):
	// OutcomeInserted for a fresh insert, OutcomeBusinessChanged when a
	// business field changed, OutcomeNoChange when only clock fields moved.
	UpsertIngress(ctx context.Context, in IngressCreate) (Ingress, UpsertOutcome, error)

	// DeleteIngressesNotIn mirrors DeleteServicesNotIn.
	DeleteIngressesNotIn(ctx context.Context, namespaceID uuid.UUID, keepNames []string) (int64, error)
}

IngressStore covers ingress CRUD, upsert, and reconcile.

type IngressUpdate

type IngressUpdate = IngressMutable

IngressUpdate Fields on an Ingress that clients may set and later update.

type InvalidParamFormatError

type InvalidParamFormatError struct {
	ParamName string
	Err       error
}

func (*InvalidParamFormatError) Error

func (e *InvalidParamFormatError) Error() string

func (*InvalidParamFormatError) Unwrap

func (e *InvalidParamFormatError) Unwrap() error

type KyvernoStore added in v1.13.0

type KyvernoStore interface {

	// GetClusterPolicy fetches a cluster policy by stable UUID.
	// Returns ErrNotFound when the row is absent.
	GetClusterPolicy(ctx context.Context, id uuid.UUID) (ClusterPolicyRow, error)

	// ListClusterPolicies returns a paged list of cluster policies matching
	// filter, sorted per page.Sort/page.Order. Satisfies ADR-0042.
	ListClusterPolicies(
		ctx context.Context,
		filter ClusterPolicyListFilter,
		page ListPage,
	) ([]ClusterPolicyRow, string, error)

	// UpsertClusterPolicy upserts by (cluster_id, namespace_id, name).
	// Returns the stable row UUID. The canonical write path (ADR-0043).
	UpsertClusterPolicy(ctx context.Context, cp ClusterPolicyRow) (uuid.UUID, error)

	// DeleteClusterScopedPoliciesNotIn removes every cluster-scoped policy
	// (namespace_id IS NULL) for the given cluster whose ID is NOT in
	// keepIDs. Returns the count of deleted rows.
	DeleteClusterScopedPoliciesNotIn(ctx context.Context, clusterID uuid.UUID, keepIDs []uuid.UUID) (int64, error)

	// DeleteClusterPoliciesByNamespace removes every namespaced policy in
	// the given cluster+namespace whose ID is NOT in keepIDs. Only collector-originated
	// rows are affected. Unknown-namespace policies survive because they are
	// never swept. Returns the count of deleted rows.
	DeleteClusterPoliciesByNamespace(ctx context.Context, clusterID uuid.UUID, namespaceID uuid.UUID, keepIDs []uuid.UUID) (int64, error)

	// DeleteClusterPolicy removes a single API-managed cluster policy by UUID.
	// Returns ErrNotFound if the row does not exist or has source='collector'.
	DeleteClusterPolicy(ctx context.Context, id uuid.UUID) error

	// GetPolicyReport fetches a policy report by stable UUID.
	// Returns ErrNotFound when the row is absent.
	GetPolicyReport(ctx context.Context, id uuid.UUID) (PolicyReportRow, error)

	// ListPolicyReports returns a paged list of policy reports matching
	// filter, sorted per page.Sort/page.Order. Satisfies ADR-0042.
	ListPolicyReports(
		ctx context.Context,
		filter PolicyReportListFilter,
		page ListPage,
	) ([]PolicyReportRow, string, error)

	// UpsertPolicyReport upserts by (cluster_id, namespace_id, name).
	// Returns the stable row UUID. The canonical write path (ADR-0043).
	UpsertPolicyReport(ctx context.Context, pr PolicyReportRow) (uuid.UUID, error)

	// DeleteClusterScopedPolicyReportsNotIn removes every cluster-scoped report
	// (namespace_id IS NULL) for the given cluster whose ID is NOT in keepIDs.
	// Returns the count of deleted rows.
	DeleteClusterScopedPolicyReportsNotIn(ctx context.Context, clusterID uuid.UUID, keepIDs []uuid.UUID) (int64, error)

	// DeletePolicyReportsByNamespace removes every namespaced report in
	// the given cluster+namespace whose ID is NOT in keepIDs. Only collector-originated
	// rows are affected. Returns the count of deleted rows.
	DeletePolicyReportsByNamespace(ctx context.Context, clusterID uuid.UUID, namespaceID uuid.UUID, keepIDs []uuid.UUID) (int64, error)

	// DeletePolicyReport removes a single API-managed policy report by UUID.
	// Returns ErrNotFound if the row does not exist or has source='collector'.
	DeletePolicyReport(ctx context.Context, id uuid.UUID) error
}

KyvernoStore covers Kyverno ClusterPolicy and PolicyReport rows (ADR-0043).

type Layer

type Layer string

Layer ANSSI cartography layer the asset belongs to. See ADR-0002 for the kind-to-layer mapping and the rationale behind the six-layer model.

const (
	Administration         Layer = "administration"
	Applicative            Layer = "applicative"
	Business               Layer = "business"
	Ecosystem              Layer = "ecosystem"
	InfrastructureLogical  Layer = "infrastructure_logical"
	InfrastructurePhysical Layer = "infrastructure_physical"
)

Defines values for Layer.

func (Layer) Valid

func (e Layer) Valid() bool

Valid indicates whether the value is a known member of the Layer enum.

type Limit

type Limit = int

Limit defines model for Limit.

type ListApiTokens200JSONResponse

type ListApiTokens200JSONResponse ApiTokenList

func (ListApiTokens200JSONResponse) VisitListApiTokensResponse

func (response ListApiTokens200JSONResponse) VisitListApiTokensResponse(w http.ResponseWriter) error

type ListApiTokens400ApplicationProblemPlusJSONResponse added in v1.10.0

type ListApiTokens400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (ListApiTokens400ApplicationProblemPlusJSONResponse) VisitListApiTokensResponse added in v1.10.0

func (response ListApiTokens400ApplicationProblemPlusJSONResponse) VisitListApiTokensResponse(w http.ResponseWriter) error

type ListApiTokens401ApplicationProblemPlusJSONResponse

type ListApiTokens401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (ListApiTokens401ApplicationProblemPlusJSONResponse) VisitListApiTokensResponse

func (response ListApiTokens401ApplicationProblemPlusJSONResponse) VisitListApiTokensResponse(w http.ResponseWriter) error

type ListApiTokens403ApplicationProblemPlusJSONResponse

type ListApiTokens403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (ListApiTokens403ApplicationProblemPlusJSONResponse) VisitListApiTokensResponse

func (response ListApiTokens403ApplicationProblemPlusJSONResponse) VisitListApiTokensResponse(w http.ResponseWriter) error

type ListApiTokensParams

type ListApiTokensParams struct {
	// Limit Maximum number of items to return. Server clamps to [1, 200].
	Limit *Limit `form:"limit,omitempty" json:"limit,omitempty"`

	// Cursor Opaque cursor returned from a previous list response.
	Cursor *Cursor `form:"cursor,omitempty" json:"cursor,omitempty"`

	// Name Case-insensitive name filter. A plain term matches as a
	// substring (`du` matches anywhere in the name); a term
	// containing `*` matches as an anchored glob pattern (`du*` =
	// starts with, `*du` = ends with, `prod-*-db` = anchored both
	// ends). LIKE metacharacters (`%`, `_`, `\`) are treated
	// literally.
	Name *NameFilter `form:"name,omitempty" json:"name,omitempty"`

	// Sort Column key to sort by. Each list endpoint documents its
	// sortable keys; an unknown key returns 400. Without `sort`,
	// the endpoint's historical default order is preserved.
	Sort *SortKey `form:"sort,omitempty" json:"sort,omitempty"`

	// Order Sort direction. Defaults to `asc` when `sort` is set;
	// ignored when `sort` is absent.
	Order *ListApiTokensParamsOrder `form:"order,omitempty" json:"order,omitempty"`
}

ListApiTokensParams defines parameters for ListApiTokens.

type ListApiTokensParamsOrder added in v1.10.0

type ListApiTokensParamsOrder string

ListApiTokensParamsOrder defines parameters for ListApiTokens.

const (
	ListApiTokensParamsOrderAsc  ListApiTokensParamsOrder = "asc"
	ListApiTokensParamsOrderDesc ListApiTokensParamsOrder = "desc"
)

Defines values for ListApiTokensParamsOrder.

func (ListApiTokensParamsOrder) Valid added in v1.10.0

func (e ListApiTokensParamsOrder) Valid() bool

Valid indicates whether the value is a known member of the ListApiTokensParamsOrder enum.

type ListApiTokensRequestObject

type ListApiTokensRequestObject struct {
	Params ListApiTokensParams
}

type ListApiTokensResponseObject

type ListApiTokensResponseObject interface {
	VisitListApiTokensResponse(w http.ResponseWriter) error
}

type ListAuditEvents200JSONResponse

type ListAuditEvents200JSONResponse AuditEventList

func (ListAuditEvents200JSONResponse) VisitListAuditEventsResponse

func (response ListAuditEvents200JSONResponse) VisitListAuditEventsResponse(w http.ResponseWriter) error

type ListAuditEvents400ApplicationProblemPlusJSONResponse added in v1.10.0

type ListAuditEvents400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (ListAuditEvents400ApplicationProblemPlusJSONResponse) VisitListAuditEventsResponse added in v1.10.0

func (response ListAuditEvents400ApplicationProblemPlusJSONResponse) VisitListAuditEventsResponse(w http.ResponseWriter) error

type ListAuditEvents401ApplicationProblemPlusJSONResponse

type ListAuditEvents401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (ListAuditEvents401ApplicationProblemPlusJSONResponse) VisitListAuditEventsResponse

func (response ListAuditEvents401ApplicationProblemPlusJSONResponse) VisitListAuditEventsResponse(w http.ResponseWriter) error

type ListAuditEvents403ApplicationProblemPlusJSONResponse

type ListAuditEvents403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (ListAuditEvents403ApplicationProblemPlusJSONResponse) VisitListAuditEventsResponse

func (response ListAuditEvents403ApplicationProblemPlusJSONResponse) VisitListAuditEventsResponse(w http.ResponseWriter) error

type ListAuditEventsParams

type ListAuditEventsParams struct {
	// Limit Maximum number of events to return. The audit list clamps
	// to [1, 500] (higher than the standard 200 — dense event
	// streams need bigger pages).
	Limit *int `form:"limit,omitempty" json:"limit,omitempty"`

	// Cursor Opaque cursor returned from a previous list response.
	Cursor *Cursor `form:"cursor,omitempty" json:"cursor,omitempty"`

	// ActorId Filter to events emitted by this user.
	ActorId *openapi_types.UUID `form:"actor_id,omitempty" json:"actor_id,omitempty"`

	// ResourceType Filter to events affecting a specific resource kind (e.g. `cluster`, `user`).
	ResourceType *string `form:"resource_type,omitempty" json:"resource_type,omitempty"`

	// ResourceId Filter to events affecting a specific resource id.
	ResourceId *string `form:"resource_id,omitempty" json:"resource_id,omitempty"`

	// Action Filter to a specific action verb (e.g. `user.create`).
	Action *string `form:"action,omitempty" json:"action,omitempty"`

	// Source Filter to events served by a specific listener. Useful for
	// answering "what came through the DMZ ingest gateway" (ADR-0016)
	// without cross-referencing source IPs.
	Source *ListAuditEventsParamsSource `form:"source,omitempty" json:"source,omitempty"`
	Since  *time.Time                   `form:"since,omitempty" json:"since,omitempty"`
	Until  *time.Time                   `form:"until,omitempty" json:"until,omitempty"`

	// Sort Column key to sort by. Each list endpoint documents its
	// sortable keys; an unknown key returns 400. Without `sort`,
	// the endpoint's historical default order is preserved.
	Sort *SortKey `form:"sort,omitempty" json:"sort,omitempty"`

	// Order Sort direction. Defaults to `asc` when `sort` is set;
	// ignored when `sort` is absent.
	Order *ListAuditEventsParamsOrder `form:"order,omitempty" json:"order,omitempty"`
}

ListAuditEventsParams defines parameters for ListAuditEvents.

type ListAuditEventsParamsOrder added in v1.10.0

type ListAuditEventsParamsOrder string

ListAuditEventsParamsOrder defines parameters for ListAuditEvents.

const (
	ListAuditEventsParamsOrderAsc  ListAuditEventsParamsOrder = "asc"
	ListAuditEventsParamsOrderDesc ListAuditEventsParamsOrder = "desc"
)

Defines values for ListAuditEventsParamsOrder.

func (ListAuditEventsParamsOrder) Valid added in v1.10.0

func (e ListAuditEventsParamsOrder) Valid() bool

Valid indicates whether the value is a known member of the ListAuditEventsParamsOrder enum.

type ListAuditEventsParamsSource

type ListAuditEventsParamsSource string

ListAuditEventsParamsSource defines parameters for ListAuditEvents.

const (
	Api      ListAuditEventsParamsSource = "api"
	IngestGw ListAuditEventsParamsSource = "ingest_gw"
	System   ListAuditEventsParamsSource = "system"
)

Defines values for ListAuditEventsParamsSource.

func (ListAuditEventsParamsSource) Valid

Valid indicates whether the value is a known member of the ListAuditEventsParamsSource enum.

type ListAuditEventsRequestObject

type ListAuditEventsRequestObject struct {
	Params ListAuditEventsParams
}

type ListAuditEventsResponseObject

type ListAuditEventsResponseObject interface {
	VisitListAuditEventsResponse(w http.ResponseWriter) error
}

type ListClusters200JSONResponse

type ListClusters200JSONResponse ClusterList

func (ListClusters200JSONResponse) VisitListClustersResponse

func (response ListClusters200JSONResponse) VisitListClustersResponse(w http.ResponseWriter) error

type ListClusters400ApplicationProblemPlusJSONResponse

type ListClusters400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (ListClusters400ApplicationProblemPlusJSONResponse) VisitListClustersResponse

func (response ListClusters400ApplicationProblemPlusJSONResponse) VisitListClustersResponse(w http.ResponseWriter) error

type ListClusters401ApplicationProblemPlusJSONResponse

type ListClusters401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (ListClusters401ApplicationProblemPlusJSONResponse) VisitListClustersResponse

func (response ListClusters401ApplicationProblemPlusJSONResponse) VisitListClustersResponse(w http.ResponseWriter) error

type ListClusters403ApplicationProblemPlusJSONResponse

type ListClusters403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (ListClusters403ApplicationProblemPlusJSONResponse) VisitListClustersResponse

func (response ListClusters403ApplicationProblemPlusJSONResponse) VisitListClustersResponse(w http.ResponseWriter) error

type ListClustersParams

type ListClustersParams struct {
	// Limit Maximum number of items to return. Server clamps to [1, 200].
	Limit *Limit `form:"limit,omitempty" json:"limit,omitempty"`

	// Cursor Opaque cursor returned from a previous list response.
	Cursor *Cursor `form:"cursor,omitempty" json:"cursor,omitempty"`

	// IncludeTerminated When true, include rows whose `terminated_at` is set (soft-deleted by
	// the collector reconcile pass). Defaults to false: only live entities
	// are returned. ADR-0021 §5 / §6.
	IncludeTerminated *IncludeTerminated `form:"include_terminated,omitempty" json:"include_terminated,omitempty"`

	// Name Case-insensitive name filter. A plain term matches as a
	// substring (`du` matches anywhere in the name); a term
	// containing `*` matches as an anchored glob pattern (`du*` =
	// starts with, `*du` = ends with, `prod-*-db` = anchored both
	// ends). LIKE metacharacters (`%`, `_`, `\`) are treated
	// literally.
	Name *NameFilter `form:"name,omitempty" json:"name,omitempty"`

	// Stale Filter on the derived staleness state. `true` returns only
	// clusters whose collector heartbeat (`last_seen_at`) is older
	// than the `cluster_stale_after_days` admin setting; `false`
	// returns only fresh clusters; omitted applies no staleness
	// filter. When the feature is disabled (threshold 0),
	// `stale=true` matches nothing and `stale=false` matches
	// everything.
	Stale *bool `form:"stale,omitempty" json:"stale,omitempty"`

	// Sort Column key to sort by. Each list endpoint documents its
	// sortable keys; an unknown key returns 400. Without `sort`,
	// the endpoint's historical default order is preserved.
	Sort *SortKey `form:"sort,omitempty" json:"sort,omitempty"`

	// Order Sort direction. Defaults to `asc` when `sort` is set;
	// ignored when `sort` is absent.
	Order *ListClustersParamsOrder `form:"order,omitempty" json:"order,omitempty"`
}

ListClustersParams defines parameters for ListClusters.

type ListClustersParamsOrder added in v1.10.0

type ListClustersParamsOrder string

ListClustersParamsOrder defines parameters for ListClusters.

const (
	ListClustersParamsOrderAsc  ListClustersParamsOrder = "asc"
	ListClustersParamsOrderDesc ListClustersParamsOrder = "desc"
)

Defines values for ListClustersParamsOrder.

func (ListClustersParamsOrder) Valid added in v1.10.0

func (e ListClustersParamsOrder) Valid() bool

Valid indicates whether the value is a known member of the ListClustersParamsOrder enum.

type ListClustersRequestObject

type ListClustersRequestObject struct {
	Params ListClustersParams
}

type ListClustersResponseObject

type ListClustersResponseObject interface {
	VisitListClustersResponse(w http.ResponseWriter) error
}

type ListImageOriginMappings200JSONResponse added in v0.30.0

type ListImageOriginMappings200JSONResponse ImageOriginMappingList

func (ListImageOriginMappings200JSONResponse) VisitListImageOriginMappingsResponse added in v0.30.0

func (response ListImageOriginMappings200JSONResponse) VisitListImageOriginMappingsResponse(w http.ResponseWriter) error

type ListImageOriginMappings401ApplicationProblemPlusJSONResponse added in v0.30.0

type ListImageOriginMappings401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (ListImageOriginMappings401ApplicationProblemPlusJSONResponse) VisitListImageOriginMappingsResponse added in v0.30.0

func (response ListImageOriginMappings401ApplicationProblemPlusJSONResponse) VisitListImageOriginMappingsResponse(w http.ResponseWriter) error

type ListImageOriginMappings403ApplicationProblemPlusJSONResponse added in v0.30.0

type ListImageOriginMappings403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (ListImageOriginMappings403ApplicationProblemPlusJSONResponse) VisitListImageOriginMappingsResponse added in v0.30.0

func (response ListImageOriginMappings403ApplicationProblemPlusJSONResponse) VisitListImageOriginMappingsResponse(w http.ResponseWriter) error

type ListImageOriginMappingsParams added in v0.30.0

type ListImageOriginMappingsParams struct {
	Limit  *int    `form:"limit,omitempty" json:"limit,omitempty"`
	Cursor *string `form:"cursor,omitempty" json:"cursor,omitempty"`

	// PublicRegistry Exact match filter
	PublicRegistry *string `form:"public_registry,omitempty" json:"public_registry,omitempty"`

	// Q Case-insensitive substring on image_name
	Q *string `form:"q,omitempty" json:"q,omitempty"`
}

ListImageOriginMappingsParams defines parameters for ListImageOriginMappings.

type ListImageOriginMappingsRequestObject added in v0.30.0

type ListImageOriginMappingsRequestObject struct {
	Params ListImageOriginMappingsParams
}

type ListImageOriginMappingsResponseObject added in v0.30.0

type ListImageOriginMappingsResponseObject interface {
	VisitListImageOriginMappingsResponse(w http.ResponseWriter) error
}

type ListImageRegistries200JSONResponse

type ListImageRegistries200JSONResponse struct {
	Items []ImageRegistry `json:"items"`
}

func (ListImageRegistries200JSONResponse) VisitListImageRegistriesResponse

func (response ListImageRegistries200JSONResponse) VisitListImageRegistriesResponse(w http.ResponseWriter) error

type ListImageRegistries401ApplicationProblemPlusJSONResponse

type ListImageRegistries401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (ListImageRegistries401ApplicationProblemPlusJSONResponse) VisitListImageRegistriesResponse

func (response ListImageRegistries401ApplicationProblemPlusJSONResponse) VisitListImageRegistriesResponse(w http.ResponseWriter) error

type ListImageRegistries403ApplicationProblemPlusJSONResponse

type ListImageRegistries403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (ListImageRegistries403ApplicationProblemPlusJSONResponse) VisitListImageRegistriesResponse

func (response ListImageRegistries403ApplicationProblemPlusJSONResponse) VisitListImageRegistriesResponse(w http.ResponseWriter) error

type ListImageRegistriesRequestObject

type ListImageRegistriesRequestObject struct {
}

type ListImageRegistriesResponseObject

type ListImageRegistriesResponseObject interface {
	VisitListImageRegistriesResponse(w http.ResponseWriter) error
}

type ListImageVersions200JSONResponse

type ListImageVersions200JSONResponse ImageVersionList

func (ListImageVersions200JSONResponse) VisitListImageVersionsResponse

func (response ListImageVersions200JSONResponse) VisitListImageVersionsResponse(w http.ResponseWriter) error

type ListImageVersions401ApplicationProblemPlusJSONResponse

type ListImageVersions401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (ListImageVersions401ApplicationProblemPlusJSONResponse) VisitListImageVersionsResponse

func (response ListImageVersions401ApplicationProblemPlusJSONResponse) VisitListImageVersionsResponse(w http.ResponseWriter) error

type ListImageVersions403ApplicationProblemPlusJSONResponse

type ListImageVersions403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (ListImageVersions403ApplicationProblemPlusJSONResponse) VisitListImageVersionsResponse

func (response ListImageVersions403ApplicationProblemPlusJSONResponse) VisitListImageVersionsResponse(w http.ResponseWriter) error

type ListImageVersionsParams

type ListImageVersionsParams struct {
	Limit             *int       `form:"limit,omitempty" json:"limit,omitempty"`
	Cursor            *string    `form:"cursor,omitempty" json:"cursor,omitempty"`
	Registry          *string    `form:"registry,omitempty" json:"registry,omitempty"`
	ImageRepo         *string    `form:"image_repo,omitempty" json:"image_repo,omitempty"`
	Variant           *string    `form:"variant,omitempty" json:"variant,omitempty"`
	HasError          *bool      `form:"has_error,omitempty" json:"has_error,omitempty"`
	LastCheckedBefore *time.Time `form:"last_checked_before,omitempty" json:"last_checked_before,omitempty"`
}

ListImageVersionsParams defines parameters for ListImageVersions.

type ListImageVersionsRequestObject

type ListImageVersionsRequestObject struct {
	Params ListImageVersionsParams
}

type ListImageVersionsResponseObject

type ListImageVersionsResponseObject interface {
	VisitListImageVersionsResponse(w http.ResponseWriter) error
}

type ListIngresses200JSONResponse

type ListIngresses200JSONResponse IngressList

func (ListIngresses200JSONResponse) VisitListIngressesResponse

func (response ListIngresses200JSONResponse) VisitListIngressesResponse(w http.ResponseWriter) error

type ListIngresses400ApplicationProblemPlusJSONResponse

type ListIngresses400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (ListIngresses400ApplicationProblemPlusJSONResponse) VisitListIngressesResponse

func (response ListIngresses400ApplicationProblemPlusJSONResponse) VisitListIngressesResponse(w http.ResponseWriter) error

type ListIngresses401ApplicationProblemPlusJSONResponse

type ListIngresses401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (ListIngresses401ApplicationProblemPlusJSONResponse) VisitListIngressesResponse

func (response ListIngresses401ApplicationProblemPlusJSONResponse) VisitListIngressesResponse(w http.ResponseWriter) error

type ListIngresses403ApplicationProblemPlusJSONResponse

type ListIngresses403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (ListIngresses403ApplicationProblemPlusJSONResponse) VisitListIngressesResponse

func (response ListIngresses403ApplicationProblemPlusJSONResponse) VisitListIngressesResponse(w http.ResponseWriter) error

type ListIngressesParams

type ListIngressesParams struct {
	// Limit Maximum number of items to return. Server clamps to [1, 200].
	Limit *Limit `form:"limit,omitempty" json:"limit,omitempty"`

	// Cursor Opaque cursor returned from a previous list response.
	Cursor *Cursor `form:"cursor,omitempty" json:"cursor,omitempty"`

	// NamespaceId Return only ingresses belonging to this namespace.
	NamespaceId *IngressNamespaceIdFilter `form:"namespace_id,omitempty" json:"namespace_id,omitempty"`

	// Name Case-insensitive name filter. A plain term matches as a
	// substring (`du` matches anywhere in the name); a term
	// containing `*` matches as an anchored glob pattern (`du*` =
	// starts with, `*du` = ends with, `prod-*-db` = anchored both
	// ends). LIKE metacharacters (`%`, `_`, `\`) are treated
	// literally.
	Name *NameFilter `form:"name,omitempty" json:"name,omitempty"`

	// Sort Column key to sort by. Each list endpoint documents its
	// sortable keys; an unknown key returns 400. Without `sort`,
	// the endpoint's historical default order is preserved.
	Sort *SortKey `form:"sort,omitempty" json:"sort,omitempty"`

	// Order Sort direction. Defaults to `asc` when `sort` is set;
	// ignored when `sort` is absent.
	Order *ListIngressesParamsOrder `form:"order,omitempty" json:"order,omitempty"`
}

ListIngressesParams defines parameters for ListIngresses.

type ListIngressesParamsOrder added in v1.10.0

type ListIngressesParamsOrder string

ListIngressesParamsOrder defines parameters for ListIngresses.

const (
	ListIngressesParamsOrderAsc  ListIngressesParamsOrder = "asc"
	ListIngressesParamsOrderDesc ListIngressesParamsOrder = "desc"
)

Defines values for ListIngressesParamsOrder.

func (ListIngressesParamsOrder) Valid added in v1.10.0

func (e ListIngressesParamsOrder) Valid() bool

Valid indicates whether the value is a known member of the ListIngressesParamsOrder enum.

type ListIngressesRequestObject

type ListIngressesRequestObject struct {
	Params ListIngressesParams
}

type ListIngressesResponseObject

type ListIngressesResponseObject interface {
	VisitListIngressesResponse(w http.ResponseWriter) error
}

type ListNamespaces200JSONResponse

type ListNamespaces200JSONResponse NamespaceList

func (ListNamespaces200JSONResponse) VisitListNamespacesResponse

func (response ListNamespaces200JSONResponse) VisitListNamespacesResponse(w http.ResponseWriter) error

type ListNamespaces400ApplicationProblemPlusJSONResponse

type ListNamespaces400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (ListNamespaces400ApplicationProblemPlusJSONResponse) VisitListNamespacesResponse

func (response ListNamespaces400ApplicationProblemPlusJSONResponse) VisitListNamespacesResponse(w http.ResponseWriter) error

type ListNamespaces401ApplicationProblemPlusJSONResponse

type ListNamespaces401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (ListNamespaces401ApplicationProblemPlusJSONResponse) VisitListNamespacesResponse

func (response ListNamespaces401ApplicationProblemPlusJSONResponse) VisitListNamespacesResponse(w http.ResponseWriter) error

type ListNamespaces403ApplicationProblemPlusJSONResponse

type ListNamespaces403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (ListNamespaces403ApplicationProblemPlusJSONResponse) VisitListNamespacesResponse

func (response ListNamespaces403ApplicationProblemPlusJSONResponse) VisitListNamespacesResponse(w http.ResponseWriter) error

type ListNamespacesParams

type ListNamespacesParams struct {
	// Limit Maximum number of items to return. Server clamps to [1, 200].
	Limit *Limit `form:"limit,omitempty" json:"limit,omitempty"`

	// Cursor Opaque cursor returned from a previous list response.
	Cursor *Cursor `form:"cursor,omitempty" json:"cursor,omitempty"`

	// IncludeTerminated When true, include rows whose `terminated_at` is set (soft-deleted by
	// the collector reconcile pass). Defaults to false: only live entities
	// are returned. ADR-0021 §5 / §6.
	IncludeTerminated *IncludeTerminated `form:"include_terminated,omitempty" json:"include_terminated,omitempty"`

	// ClusterId Return only namespaces belonging to this cluster.
	ClusterId *NamespaceClusterIdFilter `form:"cluster_id,omitempty" json:"cluster_id,omitempty"`

	// Name Case-insensitive name filter. A plain term matches as a
	// substring (`du` matches anywhere in the name); a term
	// containing `*` matches as an anchored glob pattern (`du*` =
	// starts with, `*du` = ends with, `prod-*-db` = anchored both
	// ends). LIKE metacharacters (`%`, `_`, `\`) are treated
	// literally.
	Name *NameFilter `form:"name,omitempty" json:"name,omitempty"`

	// Sort Column key to sort by. Each list endpoint documents its
	// sortable keys; an unknown key returns 400. Without `sort`,
	// the endpoint's historical default order is preserved.
	Sort *SortKey `form:"sort,omitempty" json:"sort,omitempty"`

	// Order Sort direction. Defaults to `asc` when `sort` is set;
	// ignored when `sort` is absent.
	Order *ListNamespacesParamsOrder `form:"order,omitempty" json:"order,omitempty"`
}

ListNamespacesParams defines parameters for ListNamespaces.

type ListNamespacesParamsOrder added in v1.10.0

type ListNamespacesParamsOrder string

ListNamespacesParamsOrder defines parameters for ListNamespaces.

const (
	ListNamespacesParamsOrderAsc  ListNamespacesParamsOrder = "asc"
	ListNamespacesParamsOrderDesc ListNamespacesParamsOrder = "desc"
)

Defines values for ListNamespacesParamsOrder.

func (ListNamespacesParamsOrder) Valid added in v1.10.0

func (e ListNamespacesParamsOrder) Valid() bool

Valid indicates whether the value is a known member of the ListNamespacesParamsOrder enum.

type ListNamespacesRequestObject

type ListNamespacesRequestObject struct {
	Params ListNamespacesParams
}

type ListNamespacesResponseObject

type ListNamespacesResponseObject interface {
	VisitListNamespacesResponse(w http.ResponseWriter) error
}

type ListNodes200JSONResponse

type ListNodes200JSONResponse NodeList

func (ListNodes200JSONResponse) VisitListNodesResponse

func (response ListNodes200JSONResponse) VisitListNodesResponse(w http.ResponseWriter) error

type ListNodes400ApplicationProblemPlusJSONResponse

type ListNodes400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (ListNodes400ApplicationProblemPlusJSONResponse) VisitListNodesResponse

func (response ListNodes400ApplicationProblemPlusJSONResponse) VisitListNodesResponse(w http.ResponseWriter) error

type ListNodes401ApplicationProblemPlusJSONResponse

type ListNodes401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (ListNodes401ApplicationProblemPlusJSONResponse) VisitListNodesResponse

func (response ListNodes401ApplicationProblemPlusJSONResponse) VisitListNodesResponse(w http.ResponseWriter) error

type ListNodes403ApplicationProblemPlusJSONResponse

type ListNodes403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (ListNodes403ApplicationProblemPlusJSONResponse) VisitListNodesResponse

func (response ListNodes403ApplicationProblemPlusJSONResponse) VisitListNodesResponse(w http.ResponseWriter) error

type ListNodesParams

type ListNodesParams struct {
	// Limit Maximum number of items to return. Server clamps to [1, 200].
	Limit *Limit `form:"limit,omitempty" json:"limit,omitempty"`

	// Cursor Opaque cursor returned from a previous list response.
	Cursor *Cursor `form:"cursor,omitempty" json:"cursor,omitempty"`

	// IncludeTerminated When true, include rows whose `terminated_at` is set (soft-deleted by
	// the collector reconcile pass). Defaults to false: only live entities
	// are returned. ADR-0021 §5 / §6.
	IncludeTerminated *IncludeTerminated `form:"include_terminated,omitempty" json:"include_terminated,omitempty"`

	// ClusterId Return only nodes belonging to this cluster.
	ClusterId *NodeClusterIdFilter `form:"cluster_id,omitempty" json:"cluster_id,omitempty"`

	// Name Case-insensitive name filter. A plain term matches as a
	// substring (`du` matches anywhere in the name); a term
	// containing `*` matches as an anchored glob pattern (`du*` =
	// starts with, `*du` = ends with, `prod-*-db` = anchored both
	// ends). LIKE metacharacters (`%`, `_`, `\`) are treated
	// literally.
	Name *NameFilter `form:"name,omitempty" json:"name,omitempty"`

	// Sort Column key to sort by. Each list endpoint documents its
	// sortable keys; an unknown key returns 400. Without `sort`,
	// the endpoint's historical default order is preserved.
	Sort *SortKey `form:"sort,omitempty" json:"sort,omitempty"`

	// Order Sort direction. Defaults to `asc` when `sort` is set;
	// ignored when `sort` is absent.
	Order *ListNodesParamsOrder `form:"order,omitempty" json:"order,omitempty"`
}

ListNodesParams defines parameters for ListNodes.

type ListNodesParamsOrder added in v1.10.0

type ListNodesParamsOrder string

ListNodesParamsOrder defines parameters for ListNodes.

const (
	ListNodesParamsOrderAsc  ListNodesParamsOrder = "asc"
	ListNodesParamsOrderDesc ListNodesParamsOrder = "desc"
)

Defines values for ListNodesParamsOrder.

func (ListNodesParamsOrder) Valid added in v1.10.0

func (e ListNodesParamsOrder) Valid() bool

Valid indicates whether the value is a known member of the ListNodesParamsOrder enum.

type ListNodesRequestObject

type ListNodesRequestObject struct {
	Params ListNodesParams
}

type ListNodesResponseObject

type ListNodesResponseObject interface {
	VisitListNodesResponse(w http.ResponseWriter) error
}

type ListPage added in v1.10.0

type ListPage struct {
	Limit  int
	Cursor string
	// Sort is the API sort key ("" = entity default order). Keys are
	// validated against a per-entity allowlist in the store layer;
	// unknown keys yield ErrInvalidSort.
	Sort string
	// Order is "asc" or "desc". Empty means: desc for the default
	// sort (preserving historical order), asc when Sort is set.
	Order string
}

ListPage carries the uniform pagination + sort controls shared by every paginated List* method (ADR-0042). The zero value means: first page, default page size, the entity's historical default order.

type ListPersistentVolumeClaims200JSONResponse

type ListPersistentVolumeClaims200JSONResponse PersistentVolumeClaimList

func (ListPersistentVolumeClaims200JSONResponse) VisitListPersistentVolumeClaimsResponse

func (response ListPersistentVolumeClaims200JSONResponse) VisitListPersistentVolumeClaimsResponse(w http.ResponseWriter) error

type ListPersistentVolumeClaims400ApplicationProblemPlusJSONResponse

type ListPersistentVolumeClaims400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (ListPersistentVolumeClaims400ApplicationProblemPlusJSONResponse) VisitListPersistentVolumeClaimsResponse

func (response ListPersistentVolumeClaims400ApplicationProblemPlusJSONResponse) VisitListPersistentVolumeClaimsResponse(w http.ResponseWriter) error

type ListPersistentVolumeClaims401ApplicationProblemPlusJSONResponse

type ListPersistentVolumeClaims401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (ListPersistentVolumeClaims401ApplicationProblemPlusJSONResponse) VisitListPersistentVolumeClaimsResponse

func (response ListPersistentVolumeClaims401ApplicationProblemPlusJSONResponse) VisitListPersistentVolumeClaimsResponse(w http.ResponseWriter) error

type ListPersistentVolumeClaims403ApplicationProblemPlusJSONResponse

type ListPersistentVolumeClaims403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (ListPersistentVolumeClaims403ApplicationProblemPlusJSONResponse) VisitListPersistentVolumeClaimsResponse

func (response ListPersistentVolumeClaims403ApplicationProblemPlusJSONResponse) VisitListPersistentVolumeClaimsResponse(w http.ResponseWriter) error

type ListPersistentVolumeClaimsParams

type ListPersistentVolumeClaimsParams struct {
	// Limit Maximum number of items to return. Server clamps to [1, 200].
	Limit *Limit `form:"limit,omitempty" json:"limit,omitempty"`

	// Cursor Opaque cursor returned from a previous list response.
	Cursor *Cursor `form:"cursor,omitempty" json:"cursor,omitempty"`

	// NamespaceId Return only persistent volume claims belonging to this namespace.
	NamespaceId *PersistentVolumeClaimNamespaceIdFilter `form:"namespace_id,omitempty" json:"namespace_id,omitempty"`

	// Name Case-insensitive name filter. A plain term matches as a
	// substring (`du` matches anywhere in the name); a term
	// containing `*` matches as an anchored glob pattern (`du*` =
	// starts with, `*du` = ends with, `prod-*-db` = anchored both
	// ends). LIKE metacharacters (`%`, `_`, `\`) are treated
	// literally.
	Name *NameFilter `form:"name,omitempty" json:"name,omitempty"`

	// Sort Column key to sort by. Each list endpoint documents its
	// sortable keys; an unknown key returns 400. Without `sort`,
	// the endpoint's historical default order is preserved.
	Sort *SortKey `form:"sort,omitempty" json:"sort,omitempty"`

	// Order Sort direction. Defaults to `asc` when `sort` is set;
	// ignored when `sort` is absent.
	Order *ListPersistentVolumeClaimsParamsOrder `form:"order,omitempty" json:"order,omitempty"`
}

ListPersistentVolumeClaimsParams defines parameters for ListPersistentVolumeClaims.

type ListPersistentVolumeClaimsParamsOrder added in v1.10.0

type ListPersistentVolumeClaimsParamsOrder string

ListPersistentVolumeClaimsParamsOrder defines parameters for ListPersistentVolumeClaims.

const (
	ListPersistentVolumeClaimsParamsOrderAsc  ListPersistentVolumeClaimsParamsOrder = "asc"
	ListPersistentVolumeClaimsParamsOrderDesc ListPersistentVolumeClaimsParamsOrder = "desc"
)

Defines values for ListPersistentVolumeClaimsParamsOrder.

func (ListPersistentVolumeClaimsParamsOrder) Valid added in v1.10.0

Valid indicates whether the value is a known member of the ListPersistentVolumeClaimsParamsOrder enum.

type ListPersistentVolumeClaimsRequestObject

type ListPersistentVolumeClaimsRequestObject struct {
	Params ListPersistentVolumeClaimsParams
}

type ListPersistentVolumeClaimsResponseObject

type ListPersistentVolumeClaimsResponseObject interface {
	VisitListPersistentVolumeClaimsResponse(w http.ResponseWriter) error
}

type ListPersistentVolumes200JSONResponse

type ListPersistentVolumes200JSONResponse PersistentVolumeList

func (ListPersistentVolumes200JSONResponse) VisitListPersistentVolumesResponse

func (response ListPersistentVolumes200JSONResponse) VisitListPersistentVolumesResponse(w http.ResponseWriter) error

type ListPersistentVolumes400ApplicationProblemPlusJSONResponse

type ListPersistentVolumes400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (ListPersistentVolumes400ApplicationProblemPlusJSONResponse) VisitListPersistentVolumesResponse

func (response ListPersistentVolumes400ApplicationProblemPlusJSONResponse) VisitListPersistentVolumesResponse(w http.ResponseWriter) error

type ListPersistentVolumes401ApplicationProblemPlusJSONResponse

type ListPersistentVolumes401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (ListPersistentVolumes401ApplicationProblemPlusJSONResponse) VisitListPersistentVolumesResponse

func (response ListPersistentVolumes401ApplicationProblemPlusJSONResponse) VisitListPersistentVolumesResponse(w http.ResponseWriter) error

type ListPersistentVolumes403ApplicationProblemPlusJSONResponse

type ListPersistentVolumes403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (ListPersistentVolumes403ApplicationProblemPlusJSONResponse) VisitListPersistentVolumesResponse

func (response ListPersistentVolumes403ApplicationProblemPlusJSONResponse) VisitListPersistentVolumesResponse(w http.ResponseWriter) error

type ListPersistentVolumesParams

type ListPersistentVolumesParams struct {
	// Limit Maximum number of items to return. Server clamps to [1, 200].
	Limit *Limit `form:"limit,omitempty" json:"limit,omitempty"`

	// Cursor Opaque cursor returned from a previous list response.
	Cursor *Cursor `form:"cursor,omitempty" json:"cursor,omitempty"`

	// ClusterId Return only persistent volumes belonging to this cluster.
	ClusterId *PersistentVolumeClusterIdFilter `form:"cluster_id,omitempty" json:"cluster_id,omitempty"`

	// Name Case-insensitive name filter. A plain term matches as a
	// substring (`du` matches anywhere in the name); a term
	// containing `*` matches as an anchored glob pattern (`du*` =
	// starts with, `*du` = ends with, `prod-*-db` = anchored both
	// ends). LIKE metacharacters (`%`, `_`, `\`) are treated
	// literally.
	Name *NameFilter `form:"name,omitempty" json:"name,omitempty"`

	// Sort Column key to sort by. Each list endpoint documents its
	// sortable keys; an unknown key returns 400. Without `sort`,
	// the endpoint's historical default order is preserved.
	Sort *SortKey `form:"sort,omitempty" json:"sort,omitempty"`

	// Order Sort direction. Defaults to `asc` when `sort` is set;
	// ignored when `sort` is absent.
	Order *ListPersistentVolumesParamsOrder `form:"order,omitempty" json:"order,omitempty"`
}

ListPersistentVolumesParams defines parameters for ListPersistentVolumes.

type ListPersistentVolumesParamsOrder added in v1.10.0

type ListPersistentVolumesParamsOrder string

ListPersistentVolumesParamsOrder defines parameters for ListPersistentVolumes.

const (
	ListPersistentVolumesParamsOrderAsc  ListPersistentVolumesParamsOrder = "asc"
	ListPersistentVolumesParamsOrderDesc ListPersistentVolumesParamsOrder = "desc"
)

Defines values for ListPersistentVolumesParamsOrder.

func (ListPersistentVolumesParamsOrder) Valid added in v1.10.0

Valid indicates whether the value is a known member of the ListPersistentVolumesParamsOrder enum.

type ListPersistentVolumesRequestObject

type ListPersistentVolumesRequestObject struct {
	Params ListPersistentVolumesParams
}

type ListPersistentVolumesResponseObject

type ListPersistentVolumesResponseObject interface {
	VisitListPersistentVolumesResponse(w http.ResponseWriter) error
}

type ListPods200JSONResponse

type ListPods200JSONResponse PodList

func (ListPods200JSONResponse) VisitListPodsResponse

func (response ListPods200JSONResponse) VisitListPodsResponse(w http.ResponseWriter) error

type ListPods400ApplicationProblemPlusJSONResponse

type ListPods400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (ListPods400ApplicationProblemPlusJSONResponse) VisitListPodsResponse

func (response ListPods400ApplicationProblemPlusJSONResponse) VisitListPodsResponse(w http.ResponseWriter) error

type ListPods401ApplicationProblemPlusJSONResponse

type ListPods401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (ListPods401ApplicationProblemPlusJSONResponse) VisitListPodsResponse

func (response ListPods401ApplicationProblemPlusJSONResponse) VisitListPodsResponse(w http.ResponseWriter) error

type ListPods403ApplicationProblemPlusJSONResponse

type ListPods403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (ListPods403ApplicationProblemPlusJSONResponse) VisitListPodsResponse

func (response ListPods403ApplicationProblemPlusJSONResponse) VisitListPodsResponse(w http.ResponseWriter) error

type ListPodsParams

type ListPodsParams struct {
	// Limit Maximum number of items to return. Server clamps to [1, 200].
	Limit *Limit `form:"limit,omitempty" json:"limit,omitempty"`

	// Cursor Opaque cursor returned from a previous list response.
	Cursor *Cursor `form:"cursor,omitempty" json:"cursor,omitempty"`

	// NamespaceId Return only pods belonging to this namespace.
	NamespaceId *PodNamespaceIdFilter `form:"namespace_id,omitempty" json:"namespace_id,omitempty"`

	// Image Case-insensitive substring match against any container's `image`
	// field in the pod's containers JSON (init containers included).
	// Handy for answering "which pods run `log4j:2.15.0`?" — a partial
	// like `log4j:2.15` will match `log4j:2.15.0`, `log4j:2.15.1`, etc.
	Image *PodImageFilter `form:"image,omitempty" json:"image,omitempty"`

	// NodeName Exact match against the pod's `node_name`. Lets the Node detail
	// view answer "which pods are hosted on this node?" without
	// paginating every pod in the cluster.
	NodeName *PodNodeNameFilter `form:"node_name,omitempty" json:"node_name,omitempty"`

	// WorkloadId Filter pods by their controlling workload. Returns only pods whose
	// `workload_id` FK matches the given UUID.
	WorkloadId *PodWorkloadIdFilter `form:"workload_id,omitempty" json:"workload_id,omitempty"`

	// Name Case-insensitive name filter. A plain term matches as a
	// substring (`du` matches anywhere in the name); a term
	// containing `*` matches as an anchored glob pattern (`du*` =
	// starts with, `*du` = ends with, `prod-*-db` = anchored both
	// ends). LIKE metacharacters (`%`, `_`, `\`) are treated
	// literally.
	Name *NameFilter `form:"name,omitempty" json:"name,omitempty"`

	// Sort Column key to sort by. Each list endpoint documents its
	// sortable keys; an unknown key returns 400. Without `sort`,
	// the endpoint's historical default order is preserved.
	Sort *SortKey `form:"sort,omitempty" json:"sort,omitempty"`

	// Order Sort direction. Defaults to `asc` when `sort` is set;
	// ignored when `sort` is absent.
	Order *ListPodsParamsOrder `form:"order,omitempty" json:"order,omitempty"`
}

ListPodsParams defines parameters for ListPods.

type ListPodsParamsOrder added in v1.10.0

type ListPodsParamsOrder string

ListPodsParamsOrder defines parameters for ListPods.

const (
	ListPodsParamsOrderAsc  ListPodsParamsOrder = "asc"
	ListPodsParamsOrderDesc ListPodsParamsOrder = "desc"
)

Defines values for ListPodsParamsOrder.

func (ListPodsParamsOrder) Valid added in v1.10.0

func (e ListPodsParamsOrder) Valid() bool

Valid indicates whether the value is a known member of the ListPodsParamsOrder enum.

type ListPodsRequestObject

type ListPodsRequestObject struct {
	Params ListPodsParams
}

type ListPodsResponseObject

type ListPodsResponseObject interface {
	VisitListPodsResponse(w http.ResponseWriter) error
}

type ListServices200JSONResponse

type ListServices200JSONResponse ServiceList

func (ListServices200JSONResponse) VisitListServicesResponse

func (response ListServices200JSONResponse) VisitListServicesResponse(w http.ResponseWriter) error

type ListServices400ApplicationProblemPlusJSONResponse

type ListServices400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (ListServices400ApplicationProblemPlusJSONResponse) VisitListServicesResponse

func (response ListServices400ApplicationProblemPlusJSONResponse) VisitListServicesResponse(w http.ResponseWriter) error

type ListServices401ApplicationProblemPlusJSONResponse

type ListServices401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (ListServices401ApplicationProblemPlusJSONResponse) VisitListServicesResponse

func (response ListServices401ApplicationProblemPlusJSONResponse) VisitListServicesResponse(w http.ResponseWriter) error

type ListServices403ApplicationProblemPlusJSONResponse

type ListServices403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (ListServices403ApplicationProblemPlusJSONResponse) VisitListServicesResponse

func (response ListServices403ApplicationProblemPlusJSONResponse) VisitListServicesResponse(w http.ResponseWriter) error

type ListServicesParams

type ListServicesParams struct {
	// Limit Maximum number of items to return. Server clamps to [1, 200].
	Limit *Limit `form:"limit,omitempty" json:"limit,omitempty"`

	// Cursor Opaque cursor returned from a previous list response.
	Cursor *Cursor `form:"cursor,omitempty" json:"cursor,omitempty"`

	// NamespaceId Return only services belonging to this namespace.
	NamespaceId *ServiceNamespaceIdFilter `form:"namespace_id,omitempty" json:"namespace_id,omitempty"`

	// Name Case-insensitive name filter. A plain term matches as a
	// substring (`du` matches anywhere in the name); a term
	// containing `*` matches as an anchored glob pattern (`du*` =
	// starts with, `*du` = ends with, `prod-*-db` = anchored both
	// ends). LIKE metacharacters (`%`, `_`, `\`) are treated
	// literally.
	Name *NameFilter `form:"name,omitempty" json:"name,omitempty"`

	// Sort Column key to sort by. Each list endpoint documents its
	// sortable keys; an unknown key returns 400. Without `sort`,
	// the endpoint's historical default order is preserved.
	Sort *SortKey `form:"sort,omitempty" json:"sort,omitempty"`

	// Order Sort direction. Defaults to `asc` when `sort` is set;
	// ignored when `sort` is absent.
	Order *ListServicesParamsOrder `form:"order,omitempty" json:"order,omitempty"`
}

ListServicesParams defines parameters for ListServices.

type ListServicesParamsOrder added in v1.10.0

type ListServicesParamsOrder string

ListServicesParamsOrder defines parameters for ListServices.

const (
	ListServicesParamsOrderAsc  ListServicesParamsOrder = "asc"
	ListServicesParamsOrderDesc ListServicesParamsOrder = "desc"
)

Defines values for ListServicesParamsOrder.

func (ListServicesParamsOrder) Valid added in v1.10.0

func (e ListServicesParamsOrder) Valid() bool

Valid indicates whether the value is a known member of the ListServicesParamsOrder enum.

type ListServicesRequestObject

type ListServicesRequestObject struct {
	Params ListServicesParams
}

type ListServicesResponseObject

type ListServicesResponseObject interface {
	VisitListServicesResponse(w http.ResponseWriter) error
}

type ListSessions200JSONResponse

type ListSessions200JSONResponse SessionList

func (ListSessions200JSONResponse) VisitListSessionsResponse

func (response ListSessions200JSONResponse) VisitListSessionsResponse(w http.ResponseWriter) error

type ListSessions400ApplicationProblemPlusJSONResponse added in v1.10.0

type ListSessions400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (ListSessions400ApplicationProblemPlusJSONResponse) VisitListSessionsResponse added in v1.10.0

func (response ListSessions400ApplicationProblemPlusJSONResponse) VisitListSessionsResponse(w http.ResponseWriter) error

type ListSessions401ApplicationProblemPlusJSONResponse

type ListSessions401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (ListSessions401ApplicationProblemPlusJSONResponse) VisitListSessionsResponse

func (response ListSessions401ApplicationProblemPlusJSONResponse) VisitListSessionsResponse(w http.ResponseWriter) error

type ListSessions403ApplicationProblemPlusJSONResponse

type ListSessions403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (ListSessions403ApplicationProblemPlusJSONResponse) VisitListSessionsResponse

func (response ListSessions403ApplicationProblemPlusJSONResponse) VisitListSessionsResponse(w http.ResponseWriter) error

type ListSessionsParams

type ListSessionsParams struct {
	// Limit Maximum number of items to return. Server clamps to [1, 200].
	Limit *Limit `form:"limit,omitempty" json:"limit,omitempty"`

	// Cursor Opaque cursor returned from a previous list response.
	Cursor *Cursor `form:"cursor,omitempty" json:"cursor,omitempty"`

	// Name Case-insensitive name filter. A plain term matches as a
	// substring (`du` matches anywhere in the name); a term
	// containing `*` matches as an anchored glob pattern (`du*` =
	// starts with, `*du` = ends with, `prod-*-db` = anchored both
	// ends). LIKE metacharacters (`%`, `_`, `\`) are treated
	// literally.
	Name *NameFilter `form:"name,omitempty" json:"name,omitempty"`

	// Sort Column key to sort by. Each list endpoint documents its
	// sortable keys; an unknown key returns 400. Without `sort`,
	// the endpoint's historical default order is preserved.
	Sort *SortKey `form:"sort,omitempty" json:"sort,omitempty"`

	// Order Sort direction. Defaults to `asc` when `sort` is set;
	// ignored when `sort` is absent.
	Order *ListSessionsParamsOrder `form:"order,omitempty" json:"order,omitempty"`
}

ListSessionsParams defines parameters for ListSessions.

type ListSessionsParamsOrder added in v1.10.0

type ListSessionsParamsOrder string

ListSessionsParamsOrder defines parameters for ListSessions.

const (
	ListSessionsParamsOrderAsc  ListSessionsParamsOrder = "asc"
	ListSessionsParamsOrderDesc ListSessionsParamsOrder = "desc"
)

Defines values for ListSessionsParamsOrder.

func (ListSessionsParamsOrder) Valid added in v1.10.0

func (e ListSessionsParamsOrder) Valid() bool

Valid indicates whether the value is a known member of the ListSessionsParamsOrder enum.

type ListSessionsRequestObject

type ListSessionsRequestObject struct {
	Params ListSessionsParams
}

type ListSessionsResponseObject

type ListSessionsResponseObject interface {
	VisitListSessionsResponse(w http.ResponseWriter) error
}

type ListUsers200JSONResponse

type ListUsers200JSONResponse UserList

func (ListUsers200JSONResponse) VisitListUsersResponse

func (response ListUsers200JSONResponse) VisitListUsersResponse(w http.ResponseWriter) error

type ListUsers400ApplicationProblemPlusJSONResponse added in v1.10.0

type ListUsers400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (ListUsers400ApplicationProblemPlusJSONResponse) VisitListUsersResponse added in v1.10.0

func (response ListUsers400ApplicationProblemPlusJSONResponse) VisitListUsersResponse(w http.ResponseWriter) error

type ListUsers401ApplicationProblemPlusJSONResponse

type ListUsers401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (ListUsers401ApplicationProblemPlusJSONResponse) VisitListUsersResponse

func (response ListUsers401ApplicationProblemPlusJSONResponse) VisitListUsersResponse(w http.ResponseWriter) error

type ListUsers403ApplicationProblemPlusJSONResponse

type ListUsers403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (ListUsers403ApplicationProblemPlusJSONResponse) VisitListUsersResponse

func (response ListUsers403ApplicationProblemPlusJSONResponse) VisitListUsersResponse(w http.ResponseWriter) error

type ListUsersParams

type ListUsersParams struct {
	// Limit Maximum number of items to return. Server clamps to [1, 200].
	Limit *Limit `form:"limit,omitempty" json:"limit,omitempty"`

	// Cursor Opaque cursor returned from a previous list response.
	Cursor *Cursor `form:"cursor,omitempty" json:"cursor,omitempty"`

	// Name Case-insensitive name filter. A plain term matches as a
	// substring (`du` matches anywhere in the name); a term
	// containing `*` matches as an anchored glob pattern (`du*` =
	// starts with, `*du` = ends with, `prod-*-db` = anchored both
	// ends). LIKE metacharacters (`%`, `_`, `\`) are treated
	// literally.
	Name *NameFilter `form:"name,omitempty" json:"name,omitempty"`

	// Sort Column key to sort by. Each list endpoint documents its
	// sortable keys; an unknown key returns 400. Without `sort`,
	// the endpoint's historical default order is preserved.
	Sort *SortKey `form:"sort,omitempty" json:"sort,omitempty"`

	// Order Sort direction. Defaults to `asc` when `sort` is set;
	// ignored when `sort` is absent.
	Order *ListUsersParamsOrder `form:"order,omitempty" json:"order,omitempty"`
}

ListUsersParams defines parameters for ListUsers.

type ListUsersParamsOrder added in v1.10.0

type ListUsersParamsOrder string

ListUsersParamsOrder defines parameters for ListUsers.

const (
	ListUsersParamsOrderAsc  ListUsersParamsOrder = "asc"
	ListUsersParamsOrderDesc ListUsersParamsOrder = "desc"
)

Defines values for ListUsersParamsOrder.

func (ListUsersParamsOrder) Valid added in v1.10.0

func (e ListUsersParamsOrder) Valid() bool

Valid indicates whether the value is a known member of the ListUsersParamsOrder enum.

type ListUsersRequestObject

type ListUsersRequestObject struct {
	Params ListUsersParams
}

type ListUsersResponseObject

type ListUsersResponseObject interface {
	VisitListUsersResponse(w http.ResponseWriter) error
}

type ListWorkloads200JSONResponse

type ListWorkloads200JSONResponse WorkloadList

func (ListWorkloads200JSONResponse) VisitListWorkloadsResponse

func (response ListWorkloads200JSONResponse) VisitListWorkloadsResponse(w http.ResponseWriter) error

type ListWorkloads400ApplicationProblemPlusJSONResponse

type ListWorkloads400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (ListWorkloads400ApplicationProblemPlusJSONResponse) VisitListWorkloadsResponse

func (response ListWorkloads400ApplicationProblemPlusJSONResponse) VisitListWorkloadsResponse(w http.ResponseWriter) error

type ListWorkloads401ApplicationProblemPlusJSONResponse

type ListWorkloads401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (ListWorkloads401ApplicationProblemPlusJSONResponse) VisitListWorkloadsResponse

func (response ListWorkloads401ApplicationProblemPlusJSONResponse) VisitListWorkloadsResponse(w http.ResponseWriter) error

type ListWorkloads403ApplicationProblemPlusJSONResponse

type ListWorkloads403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (ListWorkloads403ApplicationProblemPlusJSONResponse) VisitListWorkloadsResponse

func (response ListWorkloads403ApplicationProblemPlusJSONResponse) VisitListWorkloadsResponse(w http.ResponseWriter) error

type ListWorkloadsParams

type ListWorkloadsParams struct {
	// Limit Maximum number of items to return. Server clamps to [1, 200].
	Limit *Limit `form:"limit,omitempty" json:"limit,omitempty"`

	// Cursor Opaque cursor returned from a previous list response.
	Cursor *Cursor `form:"cursor,omitempty" json:"cursor,omitempty"`

	// IncludeTerminated When true, include rows whose `terminated_at` is set (soft-deleted by
	// the collector reconcile pass). Defaults to false: only live entities
	// are returned. ADR-0021 §5 / §6.
	IncludeTerminated *IncludeTerminated `form:"include_terminated,omitempty" json:"include_terminated,omitempty"`

	// NamespaceId Return only workloads belonging to this namespace.
	NamespaceId *WorkloadNamespaceIdFilter `form:"namespace_id,omitempty" json:"namespace_id,omitempty"`

	// Kind Return only workloads of this kind.
	Kind *WorkloadKindFilter `form:"kind,omitempty" json:"kind,omitempty"`

	// Image Case-insensitive substring match against any container's `image`
	// field in the workload's containers JSON (init containers included).
	// Mirrors the PodImageFilter so both kinds answer the same
	// "which assets run this component version?" question.
	Image *WorkloadImageFilter `form:"image,omitempty" json:"image,omitempty"`

	// ApplicationId Return only workloads linked to this Application (ADR-0029).
	ApplicationId *WorkloadApplicationIdFilter `form:"application_id,omitempty" json:"application_id,omitempty"`

	// ApplicationName Return only workloads linked to the Application with this name
	// (ADR-0029). Resolved server-side.
	ApplicationName *WorkloadApplicationNameFilter `form:"application_name,omitempty" json:"application_name,omitempty"`

	// Unlinked When true, return only workloads with application_id IS NULL.
	Unlinked *WorkloadUnlinkedFilter `form:"unlinked,omitempty" json:"unlinked,omitempty"`

	// Name Case-insensitive name filter. A plain term matches as a
	// substring (`du` matches anywhere in the name); a term
	// containing `*` matches as an anchored glob pattern (`du*` =
	// starts with, `*du` = ends with, `prod-*-db` = anchored both
	// ends). LIKE metacharacters (`%`, `_`, `\`) are treated
	// literally.
	Name *NameFilter `form:"name,omitempty" json:"name,omitempty"`

	// Sort Column key to sort by. Each list endpoint documents its
	// sortable keys; an unknown key returns 400. Without `sort`,
	// the endpoint's historical default order is preserved.
	Sort *SortKey `form:"sort,omitempty" json:"sort,omitempty"`

	// Order Sort direction. Defaults to `asc` when `sort` is set;
	// ignored when `sort` is absent.
	Order *ListWorkloadsParamsOrder `form:"order,omitempty" json:"order,omitempty"`

	// Include Optional enrichment selector. Only 'containers_versions' is recognised; it populates each item's containers_versions (ADR-0022/0032). Omitted by default to keep list responses cheap.
	Include *ListWorkloadsParamsInclude `form:"include,omitempty" json:"include,omitempty"`
}

ListWorkloadsParams defines parameters for ListWorkloads.

type ListWorkloadsParamsInclude added in v0.33.0

type ListWorkloadsParamsInclude string

ListWorkloadsParamsInclude defines parameters for ListWorkloads.

const (
	IncludeContainersVersions ListWorkloadsParamsInclude = "containers_versions"
)

Defines values for ListWorkloadsParamsInclude.

func (ListWorkloadsParamsInclude) Valid added in v0.33.0

func (e ListWorkloadsParamsInclude) Valid() bool

Valid indicates whether the value is a known member of the ListWorkloadsParamsInclude enum.

type ListWorkloadsParamsOrder added in v1.10.0

type ListWorkloadsParamsOrder string

ListWorkloadsParamsOrder defines parameters for ListWorkloads.

const (
	ListWorkloadsParamsOrderAsc  ListWorkloadsParamsOrder = "asc"
	ListWorkloadsParamsOrderDesc ListWorkloadsParamsOrder = "desc"
)

Defines values for ListWorkloadsParamsOrder.

func (ListWorkloadsParamsOrder) Valid added in v1.10.0

func (e ListWorkloadsParamsOrder) Valid() bool

Valid indicates whether the value is a known member of the ListWorkloadsParamsOrder enum.

type ListWorkloadsRequestObject

type ListWorkloadsRequestObject struct {
	Params ListWorkloadsParams
}

type ListWorkloadsResponseObject

type ListWorkloadsResponseObject interface {
	VisitListWorkloadsResponse(w http.ResponseWriter) error
}

type Login204Response

type Login204Response struct {
	Headers Login204ResponseHeaders
}

func (Login204Response) VisitLoginResponse

func (response Login204Response) VisitLoginResponse(w http.ResponseWriter) error

type Login204ResponseHeaders

type Login204ResponseHeaders struct {
	SetCookie *string
}

type Login400ApplicationProblemPlusJSONResponse

type Login400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (Login400ApplicationProblemPlusJSONResponse) VisitLoginResponse

type Login401ApplicationProblemPlusJSONResponse

type Login401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (Login401ApplicationProblemPlusJSONResponse) VisitLoginResponse

type Login429ApplicationProblemPlusJSONResponse

type Login429ApplicationProblemPlusJSONResponse Problem

func (Login429ApplicationProblemPlusJSONResponse) VisitLoginResponse

type LoginJSONRequestBody

type LoginJSONRequestBody = LoginRequest

LoginJSONRequestBody defines body for Login for application/json ContentType.

type LoginRateLimiter

type LoginRateLimiter struct {
	// contains filtered or unexported fields
}

LoginRateLimiter provides per-IP rate limiting for the login endpoint. Implements ADR-0007 IMP-009: 5 requests/minute per source IP.

func NewLoginRateLimiter

func NewLoginRateLimiter() *LoginRateLimiter

NewLoginRateLimiter creates a rate limiter allowing 5 login attempts per minute per source IP with a burst of 5.

func (*LoginRateLimiter) Allow

func (rl *LoginRateLimiter) Allow(ip string) bool

Allow returns true if the IP is within the rate limit.

type LoginRequest

type LoginRequest struct {
	Password string `json:"password"`
	Username string `json:"username"`
}

LoginRequest Username + password, both required.

type LoginRequestObject

type LoginRequestObject struct {
	Body *LoginJSONRequestBody
}

type LoginResponseObject

type LoginResponseObject interface {
	VisitLoginResponse(w http.ResponseWriter) error
}

type Logout204Response

type Logout204Response struct {
}

func (Logout204Response) VisitLogoutResponse

func (response Logout204Response) VisitLogoutResponse(w http.ResponseWriter) error

type LogoutRequestObject

type LogoutRequestObject struct {
}

type LogoutResponseObject

type LogoutResponseObject interface {
	VisitLogoutResponse(w http.ResponseWriter) error
}

type Me

type Me struct {
	// Id User id when kind=user, token id when kind=token.
	Id *openapi_types.UUID `json:"id,omitempty"`

	// Kind `user` when authenticated via session cookie, `token` when
	// via `Authorization: Bearer`. UIs render accordingly.
	Kind MeKind `json:"kind"`

	// MustChangePassword Present when kind=user. True for bootstrap admins and users
	// whose password was reset by an admin — the UI blocks every
	// route except `/change-password` until this is cleared.
	MustChangePassword *bool `json:"must_change_password,omitempty"`

	// Role Present when kind=user.
	Role *Role `json:"role,omitempty"`

	// Scopes Effective scopes after role→scope mapping or token declaration.
	Scopes []string `json:"scopes"`

	// TokenName Present when kind=token.
	TokenName *string `json:"token_name,omitempty"`

	// Username Present when kind=user.
	Username *string `json:"username,omitempty"`
}

Me Caller identity, role, and effective scopes.

type MeKind

type MeKind string

MeKind `user` when authenticated via session cookie, `token` when via `Authorization: Bearer`. UIs render accordingly.

const (
	MeKindToken MeKind = "token"
	MeKindUser  MeKind = "user"
)

Defines values for MeKind.

func (MeKind) Valid

func (e MeKind) Valid() bool

Valid indicates whether the value is a known member of the MeKind enum.

type MiddlewareFunc

type MiddlewareFunc func(http.Handler) http.Handler

func AuditMiddleware

func AuditMiddleware(recorder AuditRecorder, source string, trustedProxies []*net.IPNet) MiddlewareFunc

AuditMiddleware wraps the generated router and records every call that looks state-changing. Recording happens after the downstream handler returns so we capture the response status alongside the caller. Insertion failures are logged at ERROR but never surface to the client: losing the CMDB because the audit table is briefly unreachable would be a worse outcome than a gap in the log.

`source` distinguishes which listener served the request — "api" for longue-vue's public listener, "ingest_gw" for the mTLS-only listener fronted by the DMZ gateway (ADR-0016). The label is passed through to audit_events.source so operators can answer "what came through the DMZ" with a single WHERE clause.

`trustedProxies` is the operator-supplied CIDR list (ADR-0017 §2) whose X-Forwarded-For headers we honor when resolving the SourceIP for the audit row. Pass nil to ignore XFF unconditionally — the secure default and what tests should use unless they're specifically exercising proxy-trust behavior.

func AuthMiddleware

func AuthMiddleware(store auth.Store, policy auth.SecureCookiePolicy, trustedProxies []*net.IPNet) MiddlewareFunc

AuthMiddleware returns an api.MiddlewareFunc that resolves cookie → bearer → 401 and attaches the caller to the request context. Pass the same store the Server holds, the same cookie policy NewServer got, and the operator-supplied trusted-proxy CIDR list (ADR-0017) — the trust list gates whether X-Forwarded-Proto is honored when deciding the Secure cookie flag. Pass nil to ignore XFP unconditionally — the secure default.

type NameFilter added in v1.10.0

type NameFilter = string

NameFilter defines model for NameFilter.

type Namespace

type Namespace struct {
	// Annotations Free-form k/v for metadata not worth its own column. The
	// collector never writes this field.
	Annotations *map[string]string `json:"annotations,omitempty"`
	ClusterId   openapi_types.UUID `json:"cluster_id"`

	// ClusterName Denormalized `clusters.name` for the namespace's cluster.
	// Null when the cluster row is gone (orphan); the UI renders
	// that case as an explicit "(orphan)" badge rather than a
	// bare UUID. See ADR-0027.
	ClusterName *string    `json:"cluster_name,omitempty"`
	CreatedAt   *time.Time `json:"created_at,omitempty"`

	// Criticality Free-form operational tier label (`critical`, `high`,
	// `medium`, `low`). Distinct from DICT data-classification,
	// which lives on its own columns.
	Criticality *string `json:"criticality,omitempty"`

	// DisplayName Human-friendly label, free-form.
	DisplayName *string             `json:"display_name,omitempty"`
	Id          *openapi_types.UUID `json:"id,omitempty"`

	// Labels Arbitrary user-supplied string key/value labels.
	Labels *map[string]string `json:"labels,omitempty"`

	// Layer Always `infrastructure_logical` for Namespace. Set by the server.
	Layer *Layer `json:"layer,omitempty"`
	Name  string `json:"name"`

	// Notes Long-form prose.
	Notes *string `json:"notes,omitempty"`

	// Owner Free-form handle for the team / on-call that owns this
	// namespace. Surfaced on the detail page so incident
	// responders know who to wake up.
	Owner *string `json:"owner,omitempty"`

	// Phase Kubernetes namespace phase as last observed (e.g. "Active", "Terminating").
	// Open-ended to accommodate any additional phases Kubernetes introduces.
	Phase *string `json:"phase,omitempty"`

	// RunbookUrl Link to the owning team's runbook for this namespace.
	RunbookUrl *string    `json:"runbook_url,omitempty"`
	UpdatedAt  *time.Time `json:"updated_at,omitempty"`
}

Namespace defines model for Namespace.

type NamespaceClusterIdFilter

type NamespaceClusterIdFilter = openapi_types.UUID

NamespaceClusterIdFilter defines model for NamespaceClusterIdFilter.

type NamespaceCreate

type NamespaceCreate struct {
	// Annotations Free-form k/v for metadata not worth its own column. The
	// collector never writes this field.
	Annotations *map[string]string `json:"annotations,omitempty"`

	// ClusterId Parent cluster id. Immutable after creation; the cluster must
	// already exist or the create returns 404.
	ClusterId openapi_types.UUID `json:"cluster_id"`

	// Criticality Free-form operational tier label (`critical`, `high`,
	// `medium`, `low`). Distinct from DICT data-classification,
	// which lives on its own columns.
	Criticality *string `json:"criticality,omitempty"`

	// DisplayName Human-friendly label, free-form.
	DisplayName *string `json:"display_name,omitempty"`

	// Labels Arbitrary user-supplied string key/value labels.
	Labels *map[string]string `json:"labels,omitempty"`

	// Name Kubernetes namespace name (DNS-label style). Unique per cluster.
	// Immutable after creation.
	Name string `json:"name"`

	// Notes Long-form prose.
	Notes *string `json:"notes,omitempty"`

	// Owner Free-form handle for the team / on-call that owns this
	// namespace. Surfaced on the detail page so incident
	// responders know who to wake up.
	Owner *string `json:"owner,omitempty"`

	// Phase Kubernetes namespace phase as last observed (e.g. "Active", "Terminating").
	// Open-ended to accommodate any additional phases Kubernetes introduces.
	Phase *string `json:"phase,omitempty"`

	// RunbookUrl Link to the owning team's runbook for this namespace.
	RunbookUrl *string `json:"runbook_url,omitempty"`
}

NamespaceCreate defines model for NamespaceCreate.

type NamespaceId

type NamespaceId = openapi_types.UUID

NamespaceId defines model for NamespaceId.

type NamespaceList

type NamespaceList struct {
	Items []Namespace `json:"items"`

	// NextCursor Opaque cursor to pass as `?cursor=` to fetch the next page.
	// Absent or null when no more pages remain.
	NextCursor *string `json:"next_cursor,omitempty"`
}

NamespaceList Paged list of namespaces.

type NamespaceListFilter added in v1.10.0

type NamespaceListFilter struct {
	ClusterID *uuid.UUID
	// Name is the uniform name= filter: ci substring, or anchored
	// glob when the term contains `*` (spec 2026-07-10).
	Name              *string
	IncludeTerminated bool
}

NamespaceListFilter — nil fields are ignored; set fields AND-combine (same contract as NodeListFilter).

type NamespaceMutable

type NamespaceMutable struct {
	// Annotations Free-form k/v for metadata not worth its own column. The
	// collector never writes this field.
	Annotations *map[string]string `json:"annotations,omitempty"`

	// Criticality Free-form operational tier label (`critical`, `high`,
	// `medium`, `low`). Distinct from DICT data-classification,
	// which lives on its own columns.
	Criticality *string `json:"criticality,omitempty"`

	// DisplayName Human-friendly label, free-form.
	DisplayName *string `json:"display_name,omitempty"`

	// Labels Arbitrary user-supplied string key/value labels.
	Labels *map[string]string `json:"labels,omitempty"`

	// Notes Long-form prose.
	Notes *string `json:"notes,omitempty"`

	// Owner Free-form handle for the team / on-call that owns this
	// namespace. Surfaced on the detail page so incident
	// responders know who to wake up.
	Owner *string `json:"owner,omitempty"`

	// Phase Kubernetes namespace phase as last observed (e.g. "Active", "Terminating").
	// Open-ended to accommodate any additional phases Kubernetes introduces.
	Phase *string `json:"phase,omitempty"`

	// RunbookUrl Link to the owning team's runbook for this namespace.
	RunbookUrl *string `json:"runbook_url,omitempty"`
}

NamespaceMutable Fields on a Namespace that clients may set and later update.

type NamespaceStore added in v1.6.2

type NamespaceStore interface {
	// CreateNamespace inserts a new namespace. Returns ErrNotFound when the
	// parent cluster does not exist; ErrConflict when (cluster_id, name)
	// already has a namespace.
	CreateNamespace(ctx context.Context, in NamespaceCreate) (Namespace, error)

	// GetNamespace fetches a namespace by id. Returns ErrNotFound if absent.
	GetNamespace(ctx context.Context, id uuid.UUID) (Namespace, error)

	// ListNamespaces returns a paged list of namespaces matching filter,
	// sorted by page.Sort/page.Order. Unknown sort keys → ErrInvalidSort;
	// mismatched cursor → ErrInvalidCursor.
	ListNamespaces(ctx context.Context, filter NamespaceListFilter, page ListPage) (items []Namespace, nextCursor string, err error)

	// UpdateNamespace applies the merge-patch fields set in in. Returns
	// ErrNotFound if the namespace does not exist.
	UpdateNamespace(ctx context.Context, id uuid.UUID, in NamespaceUpdate) (Namespace, error)

	// DeleteNamespace removes a namespace by id. Returns ErrNotFound if absent.
	DeleteNamespace(ctx context.Context, id uuid.UUID) error

	// SoftDeleteNamespace marks the namespace and its live workloads as
	// terminated in a single transaction. See ADR-0021 §IMP-007.
	SoftDeleteNamespace(ctx context.Context, id uuid.UUID) error

	// UpsertNamespace mirrors UpsertNode for namespaces. The second return
	// value classifies the operation for audit filtering (ADR-0024):
	// OutcomeInserted for a fresh insert, OutcomeBusinessChanged when a
	// business field changed, OutcomeNoChange when only clock fields moved.
	UpsertNamespace(ctx context.Context, in NamespaceCreate) (Namespace, UpsertOutcome, error)

	// DeleteNamespacesNotIn mirrors DeleteNodesNotIn for namespaces.
	DeleteNamespacesNotIn(ctx context.Context, clusterID uuid.UUID, keepNames []string) (int64, error)
}

NamespaceStore covers namespace CRUD, upsert, soft-delete, and reconcile.

type NamespaceUpdate

type NamespaceUpdate = NamespaceMutable

NamespaceUpdate Fields on a Namespace that clients may set and later update.

type NetworkPolicy added in v1.1.0

type NetworkPolicy struct {
	ClusterId   openapi_types.UUID         `json:"cluster_id"`
	Id          openapi_types.UUID         `json:"id"`
	Name        string                     `json:"name"`
	NamespaceId openapi_types.UUID         `json:"namespace_id"`
	PodSelector map[string]interface{}     `json:"pod_selector"`
	PolicyTypes []NetworkPolicyPolicyTypes `json:"policy_types"`
}

NetworkPolicy defines model for NetworkPolicy.

type NetworkPolicyCreate added in v1.4.0

type NetworkPolicyCreate struct {
	ClusterId   openapi_types.UUID `json:"cluster_id"`
	Name        string             `json:"name"`
	NamespaceId openapi_types.UUID `json:"namespace_id"`

	// PodSelector K8s LabelSelector verbatim
	PodSelector map[string]interface{} `json:"pod_selector"`

	// PolicyTypes K8s PolicyType enum values (Ingress, Egress)
	PolicyTypes []string                 `json:"policy_types"`
	Rules       []NetworkPolicyRuleInput `json:"rules"`

	// SpecRaw Full K8s NetworkPolicySpec verbatim
	SpecRaw map[string]interface{} `json:"spec_raw"`
}

NetworkPolicyCreate Push-collector input shape for upserting a NetworkPolicy with its rules atomically (ADR-0038). The server resolves cluster_id + namespace_id + name to an existing row (UPDATE) or inserts a new one (INSERT) in a single transaction along with the full rule replacement.

type NetworkPolicyListFilter added in v1.10.0

type NetworkPolicyListFilter struct {
	// NamespaceID narrows the result to policies in this namespace (nil = all).
	NamespaceID *uuid.UUID
	// Name is a case-insensitive substring / anchored-glob match on name.
	Name *string
}

NetworkPolicyListFilter collects optional filters for ListNetworkPoliciesByCluster.

type NetworkPolicyPolicyTypes added in v1.1.0

type NetworkPolicyPolicyTypes string

NetworkPolicyPolicyTypes defines model for NetworkPolicy.PolicyTypes.

const (
	NetworkPolicyPolicyTypesEgress  NetworkPolicyPolicyTypes = "Egress"
	NetworkPolicyPolicyTypesIngress NetworkPolicyPolicyTypes = "Ingress"
)

Defines values for NetworkPolicyPolicyTypes.

func (NetworkPolicyPolicyTypes) Valid added in v1.1.0

func (e NetworkPolicyPolicyTypes) Valid() bool

Valid indicates whether the value is a known member of the NetworkPolicyPolicyTypes enum.

type NetworkPolicyRow added in v1.1.0

type NetworkPolicyRow struct {
	ID          uuid.UUID       `json:"id"`
	ClusterID   uuid.UUID       `json:"cluster_id"`
	NamespaceID uuid.UUID       `json:"namespace_id"`
	Name        string          `json:"name"`
	PodSelector json.RawMessage `json:"pod_selector"`
	PolicyTypes []string        `json:"policy_types"`
	SpecRaw     json.RawMessage `json:"spec_raw,omitempty"`
}

NetworkPolicyRow is the persisted view of one Kubernetes NetworkPolicy. PodSelector and PolicyTypes mirror the K8s API object. SpecRaw carries the full raw spec JSONB for future engine use (P2).

type NetworkPolicyRule added in v1.1.0

type NetworkPolicyRule struct {
	Direction             NetworkPolicyRuleDirection `json:"direction"`
	Id                    openapi_types.UUID         `json:"id"`
	PeerIpBlockCidr       *string                    `json:"peer_ip_block_cidr,omitempty"`
	PeerIpBlockExcept     *[]string                  `json:"peer_ip_block_except,omitempty"`
	PeerKind              NetworkPolicyRulePeerKind  `json:"peer_kind"`
	PeerNamespaceSelector *map[string]interface{}    `json:"peer_namespace_selector,omitempty"`
	PeerPodSelector       *map[string]interface{}    `json:"peer_pod_selector,omitempty"`
	Ports                 *[]map[string]interface{}  `json:"ports,omitempty"`
}

NetworkPolicyRule defines model for NetworkPolicyRule.

type NetworkPolicyRuleDirection added in v1.1.0

type NetworkPolicyRuleDirection string

NetworkPolicyRuleDirection defines model for NetworkPolicyRule.Direction.

const (
	NetworkPolicyRuleDirectionEgress  NetworkPolicyRuleDirection = "egress"
	NetworkPolicyRuleDirectionIngress NetworkPolicyRuleDirection = "ingress"
)

Defines values for NetworkPolicyRuleDirection.

func (NetworkPolicyRuleDirection) Valid added in v1.1.0

func (e NetworkPolicyRuleDirection) Valid() bool

Valid indicates whether the value is a known member of the NetworkPolicyRuleDirection enum.

type NetworkPolicyRuleInput added in v1.4.0

type NetworkPolicyRuleInput struct {
	Direction             NetworkPolicyRuleInputDirection `json:"direction"`
	PeerIpBlockCidr       *string                         `json:"peer_ip_block_cidr,omitempty"`
	PeerIpBlockExcept     *[]string                       `json:"peer_ip_block_except,omitempty"`
	PeerKind              NetworkPolicyRuleInputPeerKind  `json:"peer_kind"`
	PeerNamespaceSelector *map[string]interface{}         `json:"peer_namespace_selector,omitempty"`
	PeerPodSelector       *map[string]interface{}         `json:"peer_pod_selector,omitempty"`
	Ports                 []map[string]interface{}        `json:"ports"`
}

NetworkPolicyRuleInput One flattened ingress/egress rule. peer_kind discriminates which peer_* fields are populated: "selector" => peer_pod_selector + peer_namespace_selector; "ip_block" => peer_ip_block_cidr + peer_ip_block_except.

type NetworkPolicyRuleInputDirection added in v1.4.0

type NetworkPolicyRuleInputDirection string

NetworkPolicyRuleInputDirection defines model for NetworkPolicyRuleInput.Direction.

const (
	NetworkPolicyRuleInputDirectionEgress  NetworkPolicyRuleInputDirection = "egress"
	NetworkPolicyRuleInputDirectionIngress NetworkPolicyRuleInputDirection = "ingress"
)

Defines values for NetworkPolicyRuleInputDirection.

func (NetworkPolicyRuleInputDirection) Valid added in v1.4.0

Valid indicates whether the value is a known member of the NetworkPolicyRuleInputDirection enum.

type NetworkPolicyRuleInputPeerKind added in v1.4.0

type NetworkPolicyRuleInputPeerKind string

NetworkPolicyRuleInputPeerKind defines model for NetworkPolicyRuleInput.PeerKind.

const (
	NetworkPolicyRuleInputPeerKindIpBlock  NetworkPolicyRuleInputPeerKind = "ip_block"
	NetworkPolicyRuleInputPeerKindSelector NetworkPolicyRuleInputPeerKind = "selector"
)

Defines values for NetworkPolicyRuleInputPeerKind.

func (NetworkPolicyRuleInputPeerKind) Valid added in v1.4.0

Valid indicates whether the value is a known member of the NetworkPolicyRuleInputPeerKind enum.

type NetworkPolicyRulePeerKind added in v1.1.0

type NetworkPolicyRulePeerKind string

NetworkPolicyRulePeerKind defines model for NetworkPolicyRule.PeerKind.

const (
	NetworkPolicyRulePeerKindIpBlock  NetworkPolicyRulePeerKind = "ip_block"
	NetworkPolicyRulePeerKindSelector NetworkPolicyRulePeerKind = "selector"
)

Defines values for NetworkPolicyRulePeerKind.

func (NetworkPolicyRulePeerKind) Valid added in v1.1.0

func (e NetworkPolicyRulePeerKind) Valid() bool

Valid indicates whether the value is a known member of the NetworkPolicyRulePeerKind enum.

type NetworkPolicyRuleRow added in v1.1.0

type NetworkPolicyRuleRow struct {
	ID                    uuid.UUID       `json:"id"`
	NetworkPolicyID       uuid.UUID       `json:"network_policy_id"`
	Direction             string          `json:"direction"`
	PeerKind              string          `json:"peer_kind"`
	PeerPodSelector       json.RawMessage `json:"peer_pod_selector,omitempty"`
	PeerNamespaceSelector json.RawMessage `json:"peer_namespace_selector,omitempty"`
	PeerIPBlockCIDR       string          `json:"peer_ip_block_cidr,omitempty"`
	PeerIPBlockExcept     json.RawMessage `json:"peer_ip_block_except,omitempty"`
	Ports                 json.RawMessage `json:"ports,omitempty"`
}

NetworkPolicyRuleRow is the persisted view of one ingress or egress rule on a NetworkPolicy. Direction is "ingress" or "egress"; PeerKind is "selector" or "ip_block". Non-applicable fields are zero-valued.

type NetworkPolicyStore added in v1.6.2

type NetworkPolicyStore interface {
	// ListNetworkPoliciesByCluster returns a page of network policies for
	// the given cluster, filtered and sorted per filter/page. The optional
	// namespace filter moved from positional arg into filter.NamespaceID.
	ListNetworkPoliciesByCluster(
		ctx context.Context,
		clusterID uuid.UUID,
		filter NetworkPolicyListFilter,
		page ListPage,
	) ([]NetworkPolicyRow, string, error)

	// GetNetworkPolicy fetches a network policy by stable UUID.
	// Returns ErrNotFound when the row is absent.
	GetNetworkPolicy(ctx context.Context, id uuid.UUID) (NetworkPolicyRow, error)

	// ListNetworkPolicyRules returns all rules for a single network
	// policy, in stable insertion order.
	ListNetworkPolicyRules(ctx context.Context, policyID uuid.UUID) ([]NetworkPolicyRuleRow, error)

	// ListNetworkPoliciesForWorkload returns every NetworkPolicy in the
	// workload's namespace whose pod_selector matchLabels @> workloadLabels.
	// The empty pod_selector (`{}`) and a missing matchLabels key are treated
	// as "select everything" per the Kubernetes semantics. matchExpressions
	// support is deferred to P2.
	ListNetworkPoliciesForWorkload(ctx context.Context, namespaceID uuid.UUID, workloadLabels json.RawMessage) ([]NetworkPolicyRow, error)

	// NetworkPolicyExists returns true when a row matching (clusterID,
	// namespaceID, name) already exists. Used by CreateNetworkPolicy to
	// distinguish 201 (insert) from 200 (update) without re-reading the
	// whole row.
	NetworkPolicyExists(ctx context.Context, clusterID, namespaceID uuid.UUID, name string) (bool, error)

	// UpsertNetworkPolicy upserts the policy and replaces its rules in one
	// transaction. Returns the stable row UUID. This is the canonical write
	// path (ADR-0038).
	UpsertNetworkPolicy(ctx context.Context, np NetworkPolicyRow, rules []NetworkPolicyRuleRow) (uuid.UUID, error)

	// SweepNetworkPoliciesByNamespaceWithCount deletes any policy in the
	// namespace not in the keep-list and returns the count of deleted rows.
	// Used by ReconcileNetworkPolicies (ADR-0038).
	SweepNetworkPoliciesByNamespaceWithCount(ctx context.Context, nsID uuid.UUID, keep []string) (int64, error)
}

NetworkPolicyStore covers Kubernetes NetworkPolicy rows and rules (flow-matrix P1, ADR-0038).

type Node

type Node struct {
	// AllocatableCpu CPU schedulable by Kubernetes after system reservations.
	AllocatableCpu              *string `json:"allocatable_cpu,omitempty"`
	AllocatableEphemeralStorage *string `json:"allocatable_ephemeral_storage,omitempty"`
	AllocatableMemory           *string `json:"allocatable_memory,omitempty"`
	AllocatablePods             *string `json:"allocatable_pods,omitempty"`

	// Annotations Free-form k/v for metadata not worth its own column. The
	// collector never writes this field.
	Annotations *map[string]string `json:"annotations,omitempty"`

	// Architecture CPU architecture. Open-ended; common values: amd64, arm64, ppc64le, s390x.
	Architecture *string `json:"architecture,omitempty"`

	// CapacityCpu Total CPU the node reports via status.capacity.cpu (quantity).
	CapacityCpu              *string            `json:"capacity_cpu,omitempty"`
	CapacityEphemeralStorage *string            `json:"capacity_ephemeral_storage,omitempty"`
	CapacityMemory           *string            `json:"capacity_memory,omitempty"`
	CapacityPods             *string            `json:"capacity_pods,omitempty"`
	ClusterId                openapi_types.UUID `json:"cluster_id"`

	// ClusterName Denormalized `clusters.name`. Null on orphans. See ADR-0027.
	ClusterName *string `json:"cluster_name,omitempty"`

	// Conditions Status conditions from the Node (Ready, MemoryPressure,
	// DiskPressure, PIDPressure, NetworkUnavailable). Each entry
	// preserves the Kubernetes shape so readers can filter by
	// `type`/`status` without reparse.
	Conditions *[]map[string]interface{} `json:"conditions,omitempty"`

	// ContainerRuntimeVersion e.g. `containerd://1.7.13`.
	ContainerRuntimeVersion *string    `json:"container_runtime_version,omitempty"`
	CreatedAt               *time.Time `json:"created_at,omitempty"`

	// Criticality Free-form operational tier label (`critical`, `high`,
	// `medium`, `low`).
	Criticality *string `json:"criticality,omitempty"`

	// DisplayName Human-friendly label, free-form.
	DisplayName *string `json:"display_name,omitempty"`

	// ExternalIp First ExternalIP from status.addresses, if any.
	ExternalIp *string `json:"external_ip,omitempty"`

	// HardwareModel Free-form bare-metal server model (e.g. "Dell PowerEdge
	// R640"). Complements the cloud-shaped `instance_type` set
	// by the collector; operator-owned.
	HardwareModel *string             `json:"hardware_model,omitempty"`
	Id            *openapi_types.UUID `json:"id,omitempty"`

	// InstanceType Value of the `node.kubernetes.io/instance-type` label
	// (e.g. `m6i.xlarge`, `Standard_D4s_v5`).
	InstanceType *string `json:"instance_type,omitempty"`

	// InternalIp Primary InternalIP address from status.addresses.
	InternalIp       *string `json:"internal_ip,omitempty"`
	KernelVersion    *string `json:"kernel_version,omitempty"`
	KubeProxyVersion *string `json:"kube_proxy_version,omitempty"`

	// KubeletVersion Kubelet git version as reported by Kubernetes (e.g. "v1.29.5").
	KubeletVersion *string `json:"kubelet_version,omitempty"`

	// Labels Arbitrary user-supplied string key/value labels.
	Labels *map[string]string `json:"labels,omitempty"`

	// Layer Always `infrastructure_physical` for Node. Set by the server.
	Layer *Layer `json:"layer,omitempty"`
	Name  string `json:"name"`

	// Notes Long-form prose.
	Notes *string `json:"notes,omitempty"`

	// OperatingSystem OS family as reported by Kubernetes (`linux`, `windows`).
	OperatingSystem *string `json:"operating_system,omitempty"`

	// OsImage Node OS image string (e.g. "Ubuntu 22.04.3 LTS").
	OsImage *string `json:"os_image,omitempty"`

	// Owner Free-form handle for the team / on-call that owns this
	// node. Surfaced on the detail page so incident responders
	// know who to wake up.
	Owner   *string `json:"owner,omitempty"`
	PodCidr *string `json:"pod_cidr,omitempty"`

	// ProviderId Cloud provider identifier from spec.providerID
	// (e.g. `aws:///eu-west-1a/i-0abc1234567890def`).
	ProviderId *string `json:"provider_id,omitempty"`

	// Ready Convenience boolean derived from the `Ready` status condition.
	// The full condition (with reason/lastTransitionTime) is in the
	// `conditions` array.
	Ready *bool `json:"ready,omitempty"`

	// Role Node role derived from `node-role.kubernetes.io/*` labels.
	// Common values: `control-plane`, `worker`, `etcd`.
	Role *string `json:"role,omitempty"`

	// RunbookUrl Link to the owning team's runbook for this node.
	RunbookUrl *string `json:"runbook_url,omitempty"`

	// Taints Scheduling taints from spec.taints. Each entry has
	// `{key, value, effect}` — a pod lands here only if it
	// tolerates every taint whose effect is NoSchedule/NoExecute.
	Taints *[]map[string]interface{} `json:"taints,omitempty"`

	// Unschedulable spec.unschedulable — the kubectl `cordon` flag.
	Unschedulable *bool      `json:"unschedulable,omitempty"`
	UpdatedAt     *time.Time `json:"updated_at,omitempty"`

	// Zone Value of the `topology.kubernetes.io/zone` label
	// (e.g. `eu-west-1a`).
	Zone *string `json:"zone,omitempty"`
}

Node defines model for Node.

type NodeClusterIdFilter

type NodeClusterIdFilter = openapi_types.UUID

NodeClusterIdFilter defines model for NodeClusterIdFilter.

type NodeCreate

type NodeCreate struct {
	// AllocatableCpu CPU schedulable by Kubernetes after system reservations.
	AllocatableCpu              *string `json:"allocatable_cpu,omitempty"`
	AllocatableEphemeralStorage *string `json:"allocatable_ephemeral_storage,omitempty"`
	AllocatableMemory           *string `json:"allocatable_memory,omitempty"`
	AllocatablePods             *string `json:"allocatable_pods,omitempty"`

	// Annotations Free-form k/v for metadata not worth its own column. The
	// collector never writes this field.
	Annotations *map[string]string `json:"annotations,omitempty"`

	// Architecture CPU architecture. Open-ended; common values: amd64, arm64, ppc64le, s390x.
	Architecture *string `json:"architecture,omitempty"`

	// CapacityCpu Total CPU the node reports via status.capacity.cpu (quantity).
	CapacityCpu              *string `json:"capacity_cpu,omitempty"`
	CapacityEphemeralStorage *string `json:"capacity_ephemeral_storage,omitempty"`
	CapacityMemory           *string `json:"capacity_memory,omitempty"`
	CapacityPods             *string `json:"capacity_pods,omitempty"`

	// ClusterId Parent cluster id. Immutable after creation; the cluster must
	// already exist or the create returns 404.
	ClusterId openapi_types.UUID `json:"cluster_id"`

	// Conditions Status conditions from the Node (Ready, MemoryPressure,
	// DiskPressure, PIDPressure, NetworkUnavailable). Each entry
	// preserves the Kubernetes shape so readers can filter by
	// `type`/`status` without reparse.
	Conditions *[]map[string]interface{} `json:"conditions,omitempty"`

	// ContainerRuntimeVersion e.g. `containerd://1.7.13`.
	ContainerRuntimeVersion *string `json:"container_runtime_version,omitempty"`

	// Criticality Free-form operational tier label (`critical`, `high`,
	// `medium`, `low`).
	Criticality *string `json:"criticality,omitempty"`

	// DisplayName Human-friendly label, free-form.
	DisplayName *string `json:"display_name,omitempty"`

	// ExternalIp First ExternalIP from status.addresses, if any.
	ExternalIp *string `json:"external_ip,omitempty"`

	// HardwareModel Free-form bare-metal server model (e.g. "Dell PowerEdge
	// R640"). Complements the cloud-shaped `instance_type` set
	// by the collector; operator-owned.
	HardwareModel *string `json:"hardware_model,omitempty"`

	// InstanceType Value of the `node.kubernetes.io/instance-type` label
	// (e.g. `m6i.xlarge`, `Standard_D4s_v5`).
	InstanceType *string `json:"instance_type,omitempty"`

	// InternalIp Primary InternalIP address from status.addresses.
	InternalIp       *string `json:"internal_ip,omitempty"`
	KernelVersion    *string `json:"kernel_version,omitempty"`
	KubeProxyVersion *string `json:"kube_proxy_version,omitempty"`

	// KubeletVersion Kubelet git version as reported by Kubernetes (e.g. "v1.29.5").
	KubeletVersion *string `json:"kubelet_version,omitempty"`

	// Labels Arbitrary user-supplied string key/value labels.
	Labels *map[string]string `json:"labels,omitempty"`

	// Name Kubernetes node name (DNS-subdomain style). Unique per cluster.
	// Immutable after creation.
	Name string `json:"name"`

	// Notes Long-form prose.
	Notes *string `json:"notes,omitempty"`

	// OperatingSystem OS family as reported by Kubernetes (`linux`, `windows`).
	OperatingSystem *string `json:"operating_system,omitempty"`

	// OsImage Node OS image string (e.g. "Ubuntu 22.04.3 LTS").
	OsImage *string `json:"os_image,omitempty"`

	// Owner Free-form handle for the team / on-call that owns this
	// node. Surfaced on the detail page so incident responders
	// know who to wake up.
	Owner   *string `json:"owner,omitempty"`
	PodCidr *string `json:"pod_cidr,omitempty"`

	// ProviderId Cloud provider identifier from spec.providerID
	// (e.g. `aws:///eu-west-1a/i-0abc1234567890def`).
	ProviderId *string `json:"provider_id,omitempty"`

	// Ready Convenience boolean derived from the `Ready` status condition.
	// The full condition (with reason/lastTransitionTime) is in the
	// `conditions` array.
	Ready *bool `json:"ready,omitempty"`

	// Role Node role derived from `node-role.kubernetes.io/*` labels.
	// Common values: `control-plane`, `worker`, `etcd`.
	Role *string `json:"role,omitempty"`

	// RunbookUrl Link to the owning team's runbook for this node.
	RunbookUrl *string `json:"runbook_url,omitempty"`

	// Taints Scheduling taints from spec.taints. Each entry has
	// `{key, value, effect}` — a pod lands here only if it
	// tolerates every taint whose effect is NoSchedule/NoExecute.
	Taints *[]map[string]interface{} `json:"taints,omitempty"`

	// Unschedulable spec.unschedulable — the kubectl `cordon` flag.
	Unschedulable *bool `json:"unschedulable,omitempty"`

	// Zone Value of the `topology.kubernetes.io/zone` label
	// (e.g. `eu-west-1a`).
	Zone *string `json:"zone,omitempty"`
}

NodeCreate defines model for NodeCreate.

type NodeId

type NodeId = openapi_types.UUID

NodeId defines model for NodeId.

type NodeImage added in v1.7.0

type NodeImage struct {
	ProviderVMID string `json:"provider_vm_id"`
	ImageID      string `json:"image_id"`
	ImageName    string `json:"image_name"`
}

NodeImage is one (provider VM id → OS image) mapping reported by the VM collector for a Kubernetes node VM. The server matches ProviderVMID against nodes.provider_id (substring) to backfill the node's OS image (ADR-0040). Vendor-neutral: this is pure CMDB inventory.

type NodeList

type NodeList struct {
	Items []Node `json:"items"`

	// NextCursor Opaque cursor to pass as `?cursor=` to fetch the next page.
	// Absent or null when no more pages remain.
	NextCursor *string `json:"next_cursor,omitempty"`
}

NodeList Paged list of nodes.

type NodeListFilter added in v1.10.0

type NodeListFilter struct {
	ClusterID *uuid.UUID
	// Name is the uniform name= filter: ci substring, or anchored
	// glob when the term contains `*` (spec 2026-07-10).
	Name              *string
	IncludeTerminated bool
}

NodeListFilter — nil fields are ignored; set fields AND-combine (same contract as PodListFilter).

type NodeMutable

type NodeMutable struct {
	// AllocatableCpu CPU schedulable by Kubernetes after system reservations.
	AllocatableCpu              *string `json:"allocatable_cpu,omitempty"`
	AllocatableEphemeralStorage *string `json:"allocatable_ephemeral_storage,omitempty"`
	AllocatableMemory           *string `json:"allocatable_memory,omitempty"`
	AllocatablePods             *string `json:"allocatable_pods,omitempty"`

	// Annotations Free-form k/v for metadata not worth its own column. The
	// collector never writes this field.
	Annotations *map[string]string `json:"annotations,omitempty"`

	// Architecture CPU architecture. Open-ended; common values: amd64, arm64, ppc64le, s390x.
	Architecture *string `json:"architecture,omitempty"`

	// CapacityCpu Total CPU the node reports via status.capacity.cpu (quantity).
	CapacityCpu              *string `json:"capacity_cpu,omitempty"`
	CapacityEphemeralStorage *string `json:"capacity_ephemeral_storage,omitempty"`
	CapacityMemory           *string `json:"capacity_memory,omitempty"`
	CapacityPods             *string `json:"capacity_pods,omitempty"`

	// Conditions Status conditions from the Node (Ready, MemoryPressure,
	// DiskPressure, PIDPressure, NetworkUnavailable). Each entry
	// preserves the Kubernetes shape so readers can filter by
	// `type`/`status` without reparse.
	Conditions *[]map[string]interface{} `json:"conditions,omitempty"`

	// ContainerRuntimeVersion e.g. `containerd://1.7.13`.
	ContainerRuntimeVersion *string `json:"container_runtime_version,omitempty"`

	// Criticality Free-form operational tier label (`critical`, `high`,
	// `medium`, `low`).
	Criticality *string `json:"criticality,omitempty"`

	// DisplayName Human-friendly label, free-form.
	DisplayName *string `json:"display_name,omitempty"`

	// ExternalIp First ExternalIP from status.addresses, if any.
	ExternalIp *string `json:"external_ip,omitempty"`

	// HardwareModel Free-form bare-metal server model (e.g. "Dell PowerEdge
	// R640"). Complements the cloud-shaped `instance_type` set
	// by the collector; operator-owned.
	HardwareModel *string `json:"hardware_model,omitempty"`

	// InstanceType Value of the `node.kubernetes.io/instance-type` label
	// (e.g. `m6i.xlarge`, `Standard_D4s_v5`).
	InstanceType *string `json:"instance_type,omitempty"`

	// InternalIp Primary InternalIP address from status.addresses.
	InternalIp       *string `json:"internal_ip,omitempty"`
	KernelVersion    *string `json:"kernel_version,omitempty"`
	KubeProxyVersion *string `json:"kube_proxy_version,omitempty"`

	// KubeletVersion Kubelet git version as reported by Kubernetes (e.g. "v1.29.5").
	KubeletVersion *string `json:"kubelet_version,omitempty"`

	// Labels Arbitrary user-supplied string key/value labels.
	Labels *map[string]string `json:"labels,omitempty"`

	// Notes Long-form prose.
	Notes *string `json:"notes,omitempty"`

	// OperatingSystem OS family as reported by Kubernetes (`linux`, `windows`).
	OperatingSystem *string `json:"operating_system,omitempty"`

	// OsImage Node OS image string (e.g. "Ubuntu 22.04.3 LTS").
	OsImage *string `json:"os_image,omitempty"`

	// Owner Free-form handle for the team / on-call that owns this
	// node. Surfaced on the detail page so incident responders
	// know who to wake up.
	Owner   *string `json:"owner,omitempty"`
	PodCidr *string `json:"pod_cidr,omitempty"`

	// ProviderId Cloud provider identifier from spec.providerID
	// (e.g. `aws:///eu-west-1a/i-0abc1234567890def`).
	ProviderId *string `json:"provider_id,omitempty"`

	// Ready Convenience boolean derived from the `Ready` status condition.
	// The full condition (with reason/lastTransitionTime) is in the
	// `conditions` array.
	Ready *bool `json:"ready,omitempty"`

	// Role Node role derived from `node-role.kubernetes.io/*` labels.
	// Common values: `control-plane`, `worker`, `etcd`.
	Role *string `json:"role,omitempty"`

	// RunbookUrl Link to the owning team's runbook for this node.
	RunbookUrl *string `json:"runbook_url,omitempty"`

	// Taints Scheduling taints from spec.taints. Each entry has
	// `{key, value, effect}` — a pod lands here only if it
	// tolerates every taint whose effect is NoSchedule/NoExecute.
	Taints *[]map[string]interface{} `json:"taints,omitempty"`

	// Unschedulable spec.unschedulable — the kubectl `cordon` flag.
	Unschedulable *bool `json:"unschedulable,omitempty"`

	// Zone Value of the `topology.kubernetes.io/zone` label
	// (e.g. `eu-west-1a`).
	Zone *string `json:"zone,omitempty"`
}

NodeMutable Fields on a Node that clients may set and later update. Modelled on a logical-server entity, with Kubernetes-specific additions (role, taints, conditions, the full OS stack). Curated operator-owned fields (`owner`, `criticality`, `notes`, `runbook_url`, `annotations`, `hardware_model`) are populated by editors / admins through the detail page; the collector never writes them.

type NodeStore added in v1.6.2

type NodeStore interface {
	// CreateNode inserts a new node. Returns ErrNotFound when the parent
	// cluster does not exist; ErrConflict when (cluster_id, name) already
	// has a node.
	CreateNode(ctx context.Context, in NodeCreate) (Node, error)

	// GetNode fetches a node by id. Returns ErrNotFound if absent.
	GetNode(ctx context.Context, id uuid.UUID) (Node, error)

	// ListNodes returns a paged list of nodes matching filter, sorted by
	// page.Sort/page.Order. Unknown sort keys → ErrInvalidSort; mismatched
	// cursor → ErrInvalidCursor.
	ListNodes(ctx context.Context, filter NodeListFilter, page ListPage) (items []Node, nextCursor string, err error)

	// UpdateNode applies the merge-patch fields set in in. Returns
	// ErrNotFound if the node does not exist.
	UpdateNode(ctx context.Context, id uuid.UUID, in NodeUpdate) (Node, error)

	// DeleteNode removes a node by id. Returns ErrNotFound if absent.
	DeleteNode(ctx context.Context, id uuid.UUID) error

	// UpsertNode inserts a node when no row exists for (cluster_id, name),
	// or updates the mutable fields of the existing row when it does. The
	// returned Node always reflects the post-operation state. The second
	// return value classifies the operation for audit filtering (ADR-0024):
	// OutcomeInserted for a fresh insert, OutcomeBusinessChanged when a
	// business field changed, OutcomeNoChange when only clock fields moved.
	// Returns ErrNotFound if the parent cluster does not exist.
	UpsertNode(ctx context.Context, in NodeCreate) (Node, UpsertOutcome, error)

	// DeleteNodesNotIn removes every node of the given cluster whose name is
	// not in keepNames. When keepNames is empty the entire set of nodes for
	// that cluster is removed. Returns the number of rows deleted.
	DeleteNodesNotIn(ctx context.Context, clusterID uuid.UUID, keepNames []string) (int64, error)

	// BackfillNodeImages sets image_id/image_name on every node whose
	// provider_id contains a reported provider_vm_id (substring match).
	// Idempotent: a node is updated only when a value actually changes.
	// Returns matched (nodes whose provider_id matched a mapping) and
	// updated (nodes whose image fields actually changed). Empty image
	// strings are stored as NULL. Used by the vm-collector node-image
	// ingest endpoint (ADR-0040).
	BackfillNodeImages(ctx context.Context, images []NodeImage) (matched, updated int, err error)
}

NodeStore covers node CRUD, upsert, and reconcile.

type NodeUpdate

type NodeUpdate = NodeMutable

NodeUpdate Fields on a Node that clients may set and later update. Modelled on a logical-server entity, with Kubernetes-specific additions (role, taints, conditions, the full OS stack). Curated operator-owned fields (`owner`, `criticality`, `notes`, `runbook_url`, `annotations`, `hardware_model`) are populated by editors / admins through the detail page; the collector never writes them.

type NotFound

type NotFound = Problem

NotFound RFC 7807 problem details.

type NotFoundApplicationProblemPlusJSONResponse

type NotFoundApplicationProblemPlusJSONResponse Problem

type OSImage added in v1.7.0

type OSImage struct {
	ImageName string   `json:"image_name"`
	ImageIDs  []string `json:"image_ids"`
	VMCount   int      `json:"vm_count"`
	NodeCount int      `json:"node_count"`
}

OSImage is the aggregated OS-image inventory view returned by ListOSImages (ADR-0040). Counts how many VMs and nodes share the same image name, grouped across the fleet.

type OSImageStore added in v1.7.0

type OSImageStore interface {
	// ListOSImages returns one row per distinct image_name referenced by a
	// non-terminated VM or an active node, with the distinct image ids and
	// per-source counts. Ordered by image_name.
	ListOSImages(ctx context.Context) ([]OSImage, error)
}

OSImageStore exposes the deduplicated inventory of OS images in service (cloud VMs ∪ cluster nodes), keyed by image name (ADR-0040).

type OidcAuthStateInsert

type OidcAuthStateInsert struct {
	State        string
	CodeVerifier string
	Nonce        string
	CreatedAt    time.Time
	ExpiresAt    time.Time
}

OidcAuthStateInsert is the transient row stashed during an outbound OIDC redirect, consumed on the inbound callback.

type OidcAuthorize302Response

type OidcAuthorize302Response struct {
	Headers OidcAuthorize302ResponseHeaders
}

func (OidcAuthorize302Response) VisitOidcAuthorizeResponse

func (response OidcAuthorize302Response) VisitOidcAuthorizeResponse(w http.ResponseWriter) error

type OidcAuthorize302ResponseHeaders

type OidcAuthorize302ResponseHeaders struct {
	Location *string
}

type OidcAuthorize404Response

type OidcAuthorize404Response struct {
}

func (OidcAuthorize404Response) VisitOidcAuthorizeResponse

func (response OidcAuthorize404Response) VisitOidcAuthorizeResponse(w http.ResponseWriter) error

type OidcAuthorizeRequestObject

type OidcAuthorizeRequestObject struct {
}

type OidcAuthorizeResponseObject

type OidcAuthorizeResponseObject interface {
	VisitOidcAuthorizeResponse(w http.ResponseWriter) error
}

type OidcCallback302Response

type OidcCallback302Response struct {
	Headers OidcCallback302ResponseHeaders
}

func (OidcCallback302Response) VisitOidcCallbackResponse

func (response OidcCallback302Response) VisitOidcCallbackResponse(w http.ResponseWriter) error

type OidcCallback302ResponseHeaders

type OidcCallback302ResponseHeaders struct {
	Location *string
}

type OidcCallbackParams

type OidcCallbackParams struct {
	Code  string `form:"code" json:"code"`
	State string `form:"state" json:"state"`
}

OidcCallbackParams defines parameters for OidcCallback.

type OidcCallbackRequestObject

type OidcCallbackRequestObject struct {
	Params OidcCallbackParams
}

type OidcCallbackResponseObject

type OidcCallbackResponseObject interface {
	VisitOidcCallbackResponse(w http.ResponseWriter) error
}

type PatchImageOriginMapping200JSONResponse added in v0.30.0

type PatchImageOriginMapping200JSONResponse ImageOriginMapping

func (PatchImageOriginMapping200JSONResponse) VisitPatchImageOriginMappingResponse added in v0.30.0

func (response PatchImageOriginMapping200JSONResponse) VisitPatchImageOriginMappingResponse(w http.ResponseWriter) error

type PatchImageOriginMapping400ApplicationProblemPlusJSONResponse added in v0.30.0

type PatchImageOriginMapping400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (PatchImageOriginMapping400ApplicationProblemPlusJSONResponse) VisitPatchImageOriginMappingResponse added in v0.30.0

func (response PatchImageOriginMapping400ApplicationProblemPlusJSONResponse) VisitPatchImageOriginMappingResponse(w http.ResponseWriter) error

type PatchImageOriginMapping401ApplicationProblemPlusJSONResponse added in v0.30.0

type PatchImageOriginMapping401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (PatchImageOriginMapping401ApplicationProblemPlusJSONResponse) VisitPatchImageOriginMappingResponse added in v0.30.0

func (response PatchImageOriginMapping401ApplicationProblemPlusJSONResponse) VisitPatchImageOriginMappingResponse(w http.ResponseWriter) error

type PatchImageOriginMapping403ApplicationProblemPlusJSONResponse added in v0.30.0

type PatchImageOriginMapping403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (PatchImageOriginMapping403ApplicationProblemPlusJSONResponse) VisitPatchImageOriginMappingResponse added in v0.30.0

func (response PatchImageOriginMapping403ApplicationProblemPlusJSONResponse) VisitPatchImageOriginMappingResponse(w http.ResponseWriter) error

type PatchImageOriginMapping404ApplicationProblemPlusJSONResponse added in v0.30.0

type PatchImageOriginMapping404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (PatchImageOriginMapping404ApplicationProblemPlusJSONResponse) VisitPatchImageOriginMappingResponse added in v0.30.0

func (response PatchImageOriginMapping404ApplicationProblemPlusJSONResponse) VisitPatchImageOriginMappingResponse(w http.ResponseWriter) error

type PatchImageOriginMappingJSONRequestBody added in v0.30.0

type PatchImageOriginMappingJSONRequestBody = ImageOriginMappingPatch

PatchImageOriginMappingJSONRequestBody defines body for PatchImageOriginMapping for application/json ContentType.

type PatchImageOriginMappingRequestObject added in v0.30.0

type PatchImageOriginMappingRequestObject struct {
	ImageName string `json:"image_name"`
	Body      *PatchImageOriginMappingJSONRequestBody
}

type PatchImageOriginMappingResponseObject added in v0.30.0

type PatchImageOriginMappingResponseObject interface {
	VisitPatchImageOriginMappingResponse(w http.ResponseWriter) error
}

type PatchImageRegistry200JSONResponse

type PatchImageRegistry200JSONResponse ImageRegistry

func (PatchImageRegistry200JSONResponse) VisitPatchImageRegistryResponse

func (response PatchImageRegistry200JSONResponse) VisitPatchImageRegistryResponse(w http.ResponseWriter) error

type PatchImageRegistry401ApplicationProblemPlusJSONResponse

type PatchImageRegistry401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (PatchImageRegistry401ApplicationProblemPlusJSONResponse) VisitPatchImageRegistryResponse

func (response PatchImageRegistry401ApplicationProblemPlusJSONResponse) VisitPatchImageRegistryResponse(w http.ResponseWriter) error

type PatchImageRegistry403ApplicationProblemPlusJSONResponse

type PatchImageRegistry403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (PatchImageRegistry403ApplicationProblemPlusJSONResponse) VisitPatchImageRegistryResponse

func (response PatchImageRegistry403ApplicationProblemPlusJSONResponse) VisitPatchImageRegistryResponse(w http.ResponseWriter) error

type PatchImageRegistry404ApplicationProblemPlusJSONResponse

type PatchImageRegistry404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (PatchImageRegistry404ApplicationProblemPlusJSONResponse) VisitPatchImageRegistryResponse

func (response PatchImageRegistry404ApplicationProblemPlusJSONResponse) VisitPatchImageRegistryResponse(w http.ResponseWriter) error

type PatchImageRegistryJSONRequestBody

type PatchImageRegistryJSONRequestBody = ImageRegistryPatch

PatchImageRegistryJSONRequestBody defines body for PatchImageRegistry for application/json ContentType.

type PatchImageRegistryRequestObject

type PatchImageRegistryRequestObject struct {
	Hostname   string `json:"hostname"`
	PathPrefix string `json:"path_prefix"`
	Body       *PatchImageRegistryJSONRequestBody
}

type PatchImageRegistryResponseObject

type PatchImageRegistryResponseObject interface {
	VisitPatchImageRegistryResponse(w http.ResponseWriter) error
}

type PayloadTooLarge added in v1.13.0

type PayloadTooLarge = Problem

PayloadTooLarge RFC 7807 problem details.

type PayloadTooLargeApplicationProblemPlusJSONResponse added in v1.13.0

type PayloadTooLargeApplicationProblemPlusJSONResponse Problem

type PersistentVolume

type PersistentVolume struct {
	// AccessModes Kubernetes access modes the PV exposes — any of
	// `ReadWriteOnce`, `ReadOnlyMany`, `ReadWriteMany`,
	// `ReadWriteOncePod`.
	AccessModes *[]string `json:"access_modes,omitempty"`

	// Capacity Declared capacity as reported by Kubernetes (e.g. `"10Gi"`).
	// Stored verbatim; conversion to bytes is a reader concern.
	Capacity *string `json:"capacity,omitempty"`

	// ClaimRefName Name of the bound PVC (spec.claimRef.name).
	ClaimRefName *string `json:"claim_ref_name,omitempty"`

	// ClaimRefNamespace Namespace of the bound PVC (spec.claimRef.namespace).
	ClaimRefNamespace *string            `json:"claim_ref_namespace,omitempty"`
	ClusterId         openapi_types.UUID `json:"cluster_id"`
	CreatedAt         *time.Time         `json:"created_at,omitempty"`

	// CsiDriver CSI driver name when the PV is CSI-backed (spec.csi.driver).
	// Null for in-tree / legacy volume sources.
	CsiDriver *string             `json:"csi_driver,omitempty"`
	Id        *openapi_types.UUID `json:"id,omitempty"`

	// Labels Arbitrary user-supplied string key/value labels.
	Labels *map[string]string `json:"labels,omitempty"`

	// Layer Always `infrastructure_physical` for PersistentVolume. Set by the server.
	Layer *Layer `json:"layer,omitempty"`
	Name  string `json:"name"`

	// Phase Kubernetes PV phase as last observed: Pending, Available, Bound,
	// Released, Failed.
	Phase *string `json:"phase,omitempty"`

	// ReclaimPolicy Retain / Delete / Recycle.
	ReclaimPolicy    *string    `json:"reclaim_policy,omitempty"`
	StorageClassName *string    `json:"storage_class_name,omitempty"`
	UpdatedAt        *time.Time `json:"updated_at,omitempty"`

	// VolumeHandle Concrete backing storage handle (spec.csi.volumeHandle) — the
	// CSI driver's identifier for the underlying disk / share.
	VolumeHandle *string `json:"volume_handle,omitempty"`
}

PersistentVolume defines model for PersistentVolume.

type PersistentVolumeClaim

type PersistentVolumeClaim struct {
	AccessModes *[]string `json:"access_modes,omitempty"`

	// BoundVolumeId FK to the PersistentVolume this PVC is bound to. Null for
	// Pending PVCs or if the PV row has been deleted
	// (ON DELETE SET NULL).
	BoundVolumeId *openapi_types.UUID `json:"bound_volume_id,omitempty"`

	// ClusterId Denormalized `namespaces.cluster_id`. Null on orphans. See ADR-0027.
	ClusterId *openapi_types.UUID `json:"cluster_id,omitempty"`

	// ClusterName Denormalized `clusters.name`. Null on orphans. See ADR-0027.
	ClusterName *string             `json:"cluster_name,omitempty"`
	CreatedAt   *time.Time          `json:"created_at,omitempty"`
	Id          *openapi_types.UUID `json:"id,omitempty"`

	// Labels Arbitrary user-supplied string key/value labels.
	Labels *map[string]string `json:"labels,omitempty"`

	// Layer Always `applicative` for PersistentVolumeClaim. Set by the server.
	Layer       *Layer             `json:"layer,omitempty"`
	Name        string             `json:"name"`
	NamespaceId openapi_types.UUID `json:"namespace_id"`

	// NamespaceName Denormalized `namespaces.name`. Null on orphans. See ADR-0027.
	NamespaceName *string `json:"namespace_name,omitempty"`

	// Phase Kubernetes PVC phase as last observed: Pending, Bound, Lost.
	Phase *string `json:"phase,omitempty"`

	// RequestedStorage Requested size (spec.resources.requests.storage), verbatim
	// (e.g. `"5Gi"`).
	RequestedStorage *string    `json:"requested_storage,omitempty"`
	StorageClassName *string    `json:"storage_class_name,omitempty"`
	UpdatedAt        *time.Time `json:"updated_at,omitempty"`

	// VolumeName Raw `spec.volumeName` — the PV name this claim is bound to.
	// Carries the string even when the corresponding PV row hasn't
	// been ingested yet.
	VolumeName *string `json:"volume_name,omitempty"`
}

PersistentVolumeClaim defines model for PersistentVolumeClaim.

type PersistentVolumeClaimCreate

type PersistentVolumeClaimCreate struct {
	AccessModes *[]string `json:"access_modes,omitempty"`

	// BoundVolumeId FK to the PersistentVolume this PVC is bound to. Null for
	// Pending PVCs or if the PV row has been deleted
	// (ON DELETE SET NULL).
	BoundVolumeId *openapi_types.UUID `json:"bound_volume_id,omitempty"`

	// Labels Arbitrary user-supplied string key/value labels.
	Labels *map[string]string `json:"labels,omitempty"`

	// Name Kubernetes PVC name (DNS-subdomain style). Unique per
	// namespace. Immutable after creation.
	Name string `json:"name"`

	// NamespaceId Parent namespace id. Immutable after creation; the namespace
	// must already exist or the create returns 404.
	NamespaceId openapi_types.UUID `json:"namespace_id"`

	// Phase Kubernetes PVC phase as last observed: Pending, Bound, Lost.
	Phase *string `json:"phase,omitempty"`

	// RequestedStorage Requested size (spec.resources.requests.storage), verbatim
	// (e.g. `"5Gi"`).
	RequestedStorage *string `json:"requested_storage,omitempty"`
	StorageClassName *string `json:"storage_class_name,omitempty"`

	// VolumeName Raw `spec.volumeName` — the PV name this claim is bound to.
	// Carries the string even when the corresponding PV row hasn't
	// been ingested yet.
	VolumeName *string `json:"volume_name,omitempty"`
}

PersistentVolumeClaimCreate defines model for PersistentVolumeClaimCreate.

type PersistentVolumeClaimId

type PersistentVolumeClaimId = openapi_types.UUID

PersistentVolumeClaimId defines model for PersistentVolumeClaimId.

type PersistentVolumeClaimList

type PersistentVolumeClaimList struct {
	Items []PersistentVolumeClaim `json:"items"`

	// NextCursor Opaque cursor to pass as `?cursor=` to fetch the next page.
	// Absent or null when no more pages remain.
	NextCursor *string `json:"next_cursor,omitempty"`
}

PersistentVolumeClaimList Paged list of persistent volume claims.

type PersistentVolumeClaimListFilter added in v1.10.0

type PersistentVolumeClaimListFilter struct {
	NamespaceID *uuid.UUID
	Name        *string
}

PersistentVolumeClaimListFilter is the predicate set accepted by ListPersistentVolumeClaims.

type PersistentVolumeClaimMutable

type PersistentVolumeClaimMutable struct {
	AccessModes *[]string `json:"access_modes,omitempty"`

	// BoundVolumeId FK to the PersistentVolume this PVC is bound to. Null for
	// Pending PVCs or if the PV row has been deleted
	// (ON DELETE SET NULL).
	BoundVolumeId *openapi_types.UUID `json:"bound_volume_id,omitempty"`

	// Labels Arbitrary user-supplied string key/value labels.
	Labels *map[string]string `json:"labels,omitempty"`

	// Phase Kubernetes PVC phase as last observed: Pending, Bound, Lost.
	Phase *string `json:"phase,omitempty"`

	// RequestedStorage Requested size (spec.resources.requests.storage), verbatim
	// (e.g. `"5Gi"`).
	RequestedStorage *string `json:"requested_storage,omitempty"`
	StorageClassName *string `json:"storage_class_name,omitempty"`

	// VolumeName Raw `spec.volumeName` — the PV name this claim is bound to.
	// Carries the string even when the corresponding PV row hasn't
	// been ingested yet.
	VolumeName *string `json:"volume_name,omitempty"`
}

PersistentVolumeClaimMutable Fields on a PVC that clients may set and later update.

type PersistentVolumeClaimNamespaceIdFilter

type PersistentVolumeClaimNamespaceIdFilter = openapi_types.UUID

PersistentVolumeClaimNamespaceIdFilter defines model for PersistentVolumeClaimNamespaceIdFilter.

type PersistentVolumeClaimStore added in v1.6.2

type PersistentVolumeClaimStore interface {
	// CreatePersistentVolumeClaim inserts a new PVC. Returns ErrNotFound
	// when the parent namespace or the bound volume does not exist;
	// ErrConflict when (namespace_id, name) already has a PVC.
	CreatePersistentVolumeClaim(ctx context.Context, in PersistentVolumeClaimCreate) (PersistentVolumeClaim, error)

	// GetPersistentVolumeClaim fetches a PVC by id.
	GetPersistentVolumeClaim(ctx context.Context, id uuid.UUID) (PersistentVolumeClaim, error)

	// ListPersistentVolumeClaims returns a cursor-paginated page of PVCs, optionally
	// filtered by namespace and/or name. See PersistentVolumeClaimListFilter for the
	// accepted predicates.
	ListPersistentVolumeClaims(
		ctx context.Context,
		filter PersistentVolumeClaimListFilter,
		page ListPage,
	) (items []PersistentVolumeClaim, nextCursor string, err error)

	// UpdatePersistentVolumeClaim applies merge-patch.
	UpdatePersistentVolumeClaim(ctx context.Context, id uuid.UUID, in PersistentVolumeClaimUpdate) (PersistentVolumeClaim, error)

	// DeletePersistentVolumeClaim removes by id.
	DeletePersistentVolumeClaim(ctx context.Context, id uuid.UUID) error

	// UpsertPersistentVolumeClaim mirrors UpsertPod; keyed on (namespace_id, name). The second
	// return value classifies the operation for audit filtering (ADR-0024):
	// OutcomeInserted for a fresh insert, OutcomeBusinessChanged when a
	// business field changed, OutcomeNoChange when only clock fields moved.
	UpsertPersistentVolumeClaim(ctx context.Context, in PersistentVolumeClaimCreate) (PersistentVolumeClaim, UpsertOutcome, error)

	// DeletePersistentVolumeClaimsNotIn mirrors DeletePodsNotIn.
	DeletePersistentVolumeClaimsNotIn(ctx context.Context, namespaceID uuid.UUID, keepNames []string) (int64, error)
}

PersistentVolumeClaimStore covers PVC CRUD, upsert, and reconcile.

type PersistentVolumeClaimUpdate

type PersistentVolumeClaimUpdate = PersistentVolumeClaimMutable

PersistentVolumeClaimUpdate Fields on a PVC that clients may set and later update.

type PersistentVolumeClusterIdFilter

type PersistentVolumeClusterIdFilter = openapi_types.UUID

PersistentVolumeClusterIdFilter defines model for PersistentVolumeClusterIdFilter.

type PersistentVolumeCreate

type PersistentVolumeCreate struct {
	// AccessModes Kubernetes access modes the PV exposes — any of
	// `ReadWriteOnce`, `ReadOnlyMany`, `ReadWriteMany`,
	// `ReadWriteOncePod`.
	AccessModes *[]string `json:"access_modes,omitempty"`

	// Capacity Declared capacity as reported by Kubernetes (e.g. `"10Gi"`).
	// Stored verbatim; conversion to bytes is a reader concern.
	Capacity *string `json:"capacity,omitempty"`

	// ClaimRefName Name of the bound PVC (spec.claimRef.name).
	ClaimRefName *string `json:"claim_ref_name,omitempty"`

	// ClaimRefNamespace Namespace of the bound PVC (spec.claimRef.namespace).
	ClaimRefNamespace *string `json:"claim_ref_namespace,omitempty"`

	// ClusterId Parent cluster id. Immutable after creation; the cluster must
	// already exist or the create returns 404.
	ClusterId openapi_types.UUID `json:"cluster_id"`

	// CsiDriver CSI driver name when the PV is CSI-backed (spec.csi.driver).
	// Null for in-tree / legacy volume sources.
	CsiDriver *string `json:"csi_driver,omitempty"`

	// Labels Arbitrary user-supplied string key/value labels.
	Labels *map[string]string `json:"labels,omitempty"`

	// Name Kubernetes PV name. Cluster-scoped, so unique per cluster.
	// Immutable after creation.
	Name string `json:"name"`

	// Phase Kubernetes PV phase as last observed: Pending, Available, Bound,
	// Released, Failed.
	Phase *string `json:"phase,omitempty"`

	// ReclaimPolicy Retain / Delete / Recycle.
	ReclaimPolicy    *string `json:"reclaim_policy,omitempty"`
	StorageClassName *string `json:"storage_class_name,omitempty"`

	// VolumeHandle Concrete backing storage handle (spec.csi.volumeHandle) — the
	// CSI driver's identifier for the underlying disk / share.
	VolumeHandle *string `json:"volume_handle,omitempty"`
}

PersistentVolumeCreate defines model for PersistentVolumeCreate.

type PersistentVolumeId

type PersistentVolumeId = openapi_types.UUID

PersistentVolumeId defines model for PersistentVolumeId.

type PersistentVolumeList

type PersistentVolumeList struct {
	Items []PersistentVolume `json:"items"`

	// NextCursor Opaque cursor to pass as `?cursor=` to fetch the next page.
	// Absent or null when no more pages remain.
	NextCursor *string `json:"next_cursor,omitempty"`
}

PersistentVolumeList Paged list of persistent volumes.

type PersistentVolumeListFilter added in v1.10.0

type PersistentVolumeListFilter struct {
	ClusterID *uuid.UUID
	Name      *string
}

PersistentVolumeListFilter is the predicate set accepted by ListPersistentVolumes.

type PersistentVolumeMutable

type PersistentVolumeMutable struct {
	// AccessModes Kubernetes access modes the PV exposes — any of
	// `ReadWriteOnce`, `ReadOnlyMany`, `ReadWriteMany`,
	// `ReadWriteOncePod`.
	AccessModes *[]string `json:"access_modes,omitempty"`

	// Capacity Declared capacity as reported by Kubernetes (e.g. `"10Gi"`).
	// Stored verbatim; conversion to bytes is a reader concern.
	Capacity *string `json:"capacity,omitempty"`

	// ClaimRefName Name of the bound PVC (spec.claimRef.name).
	ClaimRefName *string `json:"claim_ref_name,omitempty"`

	// ClaimRefNamespace Namespace of the bound PVC (spec.claimRef.namespace).
	ClaimRefNamespace *string `json:"claim_ref_namespace,omitempty"`

	// CsiDriver CSI driver name when the PV is CSI-backed (spec.csi.driver).
	// Null for in-tree / legacy volume sources.
	CsiDriver *string `json:"csi_driver,omitempty"`

	// Labels Arbitrary user-supplied string key/value labels.
	Labels *map[string]string `json:"labels,omitempty"`

	// Phase Kubernetes PV phase as last observed: Pending, Available, Bound,
	// Released, Failed.
	Phase *string `json:"phase,omitempty"`

	// ReclaimPolicy Retain / Delete / Recycle.
	ReclaimPolicy    *string `json:"reclaim_policy,omitempty"`
	StorageClassName *string `json:"storage_class_name,omitempty"`

	// VolumeHandle Concrete backing storage handle (spec.csi.volumeHandle) — the
	// CSI driver's identifier for the underlying disk / share.
	VolumeHandle *string `json:"volume_handle,omitempty"`
}

PersistentVolumeMutable Fields on a PersistentVolume that clients may set and later update.

type PersistentVolumeStore added in v1.6.2

type PersistentVolumeStore interface {
	// CreatePersistentVolume inserts a new cluster-scoped PV. Returns
	// ErrNotFound when the parent cluster does not exist; ErrConflict when
	// (cluster_id, name) already has a PV.
	CreatePersistentVolume(ctx context.Context, in PersistentVolumeCreate) (PersistentVolume, error)

	// GetPersistentVolume fetches a PV by id.
	GetPersistentVolume(ctx context.Context, id uuid.UUID) (PersistentVolume, error)

	// ListPersistentVolumes returns a cursor-paginated page of PVs, optionally
	// filtered by cluster and/or name. See PersistentVolumeListFilter for the
	// accepted predicates.
	ListPersistentVolumes(
		ctx context.Context,
		filter PersistentVolumeListFilter,
		page ListPage,
	) (items []PersistentVolume, nextCursor string, err error)

	// UpdatePersistentVolume applies merge-patch.
	UpdatePersistentVolume(ctx context.Context, id uuid.UUID, in PersistentVolumeUpdate) (PersistentVolume, error)

	// DeletePersistentVolume removes by id.
	DeletePersistentVolume(ctx context.Context, id uuid.UUID) error

	// UpsertPersistentVolume mirrors UpsertNode; keyed on (cluster_id, name). The second
	// return value classifies the operation for audit filtering (ADR-0024):
	// OutcomeInserted for a fresh insert, OutcomeBusinessChanged when a
	// business field changed, OutcomeNoChange when only clock fields moved.
	UpsertPersistentVolume(ctx context.Context, in PersistentVolumeCreate) (PersistentVolume, UpsertOutcome, error)

	// DeletePersistentVolumesNotIn removes cluster-scoped PVs whose name is
	// not in keepNames. An empty keep slice clears every PV in that cluster.
	DeletePersistentVolumesNotIn(ctx context.Context, clusterID uuid.UUID, keepNames []string) (int64, error)
}

PersistentVolumeStore covers cluster-scoped PV CRUD, upsert, and reconcile.

type PersistentVolumeUpdate

type PersistentVolumeUpdate = PersistentVolumeMutable

PersistentVolumeUpdate Fields on a PersistentVolume that clients may set and later update.

type Pod

type Pod struct {
	// ClusterId Denormalized `namespaces.cluster_id`. Null on orphans. See ADR-0027.
	ClusterId *openapi_types.UUID `json:"cluster_id,omitempty"`

	// ClusterName Denormalized `clusters.name`. Null on orphans. See ADR-0027.
	ClusterName *string `json:"cluster_name,omitempty"`

	// Containers Containers associated with the resource. For Pods this reflects the
	// live runtime (name, image, image_id from containerStatuses, init
	// flag); for Workloads it's the pod template's declared containers
	// (name, image, init). Opaque in v1: each entry's shape is additive,
	// so new collector-extracted fields don't require a spec bump.
	Containers *ContainerList `json:"containers,omitempty"`

	// ContainersVersions Map of container name to its latest-version info. Keys are absent when the image is not yet enriched (non-parseable tag, registry not in allowlist, or not yet processed).
	ContainersVersions *map[string]ContainerVersionInfo `json:"containers_versions,omitempty"`
	CreatedAt          *time.Time                       `json:"created_at,omitempty"`
	Id                 *openapi_types.UUID              `json:"id,omitempty"`

	// Labels Arbitrary user-supplied string key/value labels.
	Labels *map[string]string `json:"labels,omitempty"`

	// Layer Always `applicative` for Pod. Set by the server.
	Layer       *Layer             `json:"layer,omitempty"`
	Name        string             `json:"name"`
	NamespaceId openapi_types.UUID `json:"namespace_id"`

	// NamespaceName Denormalized `namespaces.name`. Null on orphans. See ADR-0027.
	NamespaceName *string `json:"namespace_name,omitempty"`

	// NodeName Name of the node the pod is scheduled on.
	NodeName *string `json:"node_name,omitempty"`

	// Phase Kubernetes pod phase as last observed: Pending, Running, Succeeded,
	// Failed, or Unknown. Open-ended to accommodate any additional phases.
	Phase *string `json:"phase,omitempty"`

	// PodIp Pod IP address (IPv4 or IPv6). Informational; not validated as an
	// IP literal.
	PodIp     *string    `json:"pod_ip,omitempty"`
	UpdatedAt *time.Time `json:"updated_at,omitempty"`

	// WorkloadId Top-level Workload that controls this pod (Deployment /
	// StatefulSet / DaemonSet). The collector walks the K8s
	// ownerReference chain — for Deployment-owned pods this resolves
	// Pod -> ReplicaSet -> Deployment. Null for pods with no
	// controller or with an owner kind longue-vue doesn't model yet
	// (e.g., Job, CronJob).
	WorkloadId *openapi_types.UUID `json:"workload_id,omitempty"`

	// WorkloadName Denormalized `workloads.name` (the controller that owns the pod).
	// Null when the pod is standalone, the workload row is gone, or the
	// ownerReferences walk did not resolve. See ADR-0027.
	WorkloadName *string `json:"workload_name,omitempty"`
}

Pod defines model for Pod.

type PodCreate

type PodCreate struct {
	// Containers Containers associated with the resource. For Pods this reflects the
	// live runtime (name, image, image_id from containerStatuses, init
	// flag); for Workloads it's the pod template's declared containers
	// (name, image, init). Opaque in v1: each entry's shape is additive,
	// so new collector-extracted fields don't require a spec bump.
	Containers *ContainerList `json:"containers,omitempty"`

	// ContainersVersions Map of container name to its latest-version info. Keys are absent when the image is not yet enriched (non-parseable tag, registry not in allowlist, or not yet processed).
	ContainersVersions *map[string]ContainerVersionInfo `json:"containers_versions,omitempty"`

	// Labels Arbitrary user-supplied string key/value labels.
	Labels *map[string]string `json:"labels,omitempty"`

	// Name Kubernetes pod name (DNS-subdomain style). Unique per namespace.
	// Immutable after creation.
	Name string `json:"name"`

	// NamespaceId Parent namespace id. Immutable after creation; the namespace
	// must already exist or the create returns 404.
	NamespaceId openapi_types.UUID `json:"namespace_id"`

	// NodeName Name of the node the pod is scheduled on.
	NodeName *string `json:"node_name,omitempty"`

	// Phase Kubernetes pod phase as last observed: Pending, Running, Succeeded,
	// Failed, or Unknown. Open-ended to accommodate any additional phases.
	Phase *string `json:"phase,omitempty"`

	// PodIp Pod IP address (IPv4 or IPv6). Informational; not validated as an
	// IP literal.
	PodIp *string `json:"pod_ip,omitempty"`

	// WorkloadId Top-level Workload that controls this pod (Deployment /
	// StatefulSet / DaemonSet). The collector walks the K8s
	// ownerReference chain — for Deployment-owned pods this resolves
	// Pod -> ReplicaSet -> Deployment. Null for pods with no
	// controller or with an owner kind longue-vue doesn't model yet
	// (e.g., Job, CronJob).
	WorkloadId *openapi_types.UUID `json:"workload_id,omitempty"`
}

PodCreate defines model for PodCreate.

type PodExtractRow added in v0.22.0

type PodExtractRow struct {
	Cluster      string              `json:"cluster"`
	Id           *openapi_types.UUID `json:"id,omitempty"`
	ImageMatches *string             `json:"image_matches,omitempty"`
	Name         string              `json:"name"`
	Namespace    string              `json:"namespace"`
	Node         *string             `json:"node,omitempty"`
	Phase        *string             `json:"phase,omitempty"`
	UpdatedAt    *time.Time          `json:"updated_at,omitempty"`
	WorkloadKind *string             `json:"workload_kind,omitempty"`
	WorkloadName *string             `json:"workload_name,omitempty"`
}

PodExtractRow defines model for PodExtractRow.

type PodId

type PodId = openapi_types.UUID

PodId defines model for PodId.

type PodImageFilter

type PodImageFilter = string

PodImageFilter defines model for PodImageFilter.

type PodList

type PodList struct {
	Items []Pod `json:"items"`

	// NextCursor Opaque cursor to pass as `?cursor=` to fetch the next page.
	// Absent or null when no more pages remain.
	NextCursor *string `json:"next_cursor,omitempty"`
}

PodList Paged list of pods.

type PodListFilter

type PodListFilter struct {
	NamespaceID *uuid.UUID
	NodeName    *string
	WorkloadID  *uuid.UUID
	// ImageSubstring matches any container (init included) whose `image`
	// field case-insensitively contains the substring.
	ImageSubstring *string
	// Name is the uniform name= filter: ci substring, or anchored
	// glob when the term contains `*` (spec 2026-07-10).
	Name *string
}

PodListFilter collects the optional filters accepted by ListPods. Nil fields are ignored; all present fields are AND-combined. Stored as a struct (not positional args) so future filters are additive.

type PodMutable

type PodMutable struct {
	// Containers Containers associated with the resource. For Pods this reflects the
	// live runtime (name, image, image_id from containerStatuses, init
	// flag); for Workloads it's the pod template's declared containers
	// (name, image, init). Opaque in v1: each entry's shape is additive,
	// so new collector-extracted fields don't require a spec bump.
	Containers *ContainerList `json:"containers,omitempty"`

	// ContainersVersions Map of container name to its latest-version info. Keys are absent when the image is not yet enriched (non-parseable tag, registry not in allowlist, or not yet processed).
	ContainersVersions *map[string]ContainerVersionInfo `json:"containers_versions,omitempty"`

	// Labels Arbitrary user-supplied string key/value labels.
	Labels *map[string]string `json:"labels,omitempty"`

	// NodeName Name of the node the pod is scheduled on.
	NodeName *string `json:"node_name,omitempty"`

	// Phase Kubernetes pod phase as last observed: Pending, Running, Succeeded,
	// Failed, or Unknown. Open-ended to accommodate any additional phases.
	Phase *string `json:"phase,omitempty"`

	// PodIp Pod IP address (IPv4 or IPv6). Informational; not validated as an
	// IP literal.
	PodIp *string `json:"pod_ip,omitempty"`

	// WorkloadId Top-level Workload that controls this pod (Deployment /
	// StatefulSet / DaemonSet). The collector walks the K8s
	// ownerReference chain — for Deployment-owned pods this resolves
	// Pod -> ReplicaSet -> Deployment. Null for pods with no
	// controller or with an owner kind longue-vue doesn't model yet
	// (e.g., Job, CronJob).
	WorkloadId *openapi_types.UUID `json:"workload_id,omitempty"`
}

PodMutable Fields on a Pod that clients may set and later update.

type PodNamespaceIdFilter

type PodNamespaceIdFilter = openapi_types.UUID

PodNamespaceIdFilter defines model for PodNamespaceIdFilter.

type PodNodeNameFilter

type PodNodeNameFilter = string

PodNodeNameFilter defines model for PodNodeNameFilter.

type PodStore added in v1.6.2

type PodStore interface {
	// CreatePod inserts a new pod. Returns ErrNotFound when the parent
	// namespace does not exist; ErrConflict when (namespace_id, name) already
	// has a pod.
	CreatePod(ctx context.Context, in PodCreate) (Pod, error)

	// GetPod fetches a pod by id. Returns ErrNotFound if absent.
	GetPod(ctx context.Context, id uuid.UUID) (Pod, error)

	// ListPods returns a paged list of pods matching filter, sorted by
	// page.Sort/page.Order. Unknown sort keys → ErrInvalidSort; mismatched
	// cursor → ErrInvalidCursor.
	ListPods(ctx context.Context, filter PodListFilter, page ListPage) (items []Pod, nextCursor string, err error)

	// UpdatePod applies the merge-patch fields set in in. Returns
	// ErrNotFound if the pod does not exist.
	UpdatePod(ctx context.Context, id uuid.UUID, in PodUpdate) (Pod, error)

	// DeletePod removes a pod by id. Returns ErrNotFound if absent.
	DeletePod(ctx context.Context, id uuid.UUID) error

	// UpsertPod mirrors UpsertNode, keyed on (namespace_id, name). The second
	// return value classifies the operation for audit filtering (ADR-0024):
	// OutcomeInserted for a fresh insert, OutcomeBusinessChanged when a
	// business field changed, OutcomeNoChange when only clock fields moved.
	UpsertPod(ctx context.Context, in PodCreate) (Pod, UpsertOutcome, error)

	// DeletePodsNotIn mirrors DeleteNodesNotIn, scoped to a single namespace.
	DeletePodsNotIn(ctx context.Context, namespaceID uuid.UUID, keepNames []string) (int64, error)
}

PodStore covers pod CRUD, upsert, and reconcile.

type PodUpdate

type PodUpdate = PodMutable

PodUpdate Fields on a Pod that clients may set and later update.

type PodWorkloadIdFilter

type PodWorkloadIdFilter = openapi_types.UUID

PodWorkloadIdFilter defines model for PodWorkloadIdFilter.

type PolicyReportCreate added in v1.13.0

type PolicyReportCreate struct {
	ClusterID    uuid.UUID       `json:"cluster_id"`
	NamespaceID  *uuid.UUID      `json:"namespace_id,omitempty"`
	Name         string          `json:"name"`
	ScopeKind    *string         `json:"scope_kind,omitempty"`
	ScopeName    *string         `json:"scope_name,omitempty"`
	SummaryPass  int             `json:"summary_pass"`
	SummaryFail  int             `json:"summary_fail"`
	SummaryWarn  int             `json:"summary_warn"`
	SummaryError int             `json:"summary_error"`
	SummarySkip  int             `json:"summary_skip"`
	ResultsRaw   json.RawMessage `json:"results_raw,omitempty"`
}

PolicyReportCreate is the request body for POST /v1/policy-reports. Only the fields required for creation are exposed; server-generated fields (id, reconcile_seen_at, source) are set by the handler.

type PolicyReportListFilter added in v1.13.0

type PolicyReportListFilter struct {
	ClusterID   *uuid.UUID
	NamespaceID *uuid.UUID
	Name        *string
	ScopeKind   *string
	ScopeName   *string
}

PolicyReportListFilter — nil fields are ignored; set fields AND-combine.

type PolicyReportRow added in v1.13.0

type PolicyReportRow struct {
	ID              uuid.UUID       `json:"id"`
	ClusterID       uuid.UUID       `json:"cluster_id"`
	NamespaceID     *uuid.UUID      `json:"namespace_id,omitempty"`
	Name            string          `json:"name"`
	ScopeKind       *string         `json:"scope_kind,omitempty"`
	ScopeName       *string         `json:"scope_name,omitempty"`
	SummaryPass     int             `json:"summary_pass"`
	SummaryFail     int             `json:"summary_fail"`
	SummaryWarn     int             `json:"summary_warn"`
	SummaryError    int             `json:"summary_error"`
	SummarySkip     int             `json:"summary_skip"`
	ResultsRaw      json.RawMessage `json:"results_raw,omitempty"`
	Source          string          `json:"source"`
	ReconcileSeenAt time.Time       `json:"reconcile_seen_at"`
}

PolicyReportRow is one row from the policy_reports table — a collected Kyverno PolicyReport (namespaced) or ClusterPolicyReport (cluster-scoped). ADR-0043.

type Problem

type Problem struct {
	Detail *string `json:"detail,omitempty"`

	// Errors Field-level validation errors, when applicable.
	Errors *[]struct {
		Field   string `json:"field"`
		Message string `json:"message"`
	} `json:"errors,omitempty"`
	Instance *string `json:"instance,omitempty"`
	Status   int     `json:"status"`
	Title    string  `json:"title"`
	Type     string  `json:"type"`
}

Problem RFC 7807 problem details.

type ReconcileClusterScoped

type ReconcileClusterScoped struct {
	ClusterId openapi_types.UUID `json:"cluster_id"`
	KeepNames []string           `json:"keep_names"`
}

ReconcileClusterScoped defines model for ReconcileClusterScoped.

type ReconcileIngresses200JSONResponse

type ReconcileIngresses200JSONResponse ReconcileResult

func (ReconcileIngresses200JSONResponse) VisitReconcileIngressesResponse

func (response ReconcileIngresses200JSONResponse) VisitReconcileIngressesResponse(w http.ResponseWriter) error

type ReconcileIngresses400ApplicationProblemPlusJSONResponse

type ReconcileIngresses400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (ReconcileIngresses400ApplicationProblemPlusJSONResponse) VisitReconcileIngressesResponse

func (response ReconcileIngresses400ApplicationProblemPlusJSONResponse) VisitReconcileIngressesResponse(w http.ResponseWriter) error

type ReconcileIngresses401ApplicationProblemPlusJSONResponse

type ReconcileIngresses401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (ReconcileIngresses401ApplicationProblemPlusJSONResponse) VisitReconcileIngressesResponse

func (response ReconcileIngresses401ApplicationProblemPlusJSONResponse) VisitReconcileIngressesResponse(w http.ResponseWriter) error

type ReconcileIngresses403ApplicationProblemPlusJSONResponse

type ReconcileIngresses403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (ReconcileIngresses403ApplicationProblemPlusJSONResponse) VisitReconcileIngressesResponse

func (response ReconcileIngresses403ApplicationProblemPlusJSONResponse) VisitReconcileIngressesResponse(w http.ResponseWriter) error

type ReconcileIngressesJSONRequestBody

type ReconcileIngressesJSONRequestBody = ReconcileNamespaceScoped

ReconcileIngressesJSONRequestBody defines body for ReconcileIngresses for application/json ContentType.

type ReconcileIngressesRequestObject

type ReconcileIngressesRequestObject struct {
	Body *ReconcileIngressesJSONRequestBody
}

type ReconcileIngressesResponseObject

type ReconcileIngressesResponseObject interface {
	VisitReconcileIngressesResponse(w http.ResponseWriter) error
}

type ReconcileNamespaceScoped

type ReconcileNamespaceScoped struct {
	KeepNames   []string           `json:"keep_names"`
	NamespaceId openapi_types.UUID `json:"namespace_id"`
}

ReconcileNamespaceScoped defines model for ReconcileNamespaceScoped.

type ReconcileNamespaces200JSONResponse

type ReconcileNamespaces200JSONResponse ReconcileResult

func (ReconcileNamespaces200JSONResponse) VisitReconcileNamespacesResponse

func (response ReconcileNamespaces200JSONResponse) VisitReconcileNamespacesResponse(w http.ResponseWriter) error

type ReconcileNamespaces400ApplicationProblemPlusJSONResponse

type ReconcileNamespaces400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (ReconcileNamespaces400ApplicationProblemPlusJSONResponse) VisitReconcileNamespacesResponse

func (response ReconcileNamespaces400ApplicationProblemPlusJSONResponse) VisitReconcileNamespacesResponse(w http.ResponseWriter) error

type ReconcileNamespaces401ApplicationProblemPlusJSONResponse

type ReconcileNamespaces401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (ReconcileNamespaces401ApplicationProblemPlusJSONResponse) VisitReconcileNamespacesResponse

func (response ReconcileNamespaces401ApplicationProblemPlusJSONResponse) VisitReconcileNamespacesResponse(w http.ResponseWriter) error

type ReconcileNamespaces403ApplicationProblemPlusJSONResponse

type ReconcileNamespaces403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (ReconcileNamespaces403ApplicationProblemPlusJSONResponse) VisitReconcileNamespacesResponse

func (response ReconcileNamespaces403ApplicationProblemPlusJSONResponse) VisitReconcileNamespacesResponse(w http.ResponseWriter) error

type ReconcileNamespacesJSONRequestBody

type ReconcileNamespacesJSONRequestBody = ReconcileClusterScoped

ReconcileNamespacesJSONRequestBody defines body for ReconcileNamespaces for application/json ContentType.

type ReconcileNamespacesRequestObject

type ReconcileNamespacesRequestObject struct {
	Body *ReconcileNamespacesJSONRequestBody
}

type ReconcileNamespacesResponseObject

type ReconcileNamespacesResponseObject interface {
	VisitReconcileNamespacesResponse(w http.ResponseWriter) error
}

type ReconcileNetworkPolicies200JSONResponse added in v1.4.0

type ReconcileNetworkPolicies200JSONResponse ReconcileResult

func (ReconcileNetworkPolicies200JSONResponse) VisitReconcileNetworkPoliciesResponse added in v1.4.0

func (response ReconcileNetworkPolicies200JSONResponse) VisitReconcileNetworkPoliciesResponse(w http.ResponseWriter) error

type ReconcileNetworkPolicies400ApplicationProblemPlusJSONResponse added in v1.4.0

type ReconcileNetworkPolicies400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (ReconcileNetworkPolicies400ApplicationProblemPlusJSONResponse) VisitReconcileNetworkPoliciesResponse added in v1.4.0

func (response ReconcileNetworkPolicies400ApplicationProblemPlusJSONResponse) VisitReconcileNetworkPoliciesResponse(w http.ResponseWriter) error

type ReconcileNetworkPolicies401ApplicationProblemPlusJSONResponse added in v1.4.0

type ReconcileNetworkPolicies401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (ReconcileNetworkPolicies401ApplicationProblemPlusJSONResponse) VisitReconcileNetworkPoliciesResponse added in v1.4.0

func (response ReconcileNetworkPolicies401ApplicationProblemPlusJSONResponse) VisitReconcileNetworkPoliciesResponse(w http.ResponseWriter) error

type ReconcileNetworkPolicies403ApplicationProblemPlusJSONResponse added in v1.4.0

type ReconcileNetworkPolicies403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (ReconcileNetworkPolicies403ApplicationProblemPlusJSONResponse) VisitReconcileNetworkPoliciesResponse added in v1.4.0

func (response ReconcileNetworkPolicies403ApplicationProblemPlusJSONResponse) VisitReconcileNetworkPoliciesResponse(w http.ResponseWriter) error

type ReconcileNetworkPoliciesJSONRequestBody added in v1.4.0

type ReconcileNetworkPoliciesJSONRequestBody = ReconcileNamespaceScoped

ReconcileNetworkPoliciesJSONRequestBody defines body for ReconcileNetworkPolicies for application/json ContentType.

type ReconcileNetworkPoliciesRequestObject added in v1.4.0

type ReconcileNetworkPoliciesRequestObject struct {
	Body *ReconcileNetworkPoliciesJSONRequestBody
}

type ReconcileNetworkPoliciesResponseObject added in v1.4.0

type ReconcileNetworkPoliciesResponseObject interface {
	VisitReconcileNetworkPoliciesResponse(w http.ResponseWriter) error
}

type ReconcileNodes200JSONResponse

type ReconcileNodes200JSONResponse ReconcileResult

func (ReconcileNodes200JSONResponse) VisitReconcileNodesResponse

func (response ReconcileNodes200JSONResponse) VisitReconcileNodesResponse(w http.ResponseWriter) error

type ReconcileNodes400ApplicationProblemPlusJSONResponse

type ReconcileNodes400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (ReconcileNodes400ApplicationProblemPlusJSONResponse) VisitReconcileNodesResponse

func (response ReconcileNodes400ApplicationProblemPlusJSONResponse) VisitReconcileNodesResponse(w http.ResponseWriter) error

type ReconcileNodes401ApplicationProblemPlusJSONResponse

type ReconcileNodes401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (ReconcileNodes401ApplicationProblemPlusJSONResponse) VisitReconcileNodesResponse

func (response ReconcileNodes401ApplicationProblemPlusJSONResponse) VisitReconcileNodesResponse(w http.ResponseWriter) error

type ReconcileNodes403ApplicationProblemPlusJSONResponse

type ReconcileNodes403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (ReconcileNodes403ApplicationProblemPlusJSONResponse) VisitReconcileNodesResponse

func (response ReconcileNodes403ApplicationProblemPlusJSONResponse) VisitReconcileNodesResponse(w http.ResponseWriter) error

type ReconcileNodesJSONRequestBody

type ReconcileNodesJSONRequestBody = ReconcileClusterScoped

ReconcileNodesJSONRequestBody defines body for ReconcileNodes for application/json ContentType.

type ReconcileNodesRequestObject

type ReconcileNodesRequestObject struct {
	Body *ReconcileNodesJSONRequestBody
}

type ReconcileNodesResponseObject

type ReconcileNodesResponseObject interface {
	VisitReconcileNodesResponse(w http.ResponseWriter) error
}

type ReconcilePersistentVolumeClaims200JSONResponse

type ReconcilePersistentVolumeClaims200JSONResponse ReconcileResult

func (ReconcilePersistentVolumeClaims200JSONResponse) VisitReconcilePersistentVolumeClaimsResponse

func (response ReconcilePersistentVolumeClaims200JSONResponse) VisitReconcilePersistentVolumeClaimsResponse(w http.ResponseWriter) error

type ReconcilePersistentVolumeClaims400ApplicationProblemPlusJSONResponse

type ReconcilePersistentVolumeClaims400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (ReconcilePersistentVolumeClaims400ApplicationProblemPlusJSONResponse) VisitReconcilePersistentVolumeClaimsResponse

func (response ReconcilePersistentVolumeClaims400ApplicationProblemPlusJSONResponse) VisitReconcilePersistentVolumeClaimsResponse(w http.ResponseWriter) error

type ReconcilePersistentVolumeClaims401ApplicationProblemPlusJSONResponse

type ReconcilePersistentVolumeClaims401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (ReconcilePersistentVolumeClaims401ApplicationProblemPlusJSONResponse) VisitReconcilePersistentVolumeClaimsResponse

func (response ReconcilePersistentVolumeClaims401ApplicationProblemPlusJSONResponse) VisitReconcilePersistentVolumeClaimsResponse(w http.ResponseWriter) error

type ReconcilePersistentVolumeClaims403ApplicationProblemPlusJSONResponse

type ReconcilePersistentVolumeClaims403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (ReconcilePersistentVolumeClaims403ApplicationProblemPlusJSONResponse) VisitReconcilePersistentVolumeClaimsResponse

func (response ReconcilePersistentVolumeClaims403ApplicationProblemPlusJSONResponse) VisitReconcilePersistentVolumeClaimsResponse(w http.ResponseWriter) error

type ReconcilePersistentVolumeClaimsJSONRequestBody

type ReconcilePersistentVolumeClaimsJSONRequestBody = ReconcileNamespaceScoped

ReconcilePersistentVolumeClaimsJSONRequestBody defines body for ReconcilePersistentVolumeClaims for application/json ContentType.

type ReconcilePersistentVolumeClaimsRequestObject

type ReconcilePersistentVolumeClaimsRequestObject struct {
	Body *ReconcilePersistentVolumeClaimsJSONRequestBody
}

type ReconcilePersistentVolumeClaimsResponseObject

type ReconcilePersistentVolumeClaimsResponseObject interface {
	VisitReconcilePersistentVolumeClaimsResponse(w http.ResponseWriter) error
}

type ReconcilePersistentVolumes200JSONResponse

type ReconcilePersistentVolumes200JSONResponse ReconcileResult

func (ReconcilePersistentVolumes200JSONResponse) VisitReconcilePersistentVolumesResponse

func (response ReconcilePersistentVolumes200JSONResponse) VisitReconcilePersistentVolumesResponse(w http.ResponseWriter) error

type ReconcilePersistentVolumes400ApplicationProblemPlusJSONResponse

type ReconcilePersistentVolumes400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (ReconcilePersistentVolumes400ApplicationProblemPlusJSONResponse) VisitReconcilePersistentVolumesResponse

func (response ReconcilePersistentVolumes400ApplicationProblemPlusJSONResponse) VisitReconcilePersistentVolumesResponse(w http.ResponseWriter) error

type ReconcilePersistentVolumes401ApplicationProblemPlusJSONResponse

type ReconcilePersistentVolumes401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (ReconcilePersistentVolumes401ApplicationProblemPlusJSONResponse) VisitReconcilePersistentVolumesResponse

func (response ReconcilePersistentVolumes401ApplicationProblemPlusJSONResponse) VisitReconcilePersistentVolumesResponse(w http.ResponseWriter) error

type ReconcilePersistentVolumes403ApplicationProblemPlusJSONResponse

type ReconcilePersistentVolumes403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (ReconcilePersistentVolumes403ApplicationProblemPlusJSONResponse) VisitReconcilePersistentVolumesResponse

func (response ReconcilePersistentVolumes403ApplicationProblemPlusJSONResponse) VisitReconcilePersistentVolumesResponse(w http.ResponseWriter) error

type ReconcilePersistentVolumesJSONRequestBody

type ReconcilePersistentVolumesJSONRequestBody = ReconcileClusterScoped

ReconcilePersistentVolumesJSONRequestBody defines body for ReconcilePersistentVolumes for application/json ContentType.

type ReconcilePersistentVolumesRequestObject

type ReconcilePersistentVolumesRequestObject struct {
	Body *ReconcilePersistentVolumesJSONRequestBody
}

type ReconcilePersistentVolumesResponseObject

type ReconcilePersistentVolumesResponseObject interface {
	VisitReconcilePersistentVolumesResponse(w http.ResponseWriter) error
}

type ReconcilePods200JSONResponse

type ReconcilePods200JSONResponse ReconcileResult

func (ReconcilePods200JSONResponse) VisitReconcilePodsResponse

func (response ReconcilePods200JSONResponse) VisitReconcilePodsResponse(w http.ResponseWriter) error

type ReconcilePods400ApplicationProblemPlusJSONResponse

type ReconcilePods400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (ReconcilePods400ApplicationProblemPlusJSONResponse) VisitReconcilePodsResponse

func (response ReconcilePods400ApplicationProblemPlusJSONResponse) VisitReconcilePodsResponse(w http.ResponseWriter) error

type ReconcilePods401ApplicationProblemPlusJSONResponse

type ReconcilePods401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (ReconcilePods401ApplicationProblemPlusJSONResponse) VisitReconcilePodsResponse

func (response ReconcilePods401ApplicationProblemPlusJSONResponse) VisitReconcilePodsResponse(w http.ResponseWriter) error

type ReconcilePods403ApplicationProblemPlusJSONResponse

type ReconcilePods403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (ReconcilePods403ApplicationProblemPlusJSONResponse) VisitReconcilePodsResponse

func (response ReconcilePods403ApplicationProblemPlusJSONResponse) VisitReconcilePodsResponse(w http.ResponseWriter) error

type ReconcilePodsJSONRequestBody

type ReconcilePodsJSONRequestBody = ReconcileNamespaceScoped

ReconcilePodsJSONRequestBody defines body for ReconcilePods for application/json ContentType.

type ReconcilePodsRequestObject

type ReconcilePodsRequestObject struct {
	Body *ReconcilePodsJSONRequestBody
}

type ReconcilePodsResponseObject

type ReconcilePodsResponseObject interface {
	VisitReconcilePodsResponse(w http.ResponseWriter) error
}

type ReconcileResult

type ReconcileResult struct {
	Deleted int64 `json:"deleted"`
}

ReconcileResult defines model for ReconcileResult.

type ReconcileServices200JSONResponse

type ReconcileServices200JSONResponse ReconcileResult

func (ReconcileServices200JSONResponse) VisitReconcileServicesResponse

func (response ReconcileServices200JSONResponse) VisitReconcileServicesResponse(w http.ResponseWriter) error

type ReconcileServices400ApplicationProblemPlusJSONResponse

type ReconcileServices400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (ReconcileServices400ApplicationProblemPlusJSONResponse) VisitReconcileServicesResponse

func (response ReconcileServices400ApplicationProblemPlusJSONResponse) VisitReconcileServicesResponse(w http.ResponseWriter) error

type ReconcileServices401ApplicationProblemPlusJSONResponse

type ReconcileServices401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (ReconcileServices401ApplicationProblemPlusJSONResponse) VisitReconcileServicesResponse

func (response ReconcileServices401ApplicationProblemPlusJSONResponse) VisitReconcileServicesResponse(w http.ResponseWriter) error

type ReconcileServices403ApplicationProblemPlusJSONResponse

type ReconcileServices403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (ReconcileServices403ApplicationProblemPlusJSONResponse) VisitReconcileServicesResponse

func (response ReconcileServices403ApplicationProblemPlusJSONResponse) VisitReconcileServicesResponse(w http.ResponseWriter) error

type ReconcileServicesJSONRequestBody

type ReconcileServicesJSONRequestBody = ReconcileNamespaceScoped

ReconcileServicesJSONRequestBody defines body for ReconcileServices for application/json ContentType.

type ReconcileServicesRequestObject

type ReconcileServicesRequestObject struct {
	Body *ReconcileServicesJSONRequestBody
}

type ReconcileServicesResponseObject

type ReconcileServicesResponseObject interface {
	VisitReconcileServicesResponse(w http.ResponseWriter) error
}

type ReconcileWorkloads

type ReconcileWorkloads struct {
	KeepKinds   []string           `json:"keep_kinds"`
	KeepNames   []string           `json:"keep_names"`
	NamespaceId openapi_types.UUID `json:"namespace_id"`
}

ReconcileWorkloads defines model for ReconcileWorkloads.

type ReconcileWorkloads200JSONResponse

type ReconcileWorkloads200JSONResponse ReconcileResult

func (ReconcileWorkloads200JSONResponse) VisitReconcileWorkloadsResponse

func (response ReconcileWorkloads200JSONResponse) VisitReconcileWorkloadsResponse(w http.ResponseWriter) error

type ReconcileWorkloads400ApplicationProblemPlusJSONResponse

type ReconcileWorkloads400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (ReconcileWorkloads400ApplicationProblemPlusJSONResponse) VisitReconcileWorkloadsResponse

func (response ReconcileWorkloads400ApplicationProblemPlusJSONResponse) VisitReconcileWorkloadsResponse(w http.ResponseWriter) error

type ReconcileWorkloads401ApplicationProblemPlusJSONResponse

type ReconcileWorkloads401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (ReconcileWorkloads401ApplicationProblemPlusJSONResponse) VisitReconcileWorkloadsResponse

func (response ReconcileWorkloads401ApplicationProblemPlusJSONResponse) VisitReconcileWorkloadsResponse(w http.ResponseWriter) error

type ReconcileWorkloads403ApplicationProblemPlusJSONResponse

type ReconcileWorkloads403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (ReconcileWorkloads403ApplicationProblemPlusJSONResponse) VisitReconcileWorkloadsResponse

func (response ReconcileWorkloads403ApplicationProblemPlusJSONResponse) VisitReconcileWorkloadsResponse(w http.ResponseWriter) error

type ReconcileWorkloadsJSONRequestBody

type ReconcileWorkloadsJSONRequestBody = ReconcileWorkloads

ReconcileWorkloadsJSONRequestBody defines body for ReconcileWorkloads for application/json ContentType.

type ReconcileWorkloadsRequestObject

type ReconcileWorkloadsRequestObject struct {
	Body *ReconcileWorkloadsJSONRequestBody
}

type ReconcileWorkloadsResponseObject

type ReconcileWorkloadsResponseObject interface {
	VisitReconcileWorkloadsResponse(w http.ResponseWriter) error
}

type RefreshImageVersions202JSONResponse

type RefreshImageVersions202JSONResponse ImageVersionRefreshResponse

func (RefreshImageVersions202JSONResponse) VisitRefreshImageVersionsResponse

func (response RefreshImageVersions202JSONResponse) VisitRefreshImageVersionsResponse(w http.ResponseWriter) error

type RefreshImageVersions401ApplicationProblemPlusJSONResponse

type RefreshImageVersions401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (RefreshImageVersions401ApplicationProblemPlusJSONResponse) VisitRefreshImageVersionsResponse

func (response RefreshImageVersions401ApplicationProblemPlusJSONResponse) VisitRefreshImageVersionsResponse(w http.ResponseWriter) error

type RefreshImageVersions403ApplicationProblemPlusJSONResponse

type RefreshImageVersions403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (RefreshImageVersions403ApplicationProblemPlusJSONResponse) VisitRefreshImageVersionsResponse

func (response RefreshImageVersions403ApplicationProblemPlusJSONResponse) VisitRefreshImageVersionsResponse(w http.ResponseWriter) error

type RefreshImageVersions409ApplicationProblemPlusJSONResponse

type RefreshImageVersions409ApplicationProblemPlusJSONResponse struct {
	ConflictApplicationProblemPlusJSONResponse
}

func (RefreshImageVersions409ApplicationProblemPlusJSONResponse) VisitRefreshImageVersionsResponse

func (response RefreshImageVersions409ApplicationProblemPlusJSONResponse) VisitRefreshImageVersionsResponse(w http.ResponseWriter) error

type RefreshImageVersionsRequestObject

type RefreshImageVersionsRequestObject struct {
}

type RefreshImageVersionsResponseObject

type RefreshImageVersionsResponseObject interface {
	VisitRefreshImageVersionsResponse(w http.ResponseWriter) error
}

type RequiredHeaderError

type RequiredHeaderError struct {
	ParamName string
	Err       error
}

func (*RequiredHeaderError) Error

func (e *RequiredHeaderError) Error() string

func (*RequiredHeaderError) Unwrap

func (e *RequiredHeaderError) Unwrap() error

type RequiredParamError

type RequiredParamError struct {
	ParamName string
}

func (*RequiredParamError) Error

func (e *RequiredParamError) Error() string

type RevokeApiToken204Response

type RevokeApiToken204Response struct {
}

func (RevokeApiToken204Response) VisitRevokeApiTokenResponse

func (response RevokeApiToken204Response) VisitRevokeApiTokenResponse(w http.ResponseWriter) error

type RevokeApiToken401ApplicationProblemPlusJSONResponse

type RevokeApiToken401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (RevokeApiToken401ApplicationProblemPlusJSONResponse) VisitRevokeApiTokenResponse

func (response RevokeApiToken401ApplicationProblemPlusJSONResponse) VisitRevokeApiTokenResponse(w http.ResponseWriter) error

type RevokeApiToken403ApplicationProblemPlusJSONResponse

type RevokeApiToken403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (RevokeApiToken403ApplicationProblemPlusJSONResponse) VisitRevokeApiTokenResponse

func (response RevokeApiToken403ApplicationProblemPlusJSONResponse) VisitRevokeApiTokenResponse(w http.ResponseWriter) error

type RevokeApiToken404ApplicationProblemPlusJSONResponse

type RevokeApiToken404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (RevokeApiToken404ApplicationProblemPlusJSONResponse) VisitRevokeApiTokenResponse

func (response RevokeApiToken404ApplicationProblemPlusJSONResponse) VisitRevokeApiTokenResponse(w http.ResponseWriter) error

type RevokeApiTokenRequestObject

type RevokeApiTokenRequestObject struct {
	Id TokenId `json:"id"`
}

type RevokeApiTokenResponseObject

type RevokeApiTokenResponseObject interface {
	VisitRevokeApiTokenResponse(w http.ResponseWriter) error
}

type RevokeSession204Response

type RevokeSession204Response struct {
}

func (RevokeSession204Response) VisitRevokeSessionResponse

func (response RevokeSession204Response) VisitRevokeSessionResponse(w http.ResponseWriter) error

type RevokeSession401ApplicationProblemPlusJSONResponse

type RevokeSession401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (RevokeSession401ApplicationProblemPlusJSONResponse) VisitRevokeSessionResponse

func (response RevokeSession401ApplicationProblemPlusJSONResponse) VisitRevokeSessionResponse(w http.ResponseWriter) error

type RevokeSession403ApplicationProblemPlusJSONResponse

type RevokeSession403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (RevokeSession403ApplicationProblemPlusJSONResponse) VisitRevokeSessionResponse

func (response RevokeSession403ApplicationProblemPlusJSONResponse) VisitRevokeSessionResponse(w http.ResponseWriter) error

type RevokeSession404ApplicationProblemPlusJSONResponse

type RevokeSession404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (RevokeSession404ApplicationProblemPlusJSONResponse) VisitRevokeSessionResponse

func (response RevokeSession404ApplicationProblemPlusJSONResponse) VisitRevokeSessionResponse(w http.ResponseWriter) error

type RevokeSessionRequestObject

type RevokeSessionRequestObject struct {
	Id SessionId `json:"id"`
}

type RevokeSessionResponseObject

type RevokeSessionResponseObject interface {
	VisitRevokeSessionResponse(w http.ResponseWriter) error
}

type Role

type Role string

Role Fixed role set per ADR-0007. Each role maps to a fixed scope set — the scope check in the OpenAPI `security` blocks is unchanged, the session middleware just attaches the scopes derived from role.

const (
	Admin   Role = "admin"
	Auditor Role = "auditor"
	Editor  Role = "editor"
	Viewer  Role = "viewer"
)

Defines values for Role.

func (Role) Valid

func (e Role) Valid() bool

Valid indicates whether the value is a known member of the Role enum.

type SecurityGroup added in v1.1.0

type SecurityGroup struct {
	CloudAccountId openapi_types.UUID `json:"cloud_account_id"`
	Id             openapi_types.UUID `json:"id"`
	Name           string             `json:"name"`
	ProviderSgId   string             `json:"provider_sg_id"`
	Tags           *map[string]string `json:"tags,omitempty"`
	VpcId          *string            `json:"vpc_id,omitempty"`
}

SecurityGroup defines model for SecurityGroup.

type SecurityGroupListFilter added in v1.10.0

type SecurityGroupListFilter struct {
	// Name is a case-insensitive substring / anchored-glob match on name.
	Name *string
	// VpcID is an exact-match filter on the vpc_id column (nil = no filter).
	VpcID *string
}

SecurityGroupListFilter collects optional filters for ListSecurityGroupsByAccount.

type SecurityGroupRow added in v1.1.0

type SecurityGroupRow struct {
	ID             uuid.UUID       `json:"id"`
	CloudAccountID uuid.UUID       `json:"cloud_account_id"`
	ProviderSGID   string          `json:"provider_sg_id"`
	Name           string          `json:"name"`
	VPCID          string          `json:"vpc_id,omitempty"`
	Tags           json.RawMessage `json:"tags,omitempty"`
}

SecurityGroupRow is the persisted view of one cloud-provider security group. Tags is a JSONB map<string,string>. VPCID is empty-string when the provider does not report a VPC.

type SecurityGroupRule added in v1.1.0

type SecurityGroupRule struct {
	Description      *string                    `json:"description,omitempty"`
	Direction        SecurityGroupRuleDirection `json:"direction"`
	FromPort         *int                       `json:"from_port,omitempty"`
	Id               openapi_types.UUID         `json:"id"`
	PeerCidr         *string                    `json:"peer_cidr,omitempty"`
	PeerKind         SecurityGroupRulePeerKind  `json:"peer_kind"`
	PeerPrefixId     *string                    `json:"peer_prefix_id,omitempty"`
	PeerSgProviderId *string                    `json:"peer_sg_provider_id,omitempty"`
	Protocol         SecurityGroupRuleProtocol  `json:"protocol"`
	ToPort           *int                       `json:"to_port,omitempty"`
}

SecurityGroupRule defines model for SecurityGroupRule.

type SecurityGroupRuleDirection added in v1.1.0

type SecurityGroupRuleDirection string

SecurityGroupRuleDirection defines model for SecurityGroupRule.Direction.

const (
	SecurityGroupRuleDirectionEgress  SecurityGroupRuleDirection = "egress"
	SecurityGroupRuleDirectionIngress SecurityGroupRuleDirection = "ingress"
)

Defines values for SecurityGroupRuleDirection.

func (SecurityGroupRuleDirection) Valid added in v1.1.0

func (e SecurityGroupRuleDirection) Valid() bool

Valid indicates whether the value is a known member of the SecurityGroupRuleDirection enum.

type SecurityGroupRulePeerKind added in v1.1.0

type SecurityGroupRulePeerKind string

SecurityGroupRulePeerKind defines model for SecurityGroupRule.PeerKind.

const (
	Cidr          SecurityGroupRulePeerKind = "cidr"
	PrefixListRef SecurityGroupRulePeerKind = "prefix_list_ref"
	Self          SecurityGroupRulePeerKind = "self"
	SgRef         SecurityGroupRulePeerKind = "sg_ref"
)

Defines values for SecurityGroupRulePeerKind.

func (SecurityGroupRulePeerKind) Valid added in v1.1.0

func (e SecurityGroupRulePeerKind) Valid() bool

Valid indicates whether the value is a known member of the SecurityGroupRulePeerKind enum.

type SecurityGroupRuleProtocol added in v1.1.0

type SecurityGroupRuleProtocol string

SecurityGroupRuleProtocol defines model for SecurityGroupRule.Protocol.

Defines values for SecurityGroupRuleProtocol.

func (SecurityGroupRuleProtocol) Valid added in v1.1.0

func (e SecurityGroupRuleProtocol) Valid() bool

Valid indicates whether the value is a known member of the SecurityGroupRuleProtocol enum.

type SecurityGroupRuleRow added in v1.1.0

type SecurityGroupRuleRow struct {
	ID               uuid.UUID `json:"id"`
	SecurityGroupID  uuid.UUID `json:"security_group_id"`
	Direction        string    `json:"direction"`
	Protocol         string    `json:"protocol"`
	FromPort         *int      `json:"from_port,omitempty"`
	ToPort           *int      `json:"to_port,omitempty"`
	PeerKind         string    `json:"peer_kind"`
	PeerCIDR         string    `json:"peer_cidr,omitempty"`
	PeerSGProviderID string    `json:"peer_sg_provider_id,omitempty"`
	PeerPrefixID     string    `json:"peer_prefix_id,omitempty"`
	Description      string    `json:"description,omitempty"`
}

SecurityGroupRuleRow is the persisted view of one ingress or egress rule. Direction is "ingress" or "egress". Protocol is one of "tcp", "udp", "icmp", "any", or "-1" (some providers use "-1" for "all traffic"). FromPort / ToPort are nil when the protocol has no port concept. PeerKind is "cidr", "sg_ref", "prefix_list_ref", or "self".

type SecurityGroupStore added in v1.6.2

type SecurityGroupStore interface {
	// UpsertSecurityGroup inserts or updates by (cloud_account_id,
	// provider_sg_id). Returns the stable row UUID. Called on every
	// collector tick; idempotent.
	UpsertSecurityGroup(ctx context.Context, in SecurityGroupRow) (uuid.UUID, error)

	// GetSecurityGroup fetches a security group by stable UUID.
	// Returns ErrNotFound when the row is absent.
	GetSecurityGroup(ctx context.Context, id uuid.UUID) (SecurityGroupRow, error)

	// ReplaceSecurityGroupRules atomically replaces every rule for the
	// given security_group_id. Delete+insert in one transaction; rule
	// sets are small enough that a finer diff is over-engineering.
	ReplaceSecurityGroupRules(ctx context.Context, sgID uuid.UUID, rules []SecurityGroupRuleRow) error

	// ListSecurityGroupsByAccount returns a page of security groups for
	// the given account, filtered and sorted per filter/page.
	ListSecurityGroupsByAccount(
		ctx context.Context,
		accountID uuid.UUID,
		filter SecurityGroupListFilter,
		page ListPage,
	) ([]SecurityGroupRow, string, error)

	// ListSecurityGroupRules returns all rules for a single security
	// group, in stable insertion order.
	ListSecurityGroupRules(ctx context.Context, sgID uuid.UUID) ([]SecurityGroupRuleRow, error)

	// SweepSecurityGroupsByAccount deletes every security group in the
	// account whose provider_sg_id is NOT in seenProviderIDs. Called once
	// per account refresh tick after all VM upserts are done.
	SweepSecurityGroupsByAccount(ctx context.Context, accountID uuid.UUID, seenProviderIDs []string) error

	// GetSecurityGroupByProviderID fetches a security group by
	// (cloud_account_id, provider_sg_id). Returns ErrNotFound on miss.
	GetSecurityGroupByProviderID(ctx context.Context, accountID uuid.UUID, providerSGID string) (SecurityGroupRow, error)

	// UpsertVMSecurityGroupAttachment inserts or refreshes one
	// (account, vm, sg) attachment, stamping reconcile_seen_at. Called on
	// every collector tick; idempotent.
	UpsertVMSecurityGroupAttachment(ctx context.Context, a VMSecurityGroupAttachment) error

	// SweepVMSecurityGroupAttachments deletes attachments for the account
	// that are not in seen. Called once per account refresh tick after all
	// attachment upserts are done; MUST only run after a successful provider
	// list (CLAUDE.md reconcile contract).
	SweepVMSecurityGroupAttachments(ctx context.Context, accountID uuid.UUID, seen []VMSecurityGroupAttachment) error

	// PerimeterSecurityGroupsForCluster resolves the security groups that
	// protect a cluster's node VMs, joining nodes.provider_id to attachment
	// provider_vm_id via the same substring match the VM dedup trusts
	// (ADR-0015).
	PerimeterSecurityGroupsForCluster(ctx context.Context, clusterID uuid.UUID) ([]SecurityGroupRow, error)
}

SecurityGroupStore covers provider security groups, their rules, and VM attachments (flow-matrix P1).

type ServeMux

type ServeMux interface {
	HandleFunc(pattern string, handler func(http.ResponseWriter, *http.Request))
	http.Handler
}

ServeMux is an abstraction of http.ServeMux.

type Server

type Server struct {
	// contains filtered or unexported fields
}

Server implements StrictServerInterface for the longue-vue REST API.

func NewServer

func NewServer(
	version string,
	store Store,
	cookiePolicy auth.SecureCookiePolicy,
	oidc *auth.OIDCProvider,
	loginLimiter *LoginRateLimiter,
	verifyLimiter *VerifyRateLimiter,
) *Server

NewServer wires the handlers with a persistence backend and the build version reported on health probes. `cookiePolicy` governs the Secure flag on session cookies (see ADR-0007); auto = mirror request scheme. `oidc` may be nil to disable the OIDC flow entirely. `verifyLimiter` gates POST /v1/auth/verify (ADR-0016 §5); pass nil to disable rate limiting (test fixtures usually do).

func (*Server) ChangePassword

ChangePassword rotates the caller's password. Session-only — bearer tokens can't change a user's password.

func (*Server) CreateApiToken

CreateApiToken mints a new bearer token, returning the plaintext once.

func (*Server) CreateCluster

CreateCluster registers a cluster idempotently on its name.

On insert: returns 201 Created with the new row. On hit (a cluster with the same name already exists): returns 200 OK with the existing row unchanged. The request body is ignored on hit — callers wanting to update fields on an existing cluster must follow up with PATCH /v1/clusters/{id}.

func (*Server) CreateImageOriginMapping added in v0.30.0

CreateImageOriginMapping inserts a new (image_name, public_registry).

func (*Server) CreateImageRegistry

CreateImageRegistry inserts a new registry row.

func (*Server) CreateIngress

CreateIngress registers a new ingress under a namespace.

func (*Server) CreateNamespace

CreateNamespace registers a new namespace under a cluster.

func (*Server) CreateNetworkPolicy added in v1.4.0

CreateNetworkPolicy is the strict-server impl for POST /v1/network-policies.

Scope: write. Returns 201 on first write, 200 on subsequent upsert. The policy and its rules are persisted atomically via UpsertNetworkPolicy.

func (*Server) CreateNode

CreateNode registers a new node under a cluster.

func (*Server) CreatePersistentVolume

CreatePersistentVolume registers a new PV under a cluster.

func (*Server) CreatePersistentVolumeClaim

CreatePersistentVolumeClaim registers a new PVC under a namespace.

func (*Server) CreatePod

CreatePod registers a new pod under a namespace.

func (*Server) CreateService

CreateService registers a new service under a namespace.

func (*Server) CreateUser

CreateUser creates a new local user with a hashed password.

func (*Server) CreateWorkload

CreateWorkload registers a new workload under a namespace.

func (*Server) DeleteCluster

DeleteCluster removes a cluster. Before deleting, it snapshots the cluster metadata and cascade counts into the audit event so the record is self-contained even after the row is gone (ADR-0010).

func (*Server) DeleteImageOriginMapping added in v0.30.0

DeleteImageOriginMapping removes a mapping by image_name.

func (*Server) DeleteImageRegistry

DeleteImageRegistry removes a registry from the allowlist.

func (*Server) DeleteIngress

DeleteIngress removes an ingress.

func (*Server) DeleteNamespace

DeleteNamespace removes a namespace.

func (*Server) DeleteNode

DeleteNode removes a node.

func (*Server) DeletePersistentVolume

DeletePersistentVolume removes a PV.

func (*Server) DeletePersistentVolumeClaim

DeletePersistentVolumeClaim removes a PVC.

func (*Server) DeletePod

DeletePod removes a pod.

func (*Server) DeleteService

DeleteService removes a service.

func (*Server) DeleteUser

DeleteUser removes a user, guarding against self-deletion and against orphaning the deployment by removing the last active admin (AUTHZ-VULN-01). The last-admin check + delete is run atomically inside the store via DeleteUserGuarded — see audit finding H1 for the TOCTOU rationale.

func (*Server) DeleteWorkload

DeleteWorkload removes a workload.

func (*Server) GetAuthConfig

GetAuthConfig surfaces what the login page needs pre-session.

func (*Server) GetCluster

GetCluster fetches a cluster by id.

func (*Server) GetHealthz

GetHealthz reports that the process is alive.

func (*Server) GetImageOriginMapping added in v0.30.0

GetImageOriginMapping returns a single mapping by image_name.

func (*Server) GetImageVersion

GetImageVersion returns all variant rows for a single image_repo.

func (*Server) GetIngress

GetIngress fetches an ingress by id.

func (*Server) GetMe

GetMe returns identity + role + effective scopes for the current caller. The UI polls this on load to decide which nav items to render and whether to redirect to the forced-change page.

func (*Server) GetNamespace

GetNamespace fetches a namespace by id.

func (*Server) GetNode

GetNode fetches a node by id.

func (*Server) GetPersistentVolume

GetPersistentVolume fetches a PV by id.

func (*Server) GetPersistentVolumeClaim

GetPersistentVolumeClaim fetches a PVC by id.

func (*Server) GetPod

GetPod fetches a pod by id.

func (*Server) GetReadyz

GetReadyz reports whether the service can accept traffic by pinging the store.

func (*Server) GetService

GetService fetches a service by id.

func (*Server) GetUser

GetUser fetches a single user by id.

func (*Server) GetWorkload

GetWorkload fetches a workload by id.

func (*Server) ListApiTokens

ListApiTokens returns a paged list of API tokens (admin view).

func (*Server) ListAuditEvents

ListAuditEvents returns a filtered, paged list of audit events.

func (*Server) ListClusters

ListClusters returns a paged cluster list. name= is the uniform ci-substring/glob filter (it USED to be an exact-match short-circuit to GetClusterByName; recon 2026-07-10 found zero live callers of the exact semantics — the push collector bootstraps via the idempotent POST /v1/clusters, ADR-0016).

func (*Server) ListImageOriginMappings added in v0.30.0

ListImageOriginMappings returns a cursor-paginated slice of mappings.

func (*Server) ListImageRegistries

ListImageRegistries lists all image registry allowlist rows.

func (*Server) ListImageVersions

ListImageVersions returns a paginated list of distinct image repos with their variants.

func (*Server) ListIngresses

ListIngresses returns a paged list of ingresses, optionally filtered by namespace_id and/or name.

func (*Server) ListNamespaces

ListNamespaces returns a paged list of namespaces, optionally filtered by cluster_id and/or name.

func (*Server) ListNodes

ListNodes returns a paged list of nodes, optionally filtered by cluster_id and/or name.

func (*Server) ListPersistentVolumeClaims

ListPersistentVolumeClaims returns a paged list of PVCs.

func (*Server) ListPersistentVolumes

ListPersistentVolumes returns a paged list of PVs.

func (*Server) ListPods

ListPods returns a paged list of pods, optionally filtered by namespace_id, node_name, and/or container image substring.

func (*Server) ListServices

ListServices returns a paged list of services, optionally filtered by namespace_id and/or name.

func (*Server) ListSessions

ListSessions returns a paged list of active sessions (admin view).

func (*Server) ListUsers

ListUsers returns a paged list of all users (admin view).

func (*Server) ListWorkloads

ListWorkloads returns a paged list of workloads, optionally filtered by namespace_id and/or kind.

func (*Server) Login

Login validates username + password and issues a session cookie. 401 on any failure (no distinction between unknown user and bad password) to avoid username enumeration.

func (*Server) Logout

Logout deletes the session row (if any) and clears the cookie. Idempotent for bearer callers — nothing to revoke.

func (*Server) OidcAuthorize

OidcAuthorize mints state + PKCE + nonce, stores them, redirects to the IdP. 404 when OIDC is unconfigured.

func (*Server) OidcCallback

OidcCallback completes the flow, finds-or-creates the shadow user, mints a session, and redirects to the UI. On failure redirects to /ui/login?oidc_error=<reason> so the UI can surface what went wrong.

func (*Server) PatchImageOriginMapping added in v0.30.0

PatchImageOriginMapping applies a merge-patch.

func (*Server) PatchImageRegistry

PatchImageRegistry applies a merge-patch to an existing registry row.

func (*Server) ReconcileIngresses

ReconcileIngresses deletes every ingress of the given namespace whose name is not in keep_names.

func (*Server) ReconcileNamespaces

ReconcileNamespaces deletes every namespace of the given cluster whose name is not in keep_names.

func (*Server) ReconcileNetworkPolicies added in v1.4.0

ReconcileNetworkPolicies is the strict-server impl for POST /v1/network-policies/reconcile.

Scope: delete. Deletes every policy in the given namespace whose name is NOT in keep_names, returning the count of deleted rows. The caller MUST only invoke after a successful list tick (CLAUDE.md reconcile contract).

func (*Server) ReconcileNodes

ReconcileNodes deletes every node of the given cluster whose name is not in keep_names.

func (*Server) ReconcilePersistentVolumeClaims

ReconcilePersistentVolumeClaims deletes every PVC of the given namespace whose name is not in keep_names.

func (*Server) ReconcilePersistentVolumes

ReconcilePersistentVolumes deletes every PV of the given cluster whose name is not in keep_names.

func (*Server) ReconcilePods

ReconcilePods deletes every pod of the given namespace whose name is not in keep_names.

func (*Server) ReconcileServices

ReconcileServices deletes every service of the given namespace whose name is not in keep_names.

func (*Server) ReconcileWorkloads

ReconcileWorkloads deletes every workload of the given namespace whose (kind, name) tuple is not in the parallel keep_kinds/keep_names arrays.

func (*Server) RefreshImageVersions

RefreshImageVersions triggers an immediate enrichment cycle (admin only).

func (*Server) RevokeApiToken

RevokeApiToken marks a token as revoked so it can no longer authenticate.

func (*Server) RevokeSession

RevokeSession terminates a session by its public id.

func (*Server) SetEnricher

func (s *Server) SetEnricher(e EnricherTrigger)

SetEnricher injects the image-versions enricher trigger. Called by main.go after NewServer when the feature is enabled.

func (*Server) SetTrustedProxies

func (s *Server) SetTrustedProxies(p []*net.IPNet)

SetTrustedProxies installs the operator-supplied CIDR list at startup. Pass nil or an empty slice to ignore X-Forwarded-* unconditionally — the secure default. longue-vue's main.go calls this once after parsing LONGUE_VUE_TRUSTED_PROXIES; tests typically leave it unset.

func (*Server) UpdateCluster

UpdateCluster applies merge-patch updates to a cluster.

func (*Server) UpdateIngress

UpdateIngress applies merge-patch updates.

func (*Server) UpdateNamespace

UpdateNamespace applies merge-patch updates.

func (*Server) UpdateNode

UpdateNode applies merge-patch updates to a node.

func (*Server) UpdatePersistentVolume

UpdatePersistentVolume applies merge-patch updates.

func (*Server) UpdatePersistentVolumeClaim

UpdatePersistentVolumeClaim applies merge-patch updates.

func (*Server) UpdatePod

UpdatePod applies merge-patch updates.

func (*Server) UpdateService

UpdateService applies merge-patch updates.

func (*Server) UpdateUser

UpdateUser applies a merge-patch to an existing user. The last-admin invariant (AUTHZ-VULN-02 / audit finding H1) is enforced atomically inside the store via UpdateUserGuarded so two concurrent demotions cannot both observe `n=2` and commit.

func (*Server) UpdateWorkload

UpdateWorkload applies merge-patch updates.

ADR-0029 §2.3: when the body carries application_id or application_name, resolve to a concrete UUID first (id wins on conflict). The store layer is unaware of names; the handler is the resolution boundary so the store contract stays a thin SQL projection.

func (*Server) VerifyToken

VerifyToken re-runs the bearer-token argon2id check on a token presented in the request body and returns the resulting caller identity. Used by the DMZ ingest gateway (ADR-0016 §5) to short-circuit invalid tokens before they cross the firewall into the trusted zone.

This handler is registered ONLY on longue-vue's mTLS-only ingest listener (see api.IngestMux). The mTLS handshake is the sole authentication for the call itself — the request body's `token` field carries the PAT to be verified, NOT the caller's identity. longue-vue never trusts the outcome of this RPC for its own auth decisions; the gateway's cache uses it purely as a DMZ-side filter, and every forwarded write is re-verified by longue-vue's standard bearer middleware.

Rate-limited at longue-vue to a per-source-IP budget (default 100 req/s, burst 200) as a backstop in case the gateway's cache is bypassed.

type ServerInterface

type ServerInterface interface {
	// Liveness probe
	// (GET /healthz)
	GetHealthz(w http.ResponseWriter, r *http.Request)
	// Readiness probe
	// (GET /readyz)
	GetReadyz(w http.ResponseWriter, r *http.Request)
	// List audit events
	// (GET /v1/admin/audit)
	ListAuditEvents(w http.ResponseWriter, r *http.Request, params ListAuditEventsParams)
	// List operator-curated image_name → public_registry mappings (ADR-0030)
	// (GET /v1/admin/image-origin-mappings)
	ListImageOriginMappings(w http.ResponseWriter, r *http.Request, params ListImageOriginMappingsParams)
	// Create an image_name → public_registry mapping (ADR-0030)
	// (POST /v1/admin/image-origin-mappings)
	CreateImageOriginMapping(w http.ResponseWriter, r *http.Request)
	// Delete an image origin mapping
	// (DELETE /v1/admin/image-origin-mappings/{image_name})
	DeleteImageOriginMapping(w http.ResponseWriter, r *http.Request, imageName string)
	// Get one image origin mapping
	// (GET /v1/admin/image-origin-mappings/{image_name})
	GetImageOriginMapping(w http.ResponseWriter, r *http.Request, imageName string)
	// Update an image origin mapping (merge-patch)
	// (PATCH /v1/admin/image-origin-mappings/{image_name})
	PatchImageOriginMapping(w http.ResponseWriter, r *http.Request, imageName string)
	// List the supported registries allowlist
	// (GET /v1/admin/image-versions/registries)
	ListImageRegistries(w http.ResponseWriter, r *http.Request)
	// Add a registry to the allowlist
	// (POST /v1/admin/image-versions/registries)
	CreateImageRegistry(w http.ResponseWriter, r *http.Request)
	// Remove a registry from the allowlist
	// (DELETE /v1/admin/image-versions/registries/{hostname}/{path_prefix})
	DeleteImageRegistry(w http.ResponseWriter, r *http.Request, hostname string, pathPrefix string)
	// Update a registry's rate limit, enabled flag, or notes
	// (PATCH /v1/admin/image-versions/registries/{hostname}/{path_prefix})
	PatchImageRegistry(w http.ResponseWriter, r *http.Request, hostname string, pathPrefix string)
	// List active human sessions
	// (GET /v1/admin/sessions)
	ListSessions(w http.ResponseWriter, r *http.Request, params ListSessionsParams)
	// Revoke an active session
	// (DELETE /v1/admin/sessions/{id})
	RevokeSession(w http.ResponseWriter, r *http.Request, id SessionId)
	// List machine tokens (metadata only — plaintext never leaves creation)
	// (GET /v1/admin/tokens)
	ListApiTokens(w http.ResponseWriter, r *http.Request, params ListApiTokensParams)
	// Mint a new machine token
	// (POST /v1/admin/tokens)
	CreateApiToken(w http.ResponseWriter, r *http.Request)
	// Revoke a machine token
	// (DELETE /v1/admin/tokens/{id})
	RevokeApiToken(w http.ResponseWriter, r *http.Request, id TokenId)
	// List human users
	// (GET /v1/admin/users)
	ListUsers(w http.ResponseWriter, r *http.Request, params ListUsersParams)
	// Create a human user
	// (POST /v1/admin/users)
	CreateUser(w http.ResponseWriter, r *http.Request)
	// Delete a user
	// (DELETE /v1/admin/users/{id})
	DeleteUser(w http.ResponseWriter, r *http.Request, id UserId)
	// Get a user
	// (GET /v1/admin/users/{id})
	GetUser(w http.ResponseWriter, r *http.Request, id UserId)
	// Update a user's role, password, disabled, or lockout state
	// (PATCH /v1/admin/users/{id})
	UpdateUser(w http.ResponseWriter, r *http.Request, id UserId)
	// Change the current user's password
	// (POST /v1/auth/change-password)
	ChangePassword(w http.ResponseWriter, r *http.Request)
	// Public auth configuration the UI needs pre-login
	// (GET /v1/auth/config)
	GetAuthConfig(w http.ResponseWriter, r *http.Request)
	// Start a human session
	// (POST /v1/auth/login)
	Login(w http.ResponseWriter, r *http.Request)
	// End the current human session
	// (POST /v1/auth/logout)
	Logout(w http.ResponseWriter, r *http.Request)
	// Who am I, and what can I do
	// (GET /v1/auth/me)
	GetMe(w http.ResponseWriter, r *http.Request)
	// Start the OIDC authorization-code flow
	// (GET /v1/auth/oidc/authorize)
	OidcAuthorize(w http.ResponseWriter, r *http.Request)
	// Complete the OIDC authorization-code flow
	// (GET /v1/auth/oidc/callback)
	OidcCallback(w http.ResponseWriter, r *http.Request, params OidcCallbackParams)
	// Verify a bearer token
	// (POST /v1/auth/verify)
	VerifyToken(w http.ResponseWriter, r *http.Request)
	// List clusters
	// (GET /v1/clusters)
	ListClusters(w http.ResponseWriter, r *http.Request, params ListClustersParams)
	// Register or ensure a cluster
	// (POST /v1/clusters)
	CreateCluster(w http.ResponseWriter, r *http.Request)
	// Delete a cluster
	// (DELETE /v1/clusters/{id})
	DeleteCluster(w http.ResponseWriter, r *http.Request, id ClusterId)
	// Get a cluster
	// (GET /v1/clusters/{id})
	GetCluster(w http.ResponseWriter, r *http.Request, id ClusterId)
	// Update mutable fields of a cluster
	// (PATCH /v1/clusters/{id})
	UpdateCluster(w http.ResponseWriter, r *http.Request, id ClusterId)
	// List enriched container images with their latest tags
	// (GET /v1/image-versions)
	ListImageVersions(w http.ResponseWriter, r *http.Request, params ListImageVersionsParams)
	// Trigger an immediate enrichment cycle (admin only)
	// (POST /v1/image-versions/refresh)
	RefreshImageVersions(w http.ResponseWriter, r *http.Request)
	// Get one image's enrichment (all variants)
	// (GET /v1/image-versions/{image_repo})
	GetImageVersion(w http.ResponseWriter, r *http.Request, imageRepo string)
	// List ingresses
	// (GET /v1/ingresses)
	ListIngresses(w http.ResponseWriter, r *http.Request, params ListIngressesParams)
	// Register an ingress
	// (POST /v1/ingresses)
	CreateIngress(w http.ResponseWriter, r *http.Request)
	// Reconcile ingresses for a namespace
	// (POST /v1/ingresses/reconcile)
	ReconcileIngresses(w http.ResponseWriter, r *http.Request)
	// Delete an ingress
	// (DELETE /v1/ingresses/{id})
	DeleteIngress(w http.ResponseWriter, r *http.Request, id IngressId)
	// Get an ingress
	// (GET /v1/ingresses/{id})
	GetIngress(w http.ResponseWriter, r *http.Request, id IngressId)
	// Update mutable fields of an ingress
	// (PATCH /v1/ingresses/{id})
	UpdateIngress(w http.ResponseWriter, r *http.Request, id IngressId)
	// List namespaces
	// (GET /v1/namespaces)
	ListNamespaces(w http.ResponseWriter, r *http.Request, params ListNamespacesParams)
	// Register a namespace
	// (POST /v1/namespaces)
	CreateNamespace(w http.ResponseWriter, r *http.Request)
	// Reconcile namespaces for a cluster
	// (POST /v1/namespaces/reconcile)
	ReconcileNamespaces(w http.ResponseWriter, r *http.Request)
	// Delete a namespace
	// (DELETE /v1/namespaces/{id})
	DeleteNamespace(w http.ResponseWriter, r *http.Request, id NamespaceId)
	// Get a namespace
	// (GET /v1/namespaces/{id})
	GetNamespace(w http.ResponseWriter, r *http.Request, id NamespaceId)
	// Update mutable fields of a namespace
	// (PATCH /v1/namespaces/{id})
	UpdateNamespace(w http.ResponseWriter, r *http.Request, id NamespaceId)
	// Upsert a NetworkPolicy with its rules atomically (push-mode collector)
	// (POST /v1/network-policies)
	CreateNetworkPolicy(w http.ResponseWriter, r *http.Request)
	// Sweep NetworkPolicies by namespace (push-mode collector)
	// (POST /v1/network-policies/reconcile)
	ReconcileNetworkPolicies(w http.ResponseWriter, r *http.Request)
	// List nodes
	// (GET /v1/nodes)
	ListNodes(w http.ResponseWriter, r *http.Request, params ListNodesParams)
	// Register a node
	// (POST /v1/nodes)
	CreateNode(w http.ResponseWriter, r *http.Request)
	// Reconcile nodes for a cluster
	// (POST /v1/nodes/reconcile)
	ReconcileNodes(w http.ResponseWriter, r *http.Request)
	// Delete a node
	// (DELETE /v1/nodes/{id})
	DeleteNode(w http.ResponseWriter, r *http.Request, id NodeId)
	// Get a node
	// (GET /v1/nodes/{id})
	GetNode(w http.ResponseWriter, r *http.Request, id NodeId)
	// Update mutable fields of a node
	// (PATCH /v1/nodes/{id})
	UpdateNode(w http.ResponseWriter, r *http.Request, id NodeId)
	// List persistent volume claims
	// (GET /v1/persistentvolumeclaims)
	ListPersistentVolumeClaims(w http.ResponseWriter, r *http.Request, params ListPersistentVolumeClaimsParams)
	// Register a persistent volume claim
	// (POST /v1/persistentvolumeclaims)
	CreatePersistentVolumeClaim(w http.ResponseWriter, r *http.Request)
	// Reconcile PVCs for a namespace
	// (POST /v1/persistentvolumeclaims/reconcile)
	ReconcilePersistentVolumeClaims(w http.ResponseWriter, r *http.Request)
	// Delete a persistent volume claim
	// (DELETE /v1/persistentvolumeclaims/{id})
	DeletePersistentVolumeClaim(w http.ResponseWriter, r *http.Request, id PersistentVolumeClaimId)
	// Get a persistent volume claim
	// (GET /v1/persistentvolumeclaims/{id})
	GetPersistentVolumeClaim(w http.ResponseWriter, r *http.Request, id PersistentVolumeClaimId)
	// Update mutable fields of a persistent volume claim
	// (PATCH /v1/persistentvolumeclaims/{id})
	UpdatePersistentVolumeClaim(w http.ResponseWriter, r *http.Request, id PersistentVolumeClaimId)
	// List persistent volumes
	// (GET /v1/persistentvolumes)
	ListPersistentVolumes(w http.ResponseWriter, r *http.Request, params ListPersistentVolumesParams)
	// Register a persistent volume
	// (POST /v1/persistentvolumes)
	CreatePersistentVolume(w http.ResponseWriter, r *http.Request)
	// Reconcile persistent volumes for a cluster
	// (POST /v1/persistentvolumes/reconcile)
	ReconcilePersistentVolumes(w http.ResponseWriter, r *http.Request)
	// Delete a persistent volume
	// (DELETE /v1/persistentvolumes/{id})
	DeletePersistentVolume(w http.ResponseWriter, r *http.Request, id PersistentVolumeId)
	// Get a persistent volume
	// (GET /v1/persistentvolumes/{id})
	GetPersistentVolume(w http.ResponseWriter, r *http.Request, id PersistentVolumeId)
	// Update mutable fields of a persistent volume
	// (PATCH /v1/persistentvolumes/{id})
	UpdatePersistentVolume(w http.ResponseWriter, r *http.Request, id PersistentVolumeId)
	// List pods
	// (GET /v1/pods)
	ListPods(w http.ResponseWriter, r *http.Request, params ListPodsParams)
	// Register a pod
	// (POST /v1/pods)
	CreatePod(w http.ResponseWriter, r *http.Request)
	// Reconcile pods for a namespace
	// (POST /v1/pods/reconcile)
	ReconcilePods(w http.ResponseWriter, r *http.Request)
	// Delete a pod
	// (DELETE /v1/pods/{id})
	DeletePod(w http.ResponseWriter, r *http.Request, id PodId)
	// Get a pod
	// (GET /v1/pods/{id})
	GetPod(w http.ResponseWriter, r *http.Request, id PodId)
	// Update mutable fields of a pod
	// (PATCH /v1/pods/{id})
	UpdatePod(w http.ResponseWriter, r *http.Request, id PodId)
	// List services
	// (GET /v1/services)
	ListServices(w http.ResponseWriter, r *http.Request, params ListServicesParams)
	// Register a service
	// (POST /v1/services)
	CreateService(w http.ResponseWriter, r *http.Request)
	// Reconcile services for a namespace
	// (POST /v1/services/reconcile)
	ReconcileServices(w http.ResponseWriter, r *http.Request)
	// Delete a service
	// (DELETE /v1/services/{id})
	DeleteService(w http.ResponseWriter, r *http.Request, id ServiceId)
	// Get a service
	// (GET /v1/services/{id})
	GetService(w http.ResponseWriter, r *http.Request, id ServiceId)
	// Update mutable fields of a service
	// (PATCH /v1/services/{id})
	UpdateService(w http.ResponseWriter, r *http.Request, id ServiceId)
	// List workloads
	// (GET /v1/workloads)
	ListWorkloads(w http.ResponseWriter, r *http.Request, params ListWorkloadsParams)
	// Register a workload
	// (POST /v1/workloads)
	CreateWorkload(w http.ResponseWriter, r *http.Request)
	// Reconcile workloads for a namespace
	// (POST /v1/workloads/reconcile)
	ReconcileWorkloads(w http.ResponseWriter, r *http.Request)
	// Delete a workload
	// (DELETE /v1/workloads/{id})
	DeleteWorkload(w http.ResponseWriter, r *http.Request, id WorkloadId)
	// Get a workload
	// (GET /v1/workloads/{id})
	GetWorkload(w http.ResponseWriter, r *http.Request, id WorkloadId)
	// Update mutable fields of a workload
	// (PATCH /v1/workloads/{id})
	UpdateWorkload(w http.ResponseWriter, r *http.Request, id WorkloadId)
}

ServerInterface represents all server handlers.

func NewStrictHandler

func NewStrictHandler(ssi StrictServerInterface, middlewares []StrictMiddlewareFunc) ServerInterface

func NewStrictHandlerWithOptions

func NewStrictHandlerWithOptions(ssi StrictServerInterface, middlewares []StrictMiddlewareFunc, options StrictHTTPServerOptions) ServerInterface

type ServerInterfaceWrapper

type ServerInterfaceWrapper struct {
	Handler            ServerInterface
	HandlerMiddlewares []MiddlewareFunc
	ErrorHandlerFunc   func(w http.ResponseWriter, r *http.Request, err error)
}

ServerInterfaceWrapper converts contexts to parameters.

func (*ServerInterfaceWrapper) ChangePassword

func (siw *ServerInterfaceWrapper) ChangePassword(w http.ResponseWriter, r *http.Request)

ChangePassword operation middleware

func (*ServerInterfaceWrapper) CreateApiToken

func (siw *ServerInterfaceWrapper) CreateApiToken(w http.ResponseWriter, r *http.Request)

CreateApiToken operation middleware

func (*ServerInterfaceWrapper) CreateCluster

func (siw *ServerInterfaceWrapper) CreateCluster(w http.ResponseWriter, r *http.Request)

CreateCluster operation middleware

func (*ServerInterfaceWrapper) CreateImageOriginMapping added in v0.30.0

func (siw *ServerInterfaceWrapper) CreateImageOriginMapping(w http.ResponseWriter, r *http.Request)

CreateImageOriginMapping operation middleware

func (*ServerInterfaceWrapper) CreateImageRegistry

func (siw *ServerInterfaceWrapper) CreateImageRegistry(w http.ResponseWriter, r *http.Request)

CreateImageRegistry operation middleware

func (*ServerInterfaceWrapper) CreateIngress

func (siw *ServerInterfaceWrapper) CreateIngress(w http.ResponseWriter, r *http.Request)

CreateIngress operation middleware

func (*ServerInterfaceWrapper) CreateNamespace

func (siw *ServerInterfaceWrapper) CreateNamespace(w http.ResponseWriter, r *http.Request)

CreateNamespace operation middleware

func (*ServerInterfaceWrapper) CreateNetworkPolicy added in v1.4.0

func (siw *ServerInterfaceWrapper) CreateNetworkPolicy(w http.ResponseWriter, r *http.Request)

CreateNetworkPolicy operation middleware

func (*ServerInterfaceWrapper) CreateNode

func (siw *ServerInterfaceWrapper) CreateNode(w http.ResponseWriter, r *http.Request)

CreateNode operation middleware

func (*ServerInterfaceWrapper) CreatePersistentVolume

func (siw *ServerInterfaceWrapper) CreatePersistentVolume(w http.ResponseWriter, r *http.Request)

CreatePersistentVolume operation middleware

func (*ServerInterfaceWrapper) CreatePersistentVolumeClaim

func (siw *ServerInterfaceWrapper) CreatePersistentVolumeClaim(w http.ResponseWriter, r *http.Request)

CreatePersistentVolumeClaim operation middleware

func (*ServerInterfaceWrapper) CreatePod

func (siw *ServerInterfaceWrapper) CreatePod(w http.ResponseWriter, r *http.Request)

CreatePod operation middleware

func (*ServerInterfaceWrapper) CreateService

func (siw *ServerInterfaceWrapper) CreateService(w http.ResponseWriter, r *http.Request)

CreateService operation middleware

func (*ServerInterfaceWrapper) CreateUser

func (siw *ServerInterfaceWrapper) CreateUser(w http.ResponseWriter, r *http.Request)

CreateUser operation middleware

func (*ServerInterfaceWrapper) CreateWorkload

func (siw *ServerInterfaceWrapper) CreateWorkload(w http.ResponseWriter, r *http.Request)

CreateWorkload operation middleware

func (*ServerInterfaceWrapper) DeleteCluster

func (siw *ServerInterfaceWrapper) DeleteCluster(w http.ResponseWriter, r *http.Request)

DeleteCluster operation middleware

func (*ServerInterfaceWrapper) DeleteImageOriginMapping added in v0.30.0

func (siw *ServerInterfaceWrapper) DeleteImageOriginMapping(w http.ResponseWriter, r *http.Request)

DeleteImageOriginMapping operation middleware

func (*ServerInterfaceWrapper) DeleteImageRegistry

func (siw *ServerInterfaceWrapper) DeleteImageRegistry(w http.ResponseWriter, r *http.Request)

DeleteImageRegistry operation middleware

func (*ServerInterfaceWrapper) DeleteIngress

func (siw *ServerInterfaceWrapper) DeleteIngress(w http.ResponseWriter, r *http.Request)

DeleteIngress operation middleware

func (*ServerInterfaceWrapper) DeleteNamespace

func (siw *ServerInterfaceWrapper) DeleteNamespace(w http.ResponseWriter, r *http.Request)

DeleteNamespace operation middleware

func (*ServerInterfaceWrapper) DeleteNode

func (siw *ServerInterfaceWrapper) DeleteNode(w http.ResponseWriter, r *http.Request)

DeleteNode operation middleware

func (*ServerInterfaceWrapper) DeletePersistentVolume

func (siw *ServerInterfaceWrapper) DeletePersistentVolume(w http.ResponseWriter, r *http.Request)

DeletePersistentVolume operation middleware

func (*ServerInterfaceWrapper) DeletePersistentVolumeClaim

func (siw *ServerInterfaceWrapper) DeletePersistentVolumeClaim(w http.ResponseWriter, r *http.Request)

DeletePersistentVolumeClaim operation middleware

func (*ServerInterfaceWrapper) DeletePod

func (siw *ServerInterfaceWrapper) DeletePod(w http.ResponseWriter, r *http.Request)

DeletePod operation middleware

func (*ServerInterfaceWrapper) DeleteService

func (siw *ServerInterfaceWrapper) DeleteService(w http.ResponseWriter, r *http.Request)

DeleteService operation middleware

func (*ServerInterfaceWrapper) DeleteUser

func (siw *ServerInterfaceWrapper) DeleteUser(w http.ResponseWriter, r *http.Request)

DeleteUser operation middleware

func (*ServerInterfaceWrapper) DeleteWorkload

func (siw *ServerInterfaceWrapper) DeleteWorkload(w http.ResponseWriter, r *http.Request)

DeleteWorkload operation middleware

func (*ServerInterfaceWrapper) GetAuthConfig

func (siw *ServerInterfaceWrapper) GetAuthConfig(w http.ResponseWriter, r *http.Request)

GetAuthConfig operation middleware

func (*ServerInterfaceWrapper) GetCluster

func (siw *ServerInterfaceWrapper) GetCluster(w http.ResponseWriter, r *http.Request)

GetCluster operation middleware

func (*ServerInterfaceWrapper) GetHealthz

func (siw *ServerInterfaceWrapper) GetHealthz(w http.ResponseWriter, r *http.Request)

GetHealthz operation middleware

func (*ServerInterfaceWrapper) GetImageOriginMapping added in v0.30.0

func (siw *ServerInterfaceWrapper) GetImageOriginMapping(w http.ResponseWriter, r *http.Request)

GetImageOriginMapping operation middleware

func (*ServerInterfaceWrapper) GetImageVersion

func (siw *ServerInterfaceWrapper) GetImageVersion(w http.ResponseWriter, r *http.Request)

GetImageVersion operation middleware

func (*ServerInterfaceWrapper) GetIngress

func (siw *ServerInterfaceWrapper) GetIngress(w http.ResponseWriter, r *http.Request)

GetIngress operation middleware

func (*ServerInterfaceWrapper) GetMe

GetMe operation middleware

func (*ServerInterfaceWrapper) GetNamespace

func (siw *ServerInterfaceWrapper) GetNamespace(w http.ResponseWriter, r *http.Request)

GetNamespace operation middleware

func (*ServerInterfaceWrapper) GetNode

GetNode operation middleware

func (*ServerInterfaceWrapper) GetPersistentVolume

func (siw *ServerInterfaceWrapper) GetPersistentVolume(w http.ResponseWriter, r *http.Request)

GetPersistentVolume operation middleware

func (*ServerInterfaceWrapper) GetPersistentVolumeClaim

func (siw *ServerInterfaceWrapper) GetPersistentVolumeClaim(w http.ResponseWriter, r *http.Request)

GetPersistentVolumeClaim operation middleware

func (*ServerInterfaceWrapper) GetPod

GetPod operation middleware

func (*ServerInterfaceWrapper) GetReadyz

func (siw *ServerInterfaceWrapper) GetReadyz(w http.ResponseWriter, r *http.Request)

GetReadyz operation middleware

func (*ServerInterfaceWrapper) GetService

func (siw *ServerInterfaceWrapper) GetService(w http.ResponseWriter, r *http.Request)

GetService operation middleware

func (*ServerInterfaceWrapper) GetUser

GetUser operation middleware

func (*ServerInterfaceWrapper) GetWorkload

func (siw *ServerInterfaceWrapper) GetWorkload(w http.ResponseWriter, r *http.Request)

GetWorkload operation middleware

func (*ServerInterfaceWrapper) ListApiTokens

func (siw *ServerInterfaceWrapper) ListApiTokens(w http.ResponseWriter, r *http.Request)

ListApiTokens operation middleware

func (*ServerInterfaceWrapper) ListAuditEvents

func (siw *ServerInterfaceWrapper) ListAuditEvents(w http.ResponseWriter, r *http.Request)

ListAuditEvents operation middleware

func (*ServerInterfaceWrapper) ListClusters

func (siw *ServerInterfaceWrapper) ListClusters(w http.ResponseWriter, r *http.Request)

ListClusters operation middleware

func (*ServerInterfaceWrapper) ListImageOriginMappings added in v0.30.0

func (siw *ServerInterfaceWrapper) ListImageOriginMappings(w http.ResponseWriter, r *http.Request)

ListImageOriginMappings operation middleware

func (*ServerInterfaceWrapper) ListImageRegistries

func (siw *ServerInterfaceWrapper) ListImageRegistries(w http.ResponseWriter, r *http.Request)

ListImageRegistries operation middleware

func (*ServerInterfaceWrapper) ListImageVersions

func (siw *ServerInterfaceWrapper) ListImageVersions(w http.ResponseWriter, r *http.Request)

ListImageVersions operation middleware

func (*ServerInterfaceWrapper) ListIngresses

func (siw *ServerInterfaceWrapper) ListIngresses(w http.ResponseWriter, r *http.Request)

ListIngresses operation middleware

func (*ServerInterfaceWrapper) ListNamespaces

func (siw *ServerInterfaceWrapper) ListNamespaces(w http.ResponseWriter, r *http.Request)

ListNamespaces operation middleware

func (*ServerInterfaceWrapper) ListNodes

func (siw *ServerInterfaceWrapper) ListNodes(w http.ResponseWriter, r *http.Request)

ListNodes operation middleware

func (*ServerInterfaceWrapper) ListPersistentVolumeClaims

func (siw *ServerInterfaceWrapper) ListPersistentVolumeClaims(w http.ResponseWriter, r *http.Request)

ListPersistentVolumeClaims operation middleware

func (*ServerInterfaceWrapper) ListPersistentVolumes

func (siw *ServerInterfaceWrapper) ListPersistentVolumes(w http.ResponseWriter, r *http.Request)

ListPersistentVolumes operation middleware

func (*ServerInterfaceWrapper) ListPods

func (siw *ServerInterfaceWrapper) ListPods(w http.ResponseWriter, r *http.Request)

ListPods operation middleware

func (*ServerInterfaceWrapper) ListServices

func (siw *ServerInterfaceWrapper) ListServices(w http.ResponseWriter, r *http.Request)

ListServices operation middleware

func (*ServerInterfaceWrapper) ListSessions

func (siw *ServerInterfaceWrapper) ListSessions(w http.ResponseWriter, r *http.Request)

ListSessions operation middleware

func (*ServerInterfaceWrapper) ListUsers

func (siw *ServerInterfaceWrapper) ListUsers(w http.ResponseWriter, r *http.Request)

ListUsers operation middleware

func (*ServerInterfaceWrapper) ListWorkloads

func (siw *ServerInterfaceWrapper) ListWorkloads(w http.ResponseWriter, r *http.Request)

ListWorkloads operation middleware

func (*ServerInterfaceWrapper) Login

Login operation middleware

func (*ServerInterfaceWrapper) Logout

Logout operation middleware

func (*ServerInterfaceWrapper) OidcAuthorize

func (siw *ServerInterfaceWrapper) OidcAuthorize(w http.ResponseWriter, r *http.Request)

OidcAuthorize operation middleware

func (*ServerInterfaceWrapper) OidcCallback

func (siw *ServerInterfaceWrapper) OidcCallback(w http.ResponseWriter, r *http.Request)

OidcCallback operation middleware

func (*ServerInterfaceWrapper) PatchImageOriginMapping added in v0.30.0

func (siw *ServerInterfaceWrapper) PatchImageOriginMapping(w http.ResponseWriter, r *http.Request)

PatchImageOriginMapping operation middleware

func (*ServerInterfaceWrapper) PatchImageRegistry

func (siw *ServerInterfaceWrapper) PatchImageRegistry(w http.ResponseWriter, r *http.Request)

PatchImageRegistry operation middleware

func (*ServerInterfaceWrapper) ReconcileIngresses

func (siw *ServerInterfaceWrapper) ReconcileIngresses(w http.ResponseWriter, r *http.Request)

ReconcileIngresses operation middleware

func (*ServerInterfaceWrapper) ReconcileNamespaces

func (siw *ServerInterfaceWrapper) ReconcileNamespaces(w http.ResponseWriter, r *http.Request)

ReconcileNamespaces operation middleware

func (*ServerInterfaceWrapper) ReconcileNetworkPolicies added in v1.4.0

func (siw *ServerInterfaceWrapper) ReconcileNetworkPolicies(w http.ResponseWriter, r *http.Request)

ReconcileNetworkPolicies operation middleware

func (*ServerInterfaceWrapper) ReconcileNodes

func (siw *ServerInterfaceWrapper) ReconcileNodes(w http.ResponseWriter, r *http.Request)

ReconcileNodes operation middleware

func (*ServerInterfaceWrapper) ReconcilePersistentVolumeClaims

func (siw *ServerInterfaceWrapper) ReconcilePersistentVolumeClaims(w http.ResponseWriter, r *http.Request)

ReconcilePersistentVolumeClaims operation middleware

func (*ServerInterfaceWrapper) ReconcilePersistentVolumes

func (siw *ServerInterfaceWrapper) ReconcilePersistentVolumes(w http.ResponseWriter, r *http.Request)

ReconcilePersistentVolumes operation middleware

func (*ServerInterfaceWrapper) ReconcilePods

func (siw *ServerInterfaceWrapper) ReconcilePods(w http.ResponseWriter, r *http.Request)

ReconcilePods operation middleware

func (*ServerInterfaceWrapper) ReconcileServices

func (siw *ServerInterfaceWrapper) ReconcileServices(w http.ResponseWriter, r *http.Request)

ReconcileServices operation middleware

func (*ServerInterfaceWrapper) ReconcileWorkloads

func (siw *ServerInterfaceWrapper) ReconcileWorkloads(w http.ResponseWriter, r *http.Request)

ReconcileWorkloads operation middleware

func (*ServerInterfaceWrapper) RefreshImageVersions

func (siw *ServerInterfaceWrapper) RefreshImageVersions(w http.ResponseWriter, r *http.Request)

RefreshImageVersions operation middleware

func (*ServerInterfaceWrapper) RevokeApiToken

func (siw *ServerInterfaceWrapper) RevokeApiToken(w http.ResponseWriter, r *http.Request)

RevokeApiToken operation middleware

func (*ServerInterfaceWrapper) RevokeSession

func (siw *ServerInterfaceWrapper) RevokeSession(w http.ResponseWriter, r *http.Request)

RevokeSession operation middleware

func (*ServerInterfaceWrapper) UpdateCluster

func (siw *ServerInterfaceWrapper) UpdateCluster(w http.ResponseWriter, r *http.Request)

UpdateCluster operation middleware

func (*ServerInterfaceWrapper) UpdateIngress

func (siw *ServerInterfaceWrapper) UpdateIngress(w http.ResponseWriter, r *http.Request)

UpdateIngress operation middleware

func (*ServerInterfaceWrapper) UpdateNamespace

func (siw *ServerInterfaceWrapper) UpdateNamespace(w http.ResponseWriter, r *http.Request)

UpdateNamespace operation middleware

func (*ServerInterfaceWrapper) UpdateNode

func (siw *ServerInterfaceWrapper) UpdateNode(w http.ResponseWriter, r *http.Request)

UpdateNode operation middleware

func (*ServerInterfaceWrapper) UpdatePersistentVolume

func (siw *ServerInterfaceWrapper) UpdatePersistentVolume(w http.ResponseWriter, r *http.Request)

UpdatePersistentVolume operation middleware

func (*ServerInterfaceWrapper) UpdatePersistentVolumeClaim

func (siw *ServerInterfaceWrapper) UpdatePersistentVolumeClaim(w http.ResponseWriter, r *http.Request)

UpdatePersistentVolumeClaim operation middleware

func (*ServerInterfaceWrapper) UpdatePod

func (siw *ServerInterfaceWrapper) UpdatePod(w http.ResponseWriter, r *http.Request)

UpdatePod operation middleware

func (*ServerInterfaceWrapper) UpdateService

func (siw *ServerInterfaceWrapper) UpdateService(w http.ResponseWriter, r *http.Request)

UpdateService operation middleware

func (*ServerInterfaceWrapper) UpdateUser

func (siw *ServerInterfaceWrapper) UpdateUser(w http.ResponseWriter, r *http.Request)

UpdateUser operation middleware

func (*ServerInterfaceWrapper) UpdateWorkload

func (siw *ServerInterfaceWrapper) UpdateWorkload(w http.ResponseWriter, r *http.Request)

UpdateWorkload operation middleware

func (*ServerInterfaceWrapper) VerifyToken

func (siw *ServerInterfaceWrapper) VerifyToken(w http.ResponseWriter, r *http.Request)

VerifyToken operation middleware

type Service

type Service struct {
	// ClusterId Denormalized `namespaces.cluster_id`. Null on orphans. See ADR-0027.
	ClusterId *openapi_types.UUID `json:"cluster_id,omitempty"`

	// ClusterIp Assigned ClusterIP (empty for Headless / ExternalName services).
	ClusterIp *string `json:"cluster_ip,omitempty"`

	// ClusterName Denormalized `clusters.name`. Null on orphans. See ADR-0027.
	ClusterName *string             `json:"cluster_name,omitempty"`
	CreatedAt   *time.Time          `json:"created_at,omitempty"`
	Id          *openapi_types.UUID `json:"id,omitempty"`

	// Labels Arbitrary user-supplied string key/value labels.
	Labels *map[string]string `json:"labels,omitempty"`

	// Layer Always `applicative` for Service. Set by the server.
	Layer *Layer `json:"layer,omitempty"`

	// LoadBalancer External load-balancer addresses, mirroring
	// `status.loadBalancer.ingress[]`. Only Services of type
	// `LoadBalancer` typically carry entries; other types leave
	// the array empty. On-prem populated by MetalLB / Kube-VIP /
	// hardware LB; managed clusters by the cloud controller.
	LoadBalancer *[]map[string]interface{} `json:"load_balancer,omitempty"`
	Name         string                    `json:"name"`
	NamespaceId  openapi_types.UUID        `json:"namespace_id"`

	// NamespaceName Denormalized `namespaces.name`. Null on orphans. See ADR-0027.
	NamespaceName *string `json:"namespace_name,omitempty"`

	// Ports Service ports. Opaque in v1: each entry carries whatever the
	// collector chose to persist (name, port, target_port, protocol, node_port).
	Ports *[]map[string]interface{} `json:"ports,omitempty"`

	// Selector Pod label selector. Pods matching every key/value are selected.
	Selector *map[string]string `json:"selector,omitempty"`

	// Type Kubernetes Service type. Casing matches the enum Kubernetes itself
	// emits. Open-ended at the schema layer to accommodate future additions;
	// handler validation enforces the v1 subset.
	Type      *ServiceType `json:"type,omitempty"`
	UpdatedAt *time.Time   `json:"updated_at,omitempty"`
}

Service defines model for Service.

type ServiceCreate

type ServiceCreate struct {
	// ClusterIp Assigned ClusterIP (empty for Headless / ExternalName services).
	ClusterIp *string `json:"cluster_ip,omitempty"`

	// Labels Arbitrary user-supplied string key/value labels.
	Labels *map[string]string `json:"labels,omitempty"`

	// LoadBalancer External load-balancer addresses, mirroring
	// `status.loadBalancer.ingress[]`. Only Services of type
	// `LoadBalancer` typically carry entries; other types leave
	// the array empty. On-prem populated by MetalLB / Kube-VIP /
	// hardware LB; managed clusters by the cloud controller.
	LoadBalancer *[]map[string]interface{} `json:"load_balancer,omitempty"`

	// Name Kubernetes service name (DNS-label style). Unique per namespace.
	// Immutable after creation.
	Name string `json:"name"`

	// NamespaceId Parent namespace id. Immutable after creation; the namespace
	// must already exist or the create returns 404.
	NamespaceId openapi_types.UUID `json:"namespace_id"`

	// Ports Service ports. Opaque in v1: each entry carries whatever the
	// collector chose to persist (name, port, target_port, protocol, node_port).
	Ports *[]map[string]interface{} `json:"ports,omitempty"`

	// Selector Pod label selector. Pods matching every key/value are selected.
	Selector *map[string]string `json:"selector,omitempty"`

	// Type Kubernetes Service type. Casing matches the enum Kubernetes itself
	// emits. Open-ended at the schema layer to accommodate future additions;
	// handler validation enforces the v1 subset.
	Type *ServiceType `json:"type,omitempty"`
}

ServiceCreate defines model for ServiceCreate.

type ServiceId

type ServiceId = openapi_types.UUID

ServiceId defines model for ServiceId.

type ServiceList

type ServiceList struct {
	Items []Service `json:"items"`

	// NextCursor Opaque cursor to pass as `?cursor=` to fetch the next page.
	// Absent or null when no more pages remain.
	NextCursor *string `json:"next_cursor,omitempty"`
}

ServiceList Paged list of services.

type ServiceListFilter added in v1.10.0

type ServiceListFilter struct {
	NamespaceID *uuid.UUID
	Name        *string
}

ServiceListFilter is the predicate set accepted by ListServices.

type ServiceMutable

type ServiceMutable struct {
	// ClusterIp Assigned ClusterIP (empty for Headless / ExternalName services).
	ClusterIp *string `json:"cluster_ip,omitempty"`

	// Labels Arbitrary user-supplied string key/value labels.
	Labels *map[string]string `json:"labels,omitempty"`

	// LoadBalancer External load-balancer addresses, mirroring
	// `status.loadBalancer.ingress[]`. Only Services of type
	// `LoadBalancer` typically carry entries; other types leave
	// the array empty. On-prem populated by MetalLB / Kube-VIP /
	// hardware LB; managed clusters by the cloud controller.
	LoadBalancer *[]map[string]interface{} `json:"load_balancer,omitempty"`

	// Ports Service ports. Opaque in v1: each entry carries whatever the
	// collector chose to persist (name, port, target_port, protocol, node_port).
	Ports *[]map[string]interface{} `json:"ports,omitempty"`

	// Selector Pod label selector. Pods matching every key/value are selected.
	Selector *map[string]string `json:"selector,omitempty"`

	// Type Kubernetes Service type. Casing matches the enum Kubernetes itself
	// emits. Open-ended at the schema layer to accommodate future additions;
	// handler validation enforces the v1 subset.
	Type *ServiceType `json:"type,omitempty"`
}

ServiceMutable Fields on a Service that clients may set and later update.

type ServiceNamespaceIdFilter

type ServiceNamespaceIdFilter = openapi_types.UUID

ServiceNamespaceIdFilter defines model for ServiceNamespaceIdFilter.

type ServiceStore added in v1.6.2

type ServiceStore interface {
	// CreateService inserts a new service.
	CreateService(ctx context.Context, in ServiceCreate) (Service, error)

	// GetService fetches a service by id.
	GetService(ctx context.Context, id uuid.UUID) (Service, error)

	// ListServices returns a cursor-paginated page of services, optionally
	// filtered by namespace and/or name. See ServiceListFilter for the
	// accepted predicates.
	ListServices(ctx context.Context, filter ServiceListFilter, page ListPage) (items []Service, nextCursor string, err error)

	// UpdateService applies merge-patch.
	UpdateService(ctx context.Context, id uuid.UUID, in ServiceUpdate) (Service, error)

	// DeleteService removes by id.
	DeleteService(ctx context.Context, id uuid.UUID) error

	// UpsertService mirrors UpsertPod; keyed on (namespace_id, name). The second
	// return value classifies the operation for audit filtering (ADR-0024):
	// OutcomeInserted for a fresh insert, OutcomeBusinessChanged when a
	// business field changed, OutcomeNoChange when only clock fields moved.
	UpsertService(ctx context.Context, in ServiceCreate) (Service, UpsertOutcome, error)

	// DeleteServicesNotIn mirrors DeletePodsNotIn, scoped to a single namespace.
	DeleteServicesNotIn(ctx context.Context, namespaceID uuid.UUID, keepNames []string) (int64, error)
}

ServiceStore covers service CRUD, upsert, and reconcile.

type ServiceType

type ServiceType string

ServiceType Kubernetes Service type. Casing matches the enum Kubernetes itself emits. Open-ended at the schema layer to accommodate future additions; handler validation enforces the v1 subset.

const (
	ClusterIP    ServiceType = "ClusterIP"
	ExternalName ServiceType = "ExternalName"
	LoadBalancer ServiceType = "LoadBalancer"
	NodePort     ServiceType = "NodePort"
)

Defines values for ServiceType.

func (ServiceType) Valid

func (e ServiceType) Valid() bool

Valid indicates whether the value is a known member of the ServiceType enum.

type ServiceUpdate

type ServiceUpdate = ServiceMutable

ServiceUpdate Fields on a Service that clients may set and later update.

type Session

type Session struct {
	CreatedAt time.Time `json:"created_at"`
	ExpiresAt time.Time `json:"expires_at"`

	// Id Session identifier. Only the prefix is shown to admins;
	// the full id is never leaked in a list response.
	Id         string             `json:"id"`
	LastUsedAt time.Time          `json:"last_used_at"`
	SourceIp   *string            `json:"source_ip,omitempty"`
	UserAgent  *string            `json:"user_agent,omitempty"`
	UserId     openapi_types.UUID `json:"user_id"`

	// Username Denormalised for admin convenience.
	Username *string `json:"username,omitempty"`
}

Session An active human session.

type SessionId

type SessionId = string

SessionId defines model for SessionId.

type SessionInsert

type SessionInsert struct {
	ID        string
	UserID    uuid.UUID
	CreatedAt time.Time
	ExpiresAt time.Time
	UserAgent string
	SourceIP  string
}

SessionInsert carries the data for a new session row. The id field doubles as the cookie value; it's generated by the login handler and handed to CreateSession to persist.

type SessionList

type SessionList struct {
	Items      []Session `json:"items"`
	NextCursor *string   `json:"next_cursor,omitempty"`
}

SessionList Paged list of active sessions.

type SessionListFilter added in v1.10.0

type SessionListFilter struct {
	Name *string
}

SessionListFilter is the predicate set accepted by ListSessions. Name matches the owning user's username (case-insensitive).

type Settings

type Settings struct {
	EOLEnabled              bool      `json:"eol_enabled"`
	MCPEnabled              bool      `json:"mcp_enabled"`
	TimeTravelEnabled       bool      `json:"time_travel_enabled"`
	TimeTravelRetentionDays int       `json:"time_travel_retention_days"`
	TimeTravelReaperEnabled bool      `json:"time_travel_reaper_enabled"`
	ImageVersionsEnabled    bool      `json:"image_versions_enabled"`
	FlowMatrixEnabled       bool      `json:"flow_matrix_enabled"`
	PoliciesEnabled         bool      `json:"policies_enabled"`
	ClusterStaleAfterDays   int       `json:"cluster_stale_after_days"`
	UpdatedAt               time.Time `json:"updated_at"`
}

Settings holds runtime feature toggles stored in the single-row settings table.

type SettingsPatch

type SettingsPatch struct {
	EOLEnabled              *bool `json:"eol_enabled,omitempty"`
	MCPEnabled              *bool `json:"mcp_enabled,omitempty"`
	TimeTravelEnabled       *bool `json:"time_travel_enabled,omitempty"`
	TimeTravelRetentionDays *int  `json:"time_travel_retention_days,omitempty"`
	TimeTravelReaperEnabled *bool `json:"time_travel_reaper_enabled,omitempty"`
	ImageVersionsEnabled    *bool `json:"image_versions_enabled,omitempty"`
	FlowMatrixEnabled       *bool `json:"flow_matrix_enabled,omitempty"`
	PoliciesEnabled         *bool `json:"policies_enabled,omitempty"`
	ClusterStaleAfterDays   *int  `json:"cluster_stale_after_days,omitempty"`
}

SettingsPatch is the merge-patch for UpdateSettings. Nil fields are left unchanged.

type SettingsStore added in v1.6.2

type SettingsStore interface {
	// GetSettings returns the current runtime settings (single-row table).
	GetSettings(ctx context.Context) (Settings, error)

	// UpdateSettings applies the merge-patch on the settings row.
	UpdateSettings(ctx context.Context, in SettingsPatch) (Settings, error)
}

SettingsStore covers the single-row runtime feature-toggle table.

type SortKey added in v1.10.0

type SortKey = string

SortKey defines model for SortKey.

type SortOrder added in v1.10.0

type SortOrder string

SortOrder defines model for SortOrder.

const (
	SortOrderAsc  SortOrder = "asc"
	SortOrderDesc SortOrder = "desc"
)

Defines values for SortOrder.

func (SortOrder) Valid added in v1.10.0

func (e SortOrder) Valid() bool

Valid indicates whether the value is a known member of the SortOrder enum.

type StdHTTPServerOptions

type StdHTTPServerOptions struct {
	BaseURL          string
	BaseRouter       ServeMux
	Middlewares      []MiddlewareFunc
	ErrorHandlerFunc func(w http.ResponseWriter, r *http.Request, err error)
}

type Store

Store is the persistence contract consumed by the REST handlers, composed of per-domain interfaces so callers and test doubles can depend on just the slice they use. Implementations must be safe for concurrent use by multiple goroutines.

type StoreListImageOriginMappingsParams added in v0.30.0

type StoreListImageOriginMappingsParams struct {
	Limit          int
	Cursor         string
	PublicRegistry string // exact match; empty = no filter
	Q              string // case-insensitive substring on image_name
}

StoreListImageOriginMappingsParams carries cursor-based pagination and optional filters for the store layer. Limit <= 0 means "default" (resolved in the store). This is distinct from the codegen-produced ListImageOriginMappingsParams which carries HTTP query-param pointers.

type StrictHTTPServerOptions

type StrictHTTPServerOptions struct {
	RequestErrorHandlerFunc  func(w http.ResponseWriter, r *http.Request, err error)
	ResponseErrorHandlerFunc func(w http.ResponseWriter, r *http.Request, err error)
}

type StrictHandlerFunc

type StrictHandlerFunc func(ctx context.Context, w http.ResponseWriter, r *http.Request, request any) (any, error)

func InjectRequestMiddleware

func InjectRequestMiddleware(
	f StrictHandlerFunc,
	_ string,
) StrictHandlerFunc

InjectRequestMiddleware is a StrictMiddlewareFunc that stores the *http.Request in the context so strict handlers can retrieve it.

type StrictMiddlewareFunc

type StrictMiddlewareFunc func(f StrictHandlerFunc, operationID string) StrictHandlerFunc

type StrictServerInterface

type StrictServerInterface interface {
	// Liveness probe
	// (GET /healthz)
	GetHealthz(ctx context.Context, request GetHealthzRequestObject) (GetHealthzResponseObject, error)
	// Readiness probe
	// (GET /readyz)
	GetReadyz(ctx context.Context, request GetReadyzRequestObject) (GetReadyzResponseObject, error)
	// List audit events
	// (GET /v1/admin/audit)
	ListAuditEvents(ctx context.Context, request ListAuditEventsRequestObject) (ListAuditEventsResponseObject, error)
	// List operator-curated image_name → public_registry mappings (ADR-0030)
	// (GET /v1/admin/image-origin-mappings)
	ListImageOriginMappings(ctx context.Context, request ListImageOriginMappingsRequestObject) (ListImageOriginMappingsResponseObject, error)
	// Create an image_name → public_registry mapping (ADR-0030)
	// (POST /v1/admin/image-origin-mappings)
	CreateImageOriginMapping(ctx context.Context, request CreateImageOriginMappingRequestObject) (CreateImageOriginMappingResponseObject, error)
	// Delete an image origin mapping
	// (DELETE /v1/admin/image-origin-mappings/{image_name})
	DeleteImageOriginMapping(ctx context.Context, request DeleteImageOriginMappingRequestObject) (DeleteImageOriginMappingResponseObject, error)
	// Get one image origin mapping
	// (GET /v1/admin/image-origin-mappings/{image_name})
	GetImageOriginMapping(ctx context.Context, request GetImageOriginMappingRequestObject) (GetImageOriginMappingResponseObject, error)
	// Update an image origin mapping (merge-patch)
	// (PATCH /v1/admin/image-origin-mappings/{image_name})
	PatchImageOriginMapping(ctx context.Context, request PatchImageOriginMappingRequestObject) (PatchImageOriginMappingResponseObject, error)
	// List the supported registries allowlist
	// (GET /v1/admin/image-versions/registries)
	ListImageRegistries(ctx context.Context, request ListImageRegistriesRequestObject) (ListImageRegistriesResponseObject, error)
	// Add a registry to the allowlist
	// (POST /v1/admin/image-versions/registries)
	CreateImageRegistry(ctx context.Context, request CreateImageRegistryRequestObject) (CreateImageRegistryResponseObject, error)
	// Remove a registry from the allowlist
	// (DELETE /v1/admin/image-versions/registries/{hostname}/{path_prefix})
	DeleteImageRegistry(ctx context.Context, request DeleteImageRegistryRequestObject) (DeleteImageRegistryResponseObject, error)
	// Update a registry's rate limit, enabled flag, or notes
	// (PATCH /v1/admin/image-versions/registries/{hostname}/{path_prefix})
	PatchImageRegistry(ctx context.Context, request PatchImageRegistryRequestObject) (PatchImageRegistryResponseObject, error)
	// List active human sessions
	// (GET /v1/admin/sessions)
	ListSessions(ctx context.Context, request ListSessionsRequestObject) (ListSessionsResponseObject, error)
	// Revoke an active session
	// (DELETE /v1/admin/sessions/{id})
	RevokeSession(ctx context.Context, request RevokeSessionRequestObject) (RevokeSessionResponseObject, error)
	// List machine tokens (metadata only — plaintext never leaves creation)
	// (GET /v1/admin/tokens)
	ListApiTokens(ctx context.Context, request ListApiTokensRequestObject) (ListApiTokensResponseObject, error)
	// Mint a new machine token
	// (POST /v1/admin/tokens)
	CreateApiToken(ctx context.Context, request CreateApiTokenRequestObject) (CreateApiTokenResponseObject, error)
	// Revoke a machine token
	// (DELETE /v1/admin/tokens/{id})
	RevokeApiToken(ctx context.Context, request RevokeApiTokenRequestObject) (RevokeApiTokenResponseObject, error)
	// List human users
	// (GET /v1/admin/users)
	ListUsers(ctx context.Context, request ListUsersRequestObject) (ListUsersResponseObject, error)
	// Create a human user
	// (POST /v1/admin/users)
	CreateUser(ctx context.Context, request CreateUserRequestObject) (CreateUserResponseObject, error)
	// Delete a user
	// (DELETE /v1/admin/users/{id})
	DeleteUser(ctx context.Context, request DeleteUserRequestObject) (DeleteUserResponseObject, error)
	// Get a user
	// (GET /v1/admin/users/{id})
	GetUser(ctx context.Context, request GetUserRequestObject) (GetUserResponseObject, error)
	// Update a user's role, password, disabled, or lockout state
	// (PATCH /v1/admin/users/{id})
	UpdateUser(ctx context.Context, request UpdateUserRequestObject) (UpdateUserResponseObject, error)
	// Change the current user's password
	// (POST /v1/auth/change-password)
	ChangePassword(ctx context.Context, request ChangePasswordRequestObject) (ChangePasswordResponseObject, error)
	// Public auth configuration the UI needs pre-login
	// (GET /v1/auth/config)
	GetAuthConfig(ctx context.Context, request GetAuthConfigRequestObject) (GetAuthConfigResponseObject, error)
	// Start a human session
	// (POST /v1/auth/login)
	Login(ctx context.Context, request LoginRequestObject) (LoginResponseObject, error)
	// End the current human session
	// (POST /v1/auth/logout)
	Logout(ctx context.Context, request LogoutRequestObject) (LogoutResponseObject, error)
	// Who am I, and what can I do
	// (GET /v1/auth/me)
	GetMe(ctx context.Context, request GetMeRequestObject) (GetMeResponseObject, error)
	// Start the OIDC authorization-code flow
	// (GET /v1/auth/oidc/authorize)
	OidcAuthorize(ctx context.Context, request OidcAuthorizeRequestObject) (OidcAuthorizeResponseObject, error)
	// Complete the OIDC authorization-code flow
	// (GET /v1/auth/oidc/callback)
	OidcCallback(ctx context.Context, request OidcCallbackRequestObject) (OidcCallbackResponseObject, error)
	// Verify a bearer token
	// (POST /v1/auth/verify)
	VerifyToken(ctx context.Context, request VerifyTokenRequestObject) (VerifyTokenResponseObject, error)
	// List clusters
	// (GET /v1/clusters)
	ListClusters(ctx context.Context, request ListClustersRequestObject) (ListClustersResponseObject, error)
	// Register or ensure a cluster
	// (POST /v1/clusters)
	CreateCluster(ctx context.Context, request CreateClusterRequestObject) (CreateClusterResponseObject, error)
	// Delete a cluster
	// (DELETE /v1/clusters/{id})
	DeleteCluster(ctx context.Context, request DeleteClusterRequestObject) (DeleteClusterResponseObject, error)
	// Get a cluster
	// (GET /v1/clusters/{id})
	GetCluster(ctx context.Context, request GetClusterRequestObject) (GetClusterResponseObject, error)
	// Update mutable fields of a cluster
	// (PATCH /v1/clusters/{id})
	UpdateCluster(ctx context.Context, request UpdateClusterRequestObject) (UpdateClusterResponseObject, error)
	// List enriched container images with their latest tags
	// (GET /v1/image-versions)
	ListImageVersions(ctx context.Context, request ListImageVersionsRequestObject) (ListImageVersionsResponseObject, error)
	// Trigger an immediate enrichment cycle (admin only)
	// (POST /v1/image-versions/refresh)
	RefreshImageVersions(ctx context.Context, request RefreshImageVersionsRequestObject) (RefreshImageVersionsResponseObject, error)
	// Get one image's enrichment (all variants)
	// (GET /v1/image-versions/{image_repo})
	GetImageVersion(ctx context.Context, request GetImageVersionRequestObject) (GetImageVersionResponseObject, error)
	// List ingresses
	// (GET /v1/ingresses)
	ListIngresses(ctx context.Context, request ListIngressesRequestObject) (ListIngressesResponseObject, error)
	// Register an ingress
	// (POST /v1/ingresses)
	CreateIngress(ctx context.Context, request CreateIngressRequestObject) (CreateIngressResponseObject, error)
	// Reconcile ingresses for a namespace
	// (POST /v1/ingresses/reconcile)
	ReconcileIngresses(ctx context.Context, request ReconcileIngressesRequestObject) (ReconcileIngressesResponseObject, error)
	// Delete an ingress
	// (DELETE /v1/ingresses/{id})
	DeleteIngress(ctx context.Context, request DeleteIngressRequestObject) (DeleteIngressResponseObject, error)
	// Get an ingress
	// (GET /v1/ingresses/{id})
	GetIngress(ctx context.Context, request GetIngressRequestObject) (GetIngressResponseObject, error)
	// Update mutable fields of an ingress
	// (PATCH /v1/ingresses/{id})
	UpdateIngress(ctx context.Context, request UpdateIngressRequestObject) (UpdateIngressResponseObject, error)
	// List namespaces
	// (GET /v1/namespaces)
	ListNamespaces(ctx context.Context, request ListNamespacesRequestObject) (ListNamespacesResponseObject, error)
	// Register a namespace
	// (POST /v1/namespaces)
	CreateNamespace(ctx context.Context, request CreateNamespaceRequestObject) (CreateNamespaceResponseObject, error)
	// Reconcile namespaces for a cluster
	// (POST /v1/namespaces/reconcile)
	ReconcileNamespaces(ctx context.Context, request ReconcileNamespacesRequestObject) (ReconcileNamespacesResponseObject, error)
	// Delete a namespace
	// (DELETE /v1/namespaces/{id})
	DeleteNamespace(ctx context.Context, request DeleteNamespaceRequestObject) (DeleteNamespaceResponseObject, error)
	// Get a namespace
	// (GET /v1/namespaces/{id})
	GetNamespace(ctx context.Context, request GetNamespaceRequestObject) (GetNamespaceResponseObject, error)
	// Update mutable fields of a namespace
	// (PATCH /v1/namespaces/{id})
	UpdateNamespace(ctx context.Context, request UpdateNamespaceRequestObject) (UpdateNamespaceResponseObject, error)
	// Upsert a NetworkPolicy with its rules atomically (push-mode collector)
	// (POST /v1/network-policies)
	CreateNetworkPolicy(ctx context.Context, request CreateNetworkPolicyRequestObject) (CreateNetworkPolicyResponseObject, error)
	// Sweep NetworkPolicies by namespace (push-mode collector)
	// (POST /v1/network-policies/reconcile)
	ReconcileNetworkPolicies(ctx context.Context, request ReconcileNetworkPoliciesRequestObject) (ReconcileNetworkPoliciesResponseObject, error)
	// List nodes
	// (GET /v1/nodes)
	ListNodes(ctx context.Context, request ListNodesRequestObject) (ListNodesResponseObject, error)
	// Register a node
	// (POST /v1/nodes)
	CreateNode(ctx context.Context, request CreateNodeRequestObject) (CreateNodeResponseObject, error)
	// Reconcile nodes for a cluster
	// (POST /v1/nodes/reconcile)
	ReconcileNodes(ctx context.Context, request ReconcileNodesRequestObject) (ReconcileNodesResponseObject, error)
	// Delete a node
	// (DELETE /v1/nodes/{id})
	DeleteNode(ctx context.Context, request DeleteNodeRequestObject) (DeleteNodeResponseObject, error)
	// Get a node
	// (GET /v1/nodes/{id})
	GetNode(ctx context.Context, request GetNodeRequestObject) (GetNodeResponseObject, error)
	// Update mutable fields of a node
	// (PATCH /v1/nodes/{id})
	UpdateNode(ctx context.Context, request UpdateNodeRequestObject) (UpdateNodeResponseObject, error)
	// List persistent volume claims
	// (GET /v1/persistentvolumeclaims)
	ListPersistentVolumeClaims(ctx context.Context, request ListPersistentVolumeClaimsRequestObject) (ListPersistentVolumeClaimsResponseObject, error)
	// Register a persistent volume claim
	// (POST /v1/persistentvolumeclaims)
	CreatePersistentVolumeClaim(ctx context.Context, request CreatePersistentVolumeClaimRequestObject) (CreatePersistentVolumeClaimResponseObject, error)
	// Reconcile PVCs for a namespace
	// (POST /v1/persistentvolumeclaims/reconcile)
	ReconcilePersistentVolumeClaims(ctx context.Context, request ReconcilePersistentVolumeClaimsRequestObject) (ReconcilePersistentVolumeClaimsResponseObject, error)
	// Delete a persistent volume claim
	// (DELETE /v1/persistentvolumeclaims/{id})
	DeletePersistentVolumeClaim(ctx context.Context, request DeletePersistentVolumeClaimRequestObject) (DeletePersistentVolumeClaimResponseObject, error)
	// Get a persistent volume claim
	// (GET /v1/persistentvolumeclaims/{id})
	GetPersistentVolumeClaim(ctx context.Context, request GetPersistentVolumeClaimRequestObject) (GetPersistentVolumeClaimResponseObject, error)
	// Update mutable fields of a persistent volume claim
	// (PATCH /v1/persistentvolumeclaims/{id})
	UpdatePersistentVolumeClaim(ctx context.Context, request UpdatePersistentVolumeClaimRequestObject) (UpdatePersistentVolumeClaimResponseObject, error)
	// List persistent volumes
	// (GET /v1/persistentvolumes)
	ListPersistentVolumes(ctx context.Context, request ListPersistentVolumesRequestObject) (ListPersistentVolumesResponseObject, error)
	// Register a persistent volume
	// (POST /v1/persistentvolumes)
	CreatePersistentVolume(ctx context.Context, request CreatePersistentVolumeRequestObject) (CreatePersistentVolumeResponseObject, error)
	// Reconcile persistent volumes for a cluster
	// (POST /v1/persistentvolumes/reconcile)
	ReconcilePersistentVolumes(ctx context.Context, request ReconcilePersistentVolumesRequestObject) (ReconcilePersistentVolumesResponseObject, error)
	// Delete a persistent volume
	// (DELETE /v1/persistentvolumes/{id})
	DeletePersistentVolume(ctx context.Context, request DeletePersistentVolumeRequestObject) (DeletePersistentVolumeResponseObject, error)
	// Get a persistent volume
	// (GET /v1/persistentvolumes/{id})
	GetPersistentVolume(ctx context.Context, request GetPersistentVolumeRequestObject) (GetPersistentVolumeResponseObject, error)
	// Update mutable fields of a persistent volume
	// (PATCH /v1/persistentvolumes/{id})
	UpdatePersistentVolume(ctx context.Context, request UpdatePersistentVolumeRequestObject) (UpdatePersistentVolumeResponseObject, error)
	// List pods
	// (GET /v1/pods)
	ListPods(ctx context.Context, request ListPodsRequestObject) (ListPodsResponseObject, error)
	// Register a pod
	// (POST /v1/pods)
	CreatePod(ctx context.Context, request CreatePodRequestObject) (CreatePodResponseObject, error)
	// Reconcile pods for a namespace
	// (POST /v1/pods/reconcile)
	ReconcilePods(ctx context.Context, request ReconcilePodsRequestObject) (ReconcilePodsResponseObject, error)
	// Delete a pod
	// (DELETE /v1/pods/{id})
	DeletePod(ctx context.Context, request DeletePodRequestObject) (DeletePodResponseObject, error)
	// Get a pod
	// (GET /v1/pods/{id})
	GetPod(ctx context.Context, request GetPodRequestObject) (GetPodResponseObject, error)
	// Update mutable fields of a pod
	// (PATCH /v1/pods/{id})
	UpdatePod(ctx context.Context, request UpdatePodRequestObject) (UpdatePodResponseObject, error)
	// List services
	// (GET /v1/services)
	ListServices(ctx context.Context, request ListServicesRequestObject) (ListServicesResponseObject, error)
	// Register a service
	// (POST /v1/services)
	CreateService(ctx context.Context, request CreateServiceRequestObject) (CreateServiceResponseObject, error)
	// Reconcile services for a namespace
	// (POST /v1/services/reconcile)
	ReconcileServices(ctx context.Context, request ReconcileServicesRequestObject) (ReconcileServicesResponseObject, error)
	// Delete a service
	// (DELETE /v1/services/{id})
	DeleteService(ctx context.Context, request DeleteServiceRequestObject) (DeleteServiceResponseObject, error)
	// Get a service
	// (GET /v1/services/{id})
	GetService(ctx context.Context, request GetServiceRequestObject) (GetServiceResponseObject, error)
	// Update mutable fields of a service
	// (PATCH /v1/services/{id})
	UpdateService(ctx context.Context, request UpdateServiceRequestObject) (UpdateServiceResponseObject, error)
	// List workloads
	// (GET /v1/workloads)
	ListWorkloads(ctx context.Context, request ListWorkloadsRequestObject) (ListWorkloadsResponseObject, error)
	// Register a workload
	// (POST /v1/workloads)
	CreateWorkload(ctx context.Context, request CreateWorkloadRequestObject) (CreateWorkloadResponseObject, error)
	// Reconcile workloads for a namespace
	// (POST /v1/workloads/reconcile)
	ReconcileWorkloads(ctx context.Context, request ReconcileWorkloadsRequestObject) (ReconcileWorkloadsResponseObject, error)
	// Delete a workload
	// (DELETE /v1/workloads/{id})
	DeleteWorkload(ctx context.Context, request DeleteWorkloadRequestObject) (DeleteWorkloadResponseObject, error)
	// Get a workload
	// (GET /v1/workloads/{id})
	GetWorkload(ctx context.Context, request GetWorkloadRequestObject) (GetWorkloadResponseObject, error)
	// Update mutable fields of a workload
	// (PATCH /v1/workloads/{id})
	UpdateWorkload(ctx context.Context, request UpdateWorkloadRequestObject) (UpdateWorkloadResponseObject, error)
}

StrictServerInterface represents all server handlers.

type TokenId

type TokenId = openapi_types.UUID

TokenId defines model for TokenId.

type TooManyValuesForParamError

type TooManyValuesForParamError struct {
	ParamName string
	Count     int
}

func (*TooManyValuesForParamError) Error

type Unauthorized

type Unauthorized = Problem

Unauthorized RFC 7807 problem details.

type UnauthorizedApplicationProblemPlusJSONResponse

type UnauthorizedApplicationProblemPlusJSONResponse Problem

type UnescapedCookieParamError

type UnescapedCookieParamError struct {
	ParamName string
	Err       error
}

func (*UnescapedCookieParamError) Error

func (e *UnescapedCookieParamError) Error() string

func (*UnescapedCookieParamError) Unwrap

func (e *UnescapedCookieParamError) Unwrap() error

type UnmarshalingParamError

type UnmarshalingParamError struct {
	ParamName string
	Err       error
}

func (*UnmarshalingParamError) Error

func (e *UnmarshalingParamError) Error() string

func (*UnmarshalingParamError) Unwrap

func (e *UnmarshalingParamError) Unwrap() error

type UnprocessableEntity added in v1.13.0

type UnprocessableEntity = Problem

UnprocessableEntity RFC 7807 problem details.

type UnprocessableEntityApplicationProblemPlusJSONResponse added in v1.13.0

type UnprocessableEntityApplicationProblemPlusJSONResponse Problem

type UpdateCluster200JSONResponse

type UpdateCluster200JSONResponse Cluster

func (UpdateCluster200JSONResponse) VisitUpdateClusterResponse

func (response UpdateCluster200JSONResponse) VisitUpdateClusterResponse(w http.ResponseWriter) error

type UpdateCluster400ApplicationProblemPlusJSONResponse

type UpdateCluster400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (UpdateCluster400ApplicationProblemPlusJSONResponse) VisitUpdateClusterResponse

func (response UpdateCluster400ApplicationProblemPlusJSONResponse) VisitUpdateClusterResponse(w http.ResponseWriter) error

type UpdateCluster401ApplicationProblemPlusJSONResponse

type UpdateCluster401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (UpdateCluster401ApplicationProblemPlusJSONResponse) VisitUpdateClusterResponse

func (response UpdateCluster401ApplicationProblemPlusJSONResponse) VisitUpdateClusterResponse(w http.ResponseWriter) error

type UpdateCluster403ApplicationProblemPlusJSONResponse

type UpdateCluster403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (UpdateCluster403ApplicationProblemPlusJSONResponse) VisitUpdateClusterResponse

func (response UpdateCluster403ApplicationProblemPlusJSONResponse) VisitUpdateClusterResponse(w http.ResponseWriter) error

type UpdateCluster404ApplicationProblemPlusJSONResponse

type UpdateCluster404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (UpdateCluster404ApplicationProblemPlusJSONResponse) VisitUpdateClusterResponse

func (response UpdateCluster404ApplicationProblemPlusJSONResponse) VisitUpdateClusterResponse(w http.ResponseWriter) error

type UpdateClusterApplicationMergePatchPlusJSONRequestBody

type UpdateClusterApplicationMergePatchPlusJSONRequestBody = ClusterUpdate

UpdateClusterApplicationMergePatchPlusJSONRequestBody defines body for UpdateCluster for application/merge-patch+json ContentType.

type UpdateClusterRequestObject

type UpdateClusterRequestObject struct {
	Id   ClusterId `json:"id"`
	Body *UpdateClusterApplicationMergePatchPlusJSONRequestBody
}

type UpdateClusterResponseObject

type UpdateClusterResponseObject interface {
	VisitUpdateClusterResponse(w http.ResponseWriter) error
}

type UpdateIngress200JSONResponse

type UpdateIngress200JSONResponse Ingress

func (UpdateIngress200JSONResponse) VisitUpdateIngressResponse

func (response UpdateIngress200JSONResponse) VisitUpdateIngressResponse(w http.ResponseWriter) error

type UpdateIngress400ApplicationProblemPlusJSONResponse

type UpdateIngress400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (UpdateIngress400ApplicationProblemPlusJSONResponse) VisitUpdateIngressResponse

func (response UpdateIngress400ApplicationProblemPlusJSONResponse) VisitUpdateIngressResponse(w http.ResponseWriter) error

type UpdateIngress401ApplicationProblemPlusJSONResponse

type UpdateIngress401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (UpdateIngress401ApplicationProblemPlusJSONResponse) VisitUpdateIngressResponse

func (response UpdateIngress401ApplicationProblemPlusJSONResponse) VisitUpdateIngressResponse(w http.ResponseWriter) error

type UpdateIngress403ApplicationProblemPlusJSONResponse

type UpdateIngress403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (UpdateIngress403ApplicationProblemPlusJSONResponse) VisitUpdateIngressResponse

func (response UpdateIngress403ApplicationProblemPlusJSONResponse) VisitUpdateIngressResponse(w http.ResponseWriter) error

type UpdateIngress404ApplicationProblemPlusJSONResponse

type UpdateIngress404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (UpdateIngress404ApplicationProblemPlusJSONResponse) VisitUpdateIngressResponse

func (response UpdateIngress404ApplicationProblemPlusJSONResponse) VisitUpdateIngressResponse(w http.ResponseWriter) error

type UpdateIngressApplicationMergePatchPlusJSONRequestBody

type UpdateIngressApplicationMergePatchPlusJSONRequestBody = IngressUpdate

UpdateIngressApplicationMergePatchPlusJSONRequestBody defines body for UpdateIngress for application/merge-patch+json ContentType.

type UpdateIngressRequestObject

type UpdateIngressRequestObject struct {
	Id   IngressId `json:"id"`
	Body *UpdateIngressApplicationMergePatchPlusJSONRequestBody
}

type UpdateIngressResponseObject

type UpdateIngressResponseObject interface {
	VisitUpdateIngressResponse(w http.ResponseWriter) error
}

type UpdateNamespace200JSONResponse

type UpdateNamespace200JSONResponse Namespace

func (UpdateNamespace200JSONResponse) VisitUpdateNamespaceResponse

func (response UpdateNamespace200JSONResponse) VisitUpdateNamespaceResponse(w http.ResponseWriter) error

type UpdateNamespace400ApplicationProblemPlusJSONResponse

type UpdateNamespace400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (UpdateNamespace400ApplicationProblemPlusJSONResponse) VisitUpdateNamespaceResponse

func (response UpdateNamespace400ApplicationProblemPlusJSONResponse) VisitUpdateNamespaceResponse(w http.ResponseWriter) error

type UpdateNamespace401ApplicationProblemPlusJSONResponse

type UpdateNamespace401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (UpdateNamespace401ApplicationProblemPlusJSONResponse) VisitUpdateNamespaceResponse

func (response UpdateNamespace401ApplicationProblemPlusJSONResponse) VisitUpdateNamespaceResponse(w http.ResponseWriter) error

type UpdateNamespace403ApplicationProblemPlusJSONResponse

type UpdateNamespace403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (UpdateNamespace403ApplicationProblemPlusJSONResponse) VisitUpdateNamespaceResponse

func (response UpdateNamespace403ApplicationProblemPlusJSONResponse) VisitUpdateNamespaceResponse(w http.ResponseWriter) error

type UpdateNamespace404ApplicationProblemPlusJSONResponse

type UpdateNamespace404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (UpdateNamespace404ApplicationProblemPlusJSONResponse) VisitUpdateNamespaceResponse

func (response UpdateNamespace404ApplicationProblemPlusJSONResponse) VisitUpdateNamespaceResponse(w http.ResponseWriter) error

type UpdateNamespaceApplicationMergePatchPlusJSONRequestBody

type UpdateNamespaceApplicationMergePatchPlusJSONRequestBody = NamespaceUpdate

UpdateNamespaceApplicationMergePatchPlusJSONRequestBody defines body for UpdateNamespace for application/merge-patch+json ContentType.

type UpdateNamespaceRequestObject

type UpdateNamespaceRequestObject struct {
	Id   NamespaceId `json:"id"`
	Body *UpdateNamespaceApplicationMergePatchPlusJSONRequestBody
}

type UpdateNamespaceResponseObject

type UpdateNamespaceResponseObject interface {
	VisitUpdateNamespaceResponse(w http.ResponseWriter) error
}

type UpdateNode200JSONResponse

type UpdateNode200JSONResponse Node

func (UpdateNode200JSONResponse) VisitUpdateNodeResponse

func (response UpdateNode200JSONResponse) VisitUpdateNodeResponse(w http.ResponseWriter) error

type UpdateNode400ApplicationProblemPlusJSONResponse

type UpdateNode400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (UpdateNode400ApplicationProblemPlusJSONResponse) VisitUpdateNodeResponse

func (response UpdateNode400ApplicationProblemPlusJSONResponse) VisitUpdateNodeResponse(w http.ResponseWriter) error

type UpdateNode401ApplicationProblemPlusJSONResponse

type UpdateNode401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (UpdateNode401ApplicationProblemPlusJSONResponse) VisitUpdateNodeResponse

func (response UpdateNode401ApplicationProblemPlusJSONResponse) VisitUpdateNodeResponse(w http.ResponseWriter) error

type UpdateNode403ApplicationProblemPlusJSONResponse

type UpdateNode403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (UpdateNode403ApplicationProblemPlusJSONResponse) VisitUpdateNodeResponse

func (response UpdateNode403ApplicationProblemPlusJSONResponse) VisitUpdateNodeResponse(w http.ResponseWriter) error

type UpdateNode404ApplicationProblemPlusJSONResponse

type UpdateNode404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (UpdateNode404ApplicationProblemPlusJSONResponse) VisitUpdateNodeResponse

func (response UpdateNode404ApplicationProblemPlusJSONResponse) VisitUpdateNodeResponse(w http.ResponseWriter) error

type UpdateNodeApplicationMergePatchPlusJSONRequestBody

type UpdateNodeApplicationMergePatchPlusJSONRequestBody = NodeUpdate

UpdateNodeApplicationMergePatchPlusJSONRequestBody defines body for UpdateNode for application/merge-patch+json ContentType.

type UpdateNodeRequestObject

type UpdateNodeRequestObject struct {
	Id   NodeId `json:"id"`
	Body *UpdateNodeApplicationMergePatchPlusJSONRequestBody
}

type UpdateNodeResponseObject

type UpdateNodeResponseObject interface {
	VisitUpdateNodeResponse(w http.ResponseWriter) error
}

type UpdatePersistentVolume200JSONResponse

type UpdatePersistentVolume200JSONResponse PersistentVolume

func (UpdatePersistentVolume200JSONResponse) VisitUpdatePersistentVolumeResponse

func (response UpdatePersistentVolume200JSONResponse) VisitUpdatePersistentVolumeResponse(w http.ResponseWriter) error

type UpdatePersistentVolume400ApplicationProblemPlusJSONResponse

type UpdatePersistentVolume400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (UpdatePersistentVolume400ApplicationProblemPlusJSONResponse) VisitUpdatePersistentVolumeResponse

func (response UpdatePersistentVolume400ApplicationProblemPlusJSONResponse) VisitUpdatePersistentVolumeResponse(w http.ResponseWriter) error

type UpdatePersistentVolume401ApplicationProblemPlusJSONResponse

type UpdatePersistentVolume401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (UpdatePersistentVolume401ApplicationProblemPlusJSONResponse) VisitUpdatePersistentVolumeResponse

func (response UpdatePersistentVolume401ApplicationProblemPlusJSONResponse) VisitUpdatePersistentVolumeResponse(w http.ResponseWriter) error

type UpdatePersistentVolume403ApplicationProblemPlusJSONResponse

type UpdatePersistentVolume403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (UpdatePersistentVolume403ApplicationProblemPlusJSONResponse) VisitUpdatePersistentVolumeResponse

func (response UpdatePersistentVolume403ApplicationProblemPlusJSONResponse) VisitUpdatePersistentVolumeResponse(w http.ResponseWriter) error

type UpdatePersistentVolume404ApplicationProblemPlusJSONResponse

type UpdatePersistentVolume404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (UpdatePersistentVolume404ApplicationProblemPlusJSONResponse) VisitUpdatePersistentVolumeResponse

func (response UpdatePersistentVolume404ApplicationProblemPlusJSONResponse) VisitUpdatePersistentVolumeResponse(w http.ResponseWriter) error

type UpdatePersistentVolumeApplicationMergePatchPlusJSONRequestBody

type UpdatePersistentVolumeApplicationMergePatchPlusJSONRequestBody = PersistentVolumeUpdate

UpdatePersistentVolumeApplicationMergePatchPlusJSONRequestBody defines body for UpdatePersistentVolume for application/merge-patch+json ContentType.

type UpdatePersistentVolumeClaim200JSONResponse

type UpdatePersistentVolumeClaim200JSONResponse PersistentVolumeClaim

func (UpdatePersistentVolumeClaim200JSONResponse) VisitUpdatePersistentVolumeClaimResponse

func (response UpdatePersistentVolumeClaim200JSONResponse) VisitUpdatePersistentVolumeClaimResponse(w http.ResponseWriter) error

type UpdatePersistentVolumeClaim400ApplicationProblemPlusJSONResponse

type UpdatePersistentVolumeClaim400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (UpdatePersistentVolumeClaim400ApplicationProblemPlusJSONResponse) VisitUpdatePersistentVolumeClaimResponse

func (response UpdatePersistentVolumeClaim400ApplicationProblemPlusJSONResponse) VisitUpdatePersistentVolumeClaimResponse(w http.ResponseWriter) error

type UpdatePersistentVolumeClaim401ApplicationProblemPlusJSONResponse

type UpdatePersistentVolumeClaim401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (UpdatePersistentVolumeClaim401ApplicationProblemPlusJSONResponse) VisitUpdatePersistentVolumeClaimResponse

func (response UpdatePersistentVolumeClaim401ApplicationProblemPlusJSONResponse) VisitUpdatePersistentVolumeClaimResponse(w http.ResponseWriter) error

type UpdatePersistentVolumeClaim403ApplicationProblemPlusJSONResponse

type UpdatePersistentVolumeClaim403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (UpdatePersistentVolumeClaim403ApplicationProblemPlusJSONResponse) VisitUpdatePersistentVolumeClaimResponse

func (response UpdatePersistentVolumeClaim403ApplicationProblemPlusJSONResponse) VisitUpdatePersistentVolumeClaimResponse(w http.ResponseWriter) error

type UpdatePersistentVolumeClaim404ApplicationProblemPlusJSONResponse

type UpdatePersistentVolumeClaim404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (UpdatePersistentVolumeClaim404ApplicationProblemPlusJSONResponse) VisitUpdatePersistentVolumeClaimResponse

func (response UpdatePersistentVolumeClaim404ApplicationProblemPlusJSONResponse) VisitUpdatePersistentVolumeClaimResponse(w http.ResponseWriter) error

type UpdatePersistentVolumeClaimApplicationMergePatchPlusJSONRequestBody

type UpdatePersistentVolumeClaimApplicationMergePatchPlusJSONRequestBody = PersistentVolumeClaimUpdate

UpdatePersistentVolumeClaimApplicationMergePatchPlusJSONRequestBody defines body for UpdatePersistentVolumeClaim for application/merge-patch+json ContentType.

type UpdatePersistentVolumeClaimRequestObject

type UpdatePersistentVolumeClaimRequestObject struct {
	Id   PersistentVolumeClaimId `json:"id"`
	Body *UpdatePersistentVolumeClaimApplicationMergePatchPlusJSONRequestBody
}

type UpdatePersistentVolumeClaimResponseObject

type UpdatePersistentVolumeClaimResponseObject interface {
	VisitUpdatePersistentVolumeClaimResponse(w http.ResponseWriter) error
}

type UpdatePersistentVolumeRequestObject

type UpdatePersistentVolumeRequestObject struct {
	Id   PersistentVolumeId `json:"id"`
	Body *UpdatePersistentVolumeApplicationMergePatchPlusJSONRequestBody
}

type UpdatePersistentVolumeResponseObject

type UpdatePersistentVolumeResponseObject interface {
	VisitUpdatePersistentVolumeResponse(w http.ResponseWriter) error
}

type UpdatePod200JSONResponse

type UpdatePod200JSONResponse Pod

func (UpdatePod200JSONResponse) VisitUpdatePodResponse

func (response UpdatePod200JSONResponse) VisitUpdatePodResponse(w http.ResponseWriter) error

type UpdatePod400ApplicationProblemPlusJSONResponse

type UpdatePod400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (UpdatePod400ApplicationProblemPlusJSONResponse) VisitUpdatePodResponse

func (response UpdatePod400ApplicationProblemPlusJSONResponse) VisitUpdatePodResponse(w http.ResponseWriter) error

type UpdatePod401ApplicationProblemPlusJSONResponse

type UpdatePod401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (UpdatePod401ApplicationProblemPlusJSONResponse) VisitUpdatePodResponse

func (response UpdatePod401ApplicationProblemPlusJSONResponse) VisitUpdatePodResponse(w http.ResponseWriter) error

type UpdatePod403ApplicationProblemPlusJSONResponse

type UpdatePod403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (UpdatePod403ApplicationProblemPlusJSONResponse) VisitUpdatePodResponse

func (response UpdatePod403ApplicationProblemPlusJSONResponse) VisitUpdatePodResponse(w http.ResponseWriter) error

type UpdatePod404ApplicationProblemPlusJSONResponse

type UpdatePod404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (UpdatePod404ApplicationProblemPlusJSONResponse) VisitUpdatePodResponse

func (response UpdatePod404ApplicationProblemPlusJSONResponse) VisitUpdatePodResponse(w http.ResponseWriter) error

type UpdatePodApplicationMergePatchPlusJSONRequestBody

type UpdatePodApplicationMergePatchPlusJSONRequestBody = PodUpdate

UpdatePodApplicationMergePatchPlusJSONRequestBody defines body for UpdatePod for application/merge-patch+json ContentType.

type UpdatePodRequestObject

type UpdatePodRequestObject struct {
	Id   PodId `json:"id"`
	Body *UpdatePodApplicationMergePatchPlusJSONRequestBody
}

type UpdatePodResponseObject

type UpdatePodResponseObject interface {
	VisitUpdatePodResponse(w http.ResponseWriter) error
}

type UpdateService200JSONResponse

type UpdateService200JSONResponse Service

func (UpdateService200JSONResponse) VisitUpdateServiceResponse

func (response UpdateService200JSONResponse) VisitUpdateServiceResponse(w http.ResponseWriter) error

type UpdateService400ApplicationProblemPlusJSONResponse

type UpdateService400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (UpdateService400ApplicationProblemPlusJSONResponse) VisitUpdateServiceResponse

func (response UpdateService400ApplicationProblemPlusJSONResponse) VisitUpdateServiceResponse(w http.ResponseWriter) error

type UpdateService401ApplicationProblemPlusJSONResponse

type UpdateService401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (UpdateService401ApplicationProblemPlusJSONResponse) VisitUpdateServiceResponse

func (response UpdateService401ApplicationProblemPlusJSONResponse) VisitUpdateServiceResponse(w http.ResponseWriter) error

type UpdateService403ApplicationProblemPlusJSONResponse

type UpdateService403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (UpdateService403ApplicationProblemPlusJSONResponse) VisitUpdateServiceResponse

func (response UpdateService403ApplicationProblemPlusJSONResponse) VisitUpdateServiceResponse(w http.ResponseWriter) error

type UpdateService404ApplicationProblemPlusJSONResponse

type UpdateService404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (UpdateService404ApplicationProblemPlusJSONResponse) VisitUpdateServiceResponse

func (response UpdateService404ApplicationProblemPlusJSONResponse) VisitUpdateServiceResponse(w http.ResponseWriter) error

type UpdateServiceApplicationMergePatchPlusJSONRequestBody

type UpdateServiceApplicationMergePatchPlusJSONRequestBody = ServiceUpdate

UpdateServiceApplicationMergePatchPlusJSONRequestBody defines body for UpdateService for application/merge-patch+json ContentType.

type UpdateServiceRequestObject

type UpdateServiceRequestObject struct {
	Id   ServiceId `json:"id"`
	Body *UpdateServiceApplicationMergePatchPlusJSONRequestBody
}

type UpdateServiceResponseObject

type UpdateServiceResponseObject interface {
	VisitUpdateServiceResponse(w http.ResponseWriter) error
}

type UpdateUser200JSONResponse

type UpdateUser200JSONResponse User

func (UpdateUser200JSONResponse) VisitUpdateUserResponse

func (response UpdateUser200JSONResponse) VisitUpdateUserResponse(w http.ResponseWriter) error

type UpdateUser400ApplicationProblemPlusJSONResponse

type UpdateUser400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (UpdateUser400ApplicationProblemPlusJSONResponse) VisitUpdateUserResponse

func (response UpdateUser400ApplicationProblemPlusJSONResponse) VisitUpdateUserResponse(w http.ResponseWriter) error

type UpdateUser401ApplicationProblemPlusJSONResponse

type UpdateUser401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (UpdateUser401ApplicationProblemPlusJSONResponse) VisitUpdateUserResponse

func (response UpdateUser401ApplicationProblemPlusJSONResponse) VisitUpdateUserResponse(w http.ResponseWriter) error

type UpdateUser403ApplicationProblemPlusJSONResponse

type UpdateUser403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (UpdateUser403ApplicationProblemPlusJSONResponse) VisitUpdateUserResponse

func (response UpdateUser403ApplicationProblemPlusJSONResponse) VisitUpdateUserResponse(w http.ResponseWriter) error

type UpdateUser404ApplicationProblemPlusJSONResponse

type UpdateUser404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (UpdateUser404ApplicationProblemPlusJSONResponse) VisitUpdateUserResponse

func (response UpdateUser404ApplicationProblemPlusJSONResponse) VisitUpdateUserResponse(w http.ResponseWriter) error

type UpdateUser409ApplicationProblemPlusJSONResponse

type UpdateUser409ApplicationProblemPlusJSONResponse struct {
	ConflictApplicationProblemPlusJSONResponse
}

func (UpdateUser409ApplicationProblemPlusJSONResponse) VisitUpdateUserResponse

func (response UpdateUser409ApplicationProblemPlusJSONResponse) VisitUpdateUserResponse(w http.ResponseWriter) error

type UpdateUserApplicationMergePatchPlusJSONRequestBody

type UpdateUserApplicationMergePatchPlusJSONRequestBody = UserUpdate

UpdateUserApplicationMergePatchPlusJSONRequestBody defines body for UpdateUser for application/merge-patch+json ContentType.

type UpdateUserRequestObject

type UpdateUserRequestObject struct {
	Id   UserId `json:"id"`
	Body *UpdateUserApplicationMergePatchPlusJSONRequestBody
}

type UpdateUserResponseObject

type UpdateUserResponseObject interface {
	VisitUpdateUserResponse(w http.ResponseWriter) error
}

type UpdateWorkload200JSONResponse

type UpdateWorkload200JSONResponse Workload

func (UpdateWorkload200JSONResponse) VisitUpdateWorkloadResponse

func (response UpdateWorkload200JSONResponse) VisitUpdateWorkloadResponse(w http.ResponseWriter) error

type UpdateWorkload400ApplicationProblemPlusJSONResponse

type UpdateWorkload400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (UpdateWorkload400ApplicationProblemPlusJSONResponse) VisitUpdateWorkloadResponse

func (response UpdateWorkload400ApplicationProblemPlusJSONResponse) VisitUpdateWorkloadResponse(w http.ResponseWriter) error

type UpdateWorkload401ApplicationProblemPlusJSONResponse

type UpdateWorkload401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (UpdateWorkload401ApplicationProblemPlusJSONResponse) VisitUpdateWorkloadResponse

func (response UpdateWorkload401ApplicationProblemPlusJSONResponse) VisitUpdateWorkloadResponse(w http.ResponseWriter) error

type UpdateWorkload403ApplicationProblemPlusJSONResponse

type UpdateWorkload403ApplicationProblemPlusJSONResponse struct {
	ForbiddenApplicationProblemPlusJSONResponse
}

func (UpdateWorkload403ApplicationProblemPlusJSONResponse) VisitUpdateWorkloadResponse

func (response UpdateWorkload403ApplicationProblemPlusJSONResponse) VisitUpdateWorkloadResponse(w http.ResponseWriter) error

type UpdateWorkload404ApplicationProblemPlusJSONResponse

type UpdateWorkload404ApplicationProblemPlusJSONResponse struct {
	NotFoundApplicationProblemPlusJSONResponse
}

func (UpdateWorkload404ApplicationProblemPlusJSONResponse) VisitUpdateWorkloadResponse

func (response UpdateWorkload404ApplicationProblemPlusJSONResponse) VisitUpdateWorkloadResponse(w http.ResponseWriter) error

type UpdateWorkloadApplicationMergePatchPlusJSONRequestBody

type UpdateWorkloadApplicationMergePatchPlusJSONRequestBody = WorkloadUpdate

UpdateWorkloadApplicationMergePatchPlusJSONRequestBody defines body for UpdateWorkload for application/merge-patch+json ContentType.

type UpdateWorkloadRequestObject

type UpdateWorkloadRequestObject struct {
	Id   WorkloadId `json:"id"`
	Body *UpdateWorkloadApplicationMergePatchPlusJSONRequestBody
}

type UpdateWorkloadResponseObject

type UpdateWorkloadResponseObject interface {
	VisitUpdateWorkloadResponse(w http.ResponseWriter) error
}

type UpsertOutcome added in v0.20.0

type UpsertOutcome int

UpsertOutcome classifies the result of an Upsert* operation so the audit middleware can decide whether to record a row. A tick that only refreshes clock fields (last_seen / updated_at) returns OutcomeNoChange and is filtered out; everything else is recorded as before.

The enum lives in internal/api (not internal/store) to avoid an import cycle: internal/store imports internal/api for entity types, so the Store interface — which lives here — must reference a type declared here. See ADR-0024.

const (
	// OutcomeInserted — the row did not exist; INSERT path was taken.
	OutcomeInserted UpsertOutcome = iota
	// OutcomeBusinessChanged — the row existed and ≥1 business field changed.
	OutcomeBusinessChanged
	// OutcomeNoChange — the row existed and only clock fields were touched.
	OutcomeNoChange
)

func (UpsertOutcome) String added in v0.20.0

func (o UpsertOutcome) String() string

String returns a stable lowercase token suitable for a Prometheus label.

type User

type User struct {
	CreatedAt  *time.Time `json:"created_at,omitempty"`
	DisabledAt *time.Time `json:"disabled_at,omitempty"`

	// FailedLoginCount Consecutive failed password attempts since last successful login. Reset
	// to 0 on successful login or admin unlock. Reaches lockout threshold
	// (6) -> `locked_at` is set.
	FailedLoginCount *int                `json:"failed_login_count,omitempty"`
	Id               *openapi_types.UUID `json:"id,omitempty"`
	LastLoginAt      *time.Time          `json:"last_login_at,omitempty"`

	// LockedAt When the account auto-locked after exceeding the failed-login threshold.
	// A locked account cannot authenticate via password. Cleared by an admin
	// via `PATCH /v1/admin/users/{id}` with `unlock=true`. NULL = not locked.
	LockedAt           *time.Time `json:"locked_at,omitempty"`
	MustChangePassword *bool      `json:"must_change_password,omitempty"`

	// Role Fixed role set per ADR-0007. Each role maps to a fixed scope set —
	// the scope check in the OpenAPI `security` blocks is unchanged, the
	// session middleware just attaches the scopes derived from role.
	Role      Role       `json:"role"`
	UpdatedAt *time.Time `json:"updated_at,omitempty"`
	Username  string     `json:"username"`
}

User A human user registered in longue-vue.

type UserCreate

type UserCreate struct {
	// MustChangePassword Default true — the standard "admin provisions, user rotates on
	// first login" flow. Set false for seeded users in automation.
	MustChangePassword *bool  `json:"must_change_password,omitempty"`
	Password           string `json:"password"`

	// Role Fixed role set per ADR-0007. Each role maps to a fixed scope set —
	// the scope check in the OpenAPI `security` blocks is unchanged, the
	// session middleware just attaches the scopes derived from role.
	Role     Role   `json:"role"`
	Username string `json:"username"`
}

UserCreate Payload to create a new human user.

type UserId

type UserId = openapi_types.UUID

UserId defines model for UserId.

type UserIdentityInsert

type UserIdentityInsert struct {
	Issuer  string
	Subject string
	Email   string
}

UserIdentityInsert carries the federation tuple persisted on first OIDC login. Email is optional but useful for admin display.

type UserInsert

type UserInsert struct {
	Username           string
	PasswordHash       string
	Role               string
	MustChangePassword bool
}

UserInsert carries the data the store needs to create a user. Kept separate from the API's UserCreate because the store sees the password hash, not the plaintext — hashing happens in the handler.

type UserList

type UserList struct {
	Items      []User  `json:"items"`
	NextCursor *string `json:"next_cursor,omitempty"`
}

UserList Paged list of users.

type UserListFilter added in v1.10.0

type UserListFilter struct {
	Name *string
}

UserListFilter is the predicate set accepted by ListUsers. Name matches the username field (case-insensitive).

type UserPatch

type UserPatch struct {
	Role               *string
	MustChangePassword *bool
	Disabled           *bool
	Unlock             *bool
}

UserPatch is the merge-patch view for UpdateUser. All fields optional. Nil means "don't touch"; non-nil means "set to this value".

Unlock=true clears failed_login_count and locked_at (admin clears a brute-force lockout). Has no effect on accounts that are not locked.

type UserUpdate

type UserUpdate struct {
	Disabled           *bool   `json:"disabled,omitempty"`
	MustChangePassword *bool   `json:"must_change_password,omitempty"`
	Password           *string `json:"password,omitempty"`

	// Role Fixed role set per ADR-0007. Each role maps to a fixed scope set —
	// the scope check in the OpenAPI `security` blocks is unchanged, the
	// session middleware just attaches the scopes derived from role.
	Role *Role `json:"role,omitempty"`

	// Unlock When true, clears `locked_at` and resets `failed_login_count` to 0.
	// No effect on accounts that are not locked. Can be combined with other
	// patch fields in the same request -- all changes apply atomically in
	// one UPDATE.
	Unlock *bool `json:"unlock,omitempty"`
}

UserUpdate Merge-patch body. Setting `password` rehashes and forces `must_change_password=true`. Setting `disabled=true` revokes every active session for the user. Setting `unlock=true` clears the lockout state on an account locked after too many failed login attempts.

type UserWithSecret

type UserWithSecret struct {
	User
	PasswordHash string
}

UserWithSecret extends the outward-facing User with the stored password hash — never serialised over the wire.

type VMApplication

type VMApplication struct {
	Product         string     `json:"product"`
	Version         string     `json:"version"`
	Name            *string    `json:"name,omitempty"`
	Notes           *string    `json:"notes,omitempty"`
	AddedAt         time.Time  `json:"added_at"`
	AddedBy         string     `json:"added_by"`
	ApplicationID   *uuid.UUID `json:"application_id,omitempty"`
	ApplicationName *string    `json:"application_name,omitempty"`
}

VMApplication is one entry in a virtual machine's `applications` JSONB column (ADR-0019). Operators record what's running on a platform VM (Vault, DNS, Cyberwatch, …) and the EOL enricher uses `Product` + `Version` to look up lifecycle data on endoflife.date.

`Product` is normalized server-side (NormalizeProductName) so that "Hashicorp Vault", "hashicorp-vault", and "Vault" deduplicate to the same key. `AddedAt` and `AddedBy` are server-stamped on insert and preserved across PATCH calls when (product, version, name) is unchanged.

ApplicationID is the per-entry ADR-0029 soft-pointer to an Application row. Lets a single VM hosting multiple products (Vault + BIND) link each product to a different Application (per ADR-0029 §2.3 / §1). The PATCH handler validates the id against the applications table and rejects the whole PATCH on lookup failure.

ApplicationName is a write-only convenience: a caller may supply a name instead of an id, and the PATCH handler resolves it via ResolveApplicationID (id wins on conflict) before persisting. The stored JSONB never contains application_name — the handler strips it to nil after resolution, and the JSON tag stays write-only courtesy of omitempty on a *string that the handler always nils out.

type VMApplicationDistinct

type VMApplicationDistinct struct {
	Product  string   `json:"product"`
	Versions []string `json:"versions"`
}

VMApplicationDistinct is one row of the distinct-applications response. `Versions` is the sorted, deduplicated list of versions seen for the product across every non-terminated VM. Drives the cascading product → version dropdown in the VM list UI.

type VMSecurityGroupAttachment added in v1.2.0

type VMSecurityGroupAttachment struct {
	CloudAccountID uuid.UUID
	ProviderVMID   string
	ProviderSGID   string
}

VMSecurityGroupAttachment links a raw provider VM id to a provider SG id within a cloud account, independent of the virtual_machines table. Node VMs are never inventoried as virtual_machines (ADR-0015 dedup), so their SG links live here keyed by raw provider VM id.

type VerifyRateLimiter

type VerifyRateLimiter struct {
	// contains filtered or unexported fields
}

VerifyRateLimiter provides per-IP rate limiting for the ingest-listener /v1/auth/verify endpoint (ADR-0016 §5).

func NewVerifyRateLimiter

func NewVerifyRateLimiter() *VerifyRateLimiter

NewVerifyRateLimiter creates a rate limiter with the default 100 rps / burst 200 per source IP. Kept for tests and call sites that don't need to tune the limits.

func NewVerifyRateLimiterWithLimits added in v0.32.0

func NewVerifyRateLimiterWithLimits(rps float64, burst int) *VerifyRateLimiter

NewVerifyRateLimiterWithLimits creates a rate limiter with the given per-IP rps and burst. Values <= 0 fall back to the defaults so a typo'd env var can't accidentally disable the limiter.

func (*VerifyRateLimiter) Allow

func (rl *VerifyRateLimiter) Allow(ip string) bool

Allow returns true if the IP is within the rate limit.

type VerifyToken200JSONResponse

type VerifyToken200JSONResponse VerifyTokenResponse

func (VerifyToken200JSONResponse) VisitVerifyTokenResponse

func (response VerifyToken200JSONResponse) VisitVerifyTokenResponse(w http.ResponseWriter) error

type VerifyToken400ApplicationProblemPlusJSONResponse

type VerifyToken400ApplicationProblemPlusJSONResponse struct {
	BadRequestApplicationProblemPlusJSONResponse
}

func (VerifyToken400ApplicationProblemPlusJSONResponse) VisitVerifyTokenResponse

func (response VerifyToken400ApplicationProblemPlusJSONResponse) VisitVerifyTokenResponse(w http.ResponseWriter) error

type VerifyToken401ApplicationProblemPlusJSONResponse

type VerifyToken401ApplicationProblemPlusJSONResponse struct {
	UnauthorizedApplicationProblemPlusJSONResponse
}

func (VerifyToken401ApplicationProblemPlusJSONResponse) VisitVerifyTokenResponse

func (response VerifyToken401ApplicationProblemPlusJSONResponse) VisitVerifyTokenResponse(w http.ResponseWriter) error

type VerifyTokenJSONRequestBody

type VerifyTokenJSONRequestBody = VerifyTokenRequest

VerifyTokenJSONRequestBody defines body for VerifyToken for application/json ContentType.

type VerifyTokenRequest

type VerifyTokenRequest struct {
	// Token Opaque PAT (`lv_pat_<prefix>_<suffix>` or legacy `argos_pat_<prefix>_<suffix>`).
	Token string `json:"token"`
}

VerifyTokenRequest Bearer token to verify. The DMZ ingest gateway (ADR-0016) uses this to short-circuit invalid tokens before they cross the firewall. Sent over mTLS only — longue-vue's public listener does not serve `POST /v1/auth/verify`.

type VerifyTokenRequestObject

type VerifyTokenRequestObject struct {
	Body *VerifyTokenJSONRequestBody
}

type VerifyTokenResponse

type VerifyTokenResponse struct {
	// BoundCloudAccountId Set on tokens issued with the `vm-collector` scope (ADR-0015).
	// The DMZ ingest gateway is intended for K8s collectors only;
	// `vm-collector` tokens are surfaced here so the gateway can
	// reject them at the cache layer rather than forwarding.
	BoundCloudAccountId *openapi_types.UUID `json:"bound_cloud_account_id,omitempty"`

	// CallerId Token id (the row's primary key in `api_tokens`).
	CallerId *openapi_types.UUID `json:"caller_id,omitempty"`

	// Exp Token expiry as a Unix epoch second. Omitted when the token
	// does not expire. The gateway caches verify results for the
	// lesser of its configured TTL and `(exp - now)`.
	Exp *int64 `json:"exp,omitempty"`

	// Kind The verify endpoint authenticates only bearer tokens. Cookie
	// sessions cannot be verified through this RPC since they do
	// not survive the DMZ hop.
	Kind VerifyTokenResponseKind `json:"kind"`

	// Scopes Token's declared scopes. The gateway must consult these
	// before forwarding to short-circuit obvious scope mismatches.
	Scopes []string `json:"scopes"`

	// TokenName Cosmetic — for log lines and audit entries on the gateway side.
	TokenName *string `json:"token_name,omitempty"`

	// Valid Always `true` in a 200 response. Reserved for future use.
	Valid bool `json:"valid"`
}

VerifyTokenResponse Token verification result. Returned only when the token is valid; invalid / unknown / expired / revoked tokens get a 401 with no identifying detail (a verifier cannot infer which bit was wrong).

type VerifyTokenResponseKind

type VerifyTokenResponseKind string

VerifyTokenResponseKind The verify endpoint authenticates only bearer tokens. Cookie sessions cannot be verified through this RPC since they do not survive the DMZ hop.

const (
	VerifyTokenResponseKindToken VerifyTokenResponseKind = "token"
)

Defines values for VerifyTokenResponseKind.

func (VerifyTokenResponseKind) Valid

func (e VerifyTokenResponseKind) Valid() bool

Valid indicates whether the value is a known member of the VerifyTokenResponseKind enum.

type VerifyTokenResponseObject

type VerifyTokenResponseObject interface {
	VisitVerifyTokenResponse(w http.ResponseWriter) error
}

type VirtualMachine

type VirtualMachine struct {
	ID                   uuid.UUID         `json:"id"`
	CloudAccountID       uuid.UUID         `json:"cloud_account_id"`
	ProviderVMID         string            `json:"provider_vm_id"`
	Name                 string            `json:"name"`
	DisplayName          *string           `json:"display_name,omitempty"`
	Role                 *string           `json:"role,omitempty"`
	PrivateIP            *string           `json:"private_ip,omitempty"`
	PublicIP             *string           `json:"public_ip,omitempty"`
	PrivateDNSName       *string           `json:"private_dns_name,omitempty"`
	VPCID                *string           `json:"vpc_id,omitempty"`
	SubnetID             *string           `json:"subnet_id,omitempty"`
	NICs                 json.RawMessage   `json:"nics,omitempty"`
	SecurityGroups       json.RawMessage   `json:"security_groups,omitempty"`
	InstanceType         *string           `json:"instance_type,omitempty"`
	Architecture         *string           `json:"architecture,omitempty"`
	Zone                 *string           `json:"zone,omitempty"`
	Region               *string           `json:"region,omitempty"`
	ImageID              *string           `json:"image_id,omitempty"`
	ImageName            *string           `json:"image_name,omitempty"`
	KeypairName          *string           `json:"keypair_name,omitempty"`
	BootMode             *string           `json:"boot_mode,omitempty"`
	ProviderAccountID    *string           `json:"provider_account_id,omitempty"`
	ProviderCreationDate *time.Time        `json:"provider_creation_date,omitempty"`
	PowerState           string            `json:"power_state"`
	StateReason          *string           `json:"state_reason,omitempty"`
	Ready                bool              `json:"ready"`
	DeletionProtection   bool              `json:"deletion_protection"`
	KernelVersion        *string           `json:"kernel_version,omitempty"`
	OperatingSystem      *string           `json:"operating_system,omitempty"`
	CapacityCPU          *string           `json:"capacity_cpu,omitempty"`
	CapacityMemory       *string           `json:"capacity_memory,omitempty"`
	BlockDevices         json.RawMessage   `json:"block_devices,omitempty"`
	RootDeviceType       *string           `json:"root_device_type,omitempty"`
	RootDeviceName       *string           `json:"root_device_name,omitempty"`
	Tags                 map[string]string `json:"tags,omitempty"`
	Labels               map[string]string `json:"labels,omitempty"`
	Annotations          map[string]string `json:"annotations,omitempty"`
	Owner                *string           `json:"owner,omitempty"`
	Criticality          *string           `json:"criticality,omitempty"`
	Notes                *string           `json:"notes,omitempty"`
	RunbookURL           *string           `json:"runbook_url,omitempty"`
	Applications         []VMApplication   `json:"applications"`
	// ApplicationID is the row-level ADR-0029 soft-pointer linking the
	// entire VM to an Application. Independent of the per-entry link on
	// VMApplication: a VM may carry a row-level "this whole VM belongs
	// to X" pointer while individual application entries point at their
	// own products. ON DELETE SET NULL via the FK in migration 00047.
	ApplicationID *uuid.UUID `json:"application_id,omitempty"`
	// ApplicationName is the denormalized `applications.name` for ApplicationID
	// (ADR-0027 pattern). Read-only, computed at read time via correlated
	// subquery; never accepted on PATCH/POST bodies.
	ApplicationName *string `json:"application_name,omitempty"`
	// EffectiveDict is the read-only inherited DICT classification
	// (ADR-0029 §6). VMs have no DICT columns of their own, so the value is
	// either the linked application's classification or source="none".
	// Computed at read time; never accepted on PATCH/POST bodies.
	EffectiveDict *EffectiveDICT `json:"effective_dict,omitempty"`
	CreatedAt     time.Time      `json:"created_at"`
	UpdatedAt     time.Time      `json:"updated_at"`
	LastSeenAt    time.Time      `json:"last_seen_at"`
	TerminatedAt  *time.Time     `json:"terminated_at,omitempty"`
}

VirtualMachine is the persisted view of a non-Kubernetes platform VM. Mirrors the enriched nodes shape where it makes sense, drops the K8s-specific fields, and adds the cloud-native columns from the rich provider payload (image, keypair, VPC, NICs, SGs, block devices).

type VirtualMachineExtractRow added in v0.22.0

type VirtualMachineExtractRow struct {
	ApplicationsMatched *string             `json:"applications_matched,omitempty"`
	CloudAccount        *string             `json:"cloud_account,omitempty"`
	DisplayName         *string             `json:"display_name,omitempty"`
	Id                  *openapi_types.UUID `json:"id,omitempty"`
	ImageId             *string             `json:"image_id,omitempty"`
	ImageName           *string             `json:"image_name,omitempty"`
	Name                string              `json:"name"`
	PowerState          *string             `json:"power_state,omitempty"`
	Region              *string             `json:"region,omitempty"`
	Role                *string             `json:"role,omitempty"`
	UpdatedAt           *time.Time          `json:"updated_at,omitempty"`
}

VirtualMachineExtractRow defines model for VirtualMachineExtractRow.

type VirtualMachineListFilter

type VirtualMachineListFilter struct {
	CloudAccountID   *uuid.UUID
	CloudAccountName *string
	Region           *string
	Role             *string
	PowerState       *string
	Name             *string
	Image            *string
	Application      *string
	// ApplicationVersion narrows Application to a specific version. Only
	// honoured when Application is also set; ignored otherwise so callers
	// can't bypass the product-name normalization. Matches the JSONB entry
	// (product, version) tuple via containment.
	ApplicationVersion *string
	IncludeTerminated  bool
	// ADR-0029 link-aware filters. ApplicationID wins on conflict with
	// ApplicationName (mirrors the cloud_account_id / cloud_account_name
	// precedence from ADR-0019); ApplicationName is normalised server-side
	// via NormalizeApplicationName before the sub-SELECT against
	// applications.name. Unlinked narrows to VMs with NULL application_id.
	ApplicationID   *uuid.UUID
	ApplicationName *string
	Unlinked        *bool
	// ApplicationNameSubstring is a case-insensitive substring match on the
	// linked application's name, used by the cross-entity Search endpoint
	// (ADR-0029 §2.4). LIKE metacharacters are escaped at the SQL layer
	// (ESCAPE '\\'). Ignored when empty. AND-combined with the other
	// link-aware filters.
	ApplicationNameSubstring *string
}

VirtualMachineListFilter collects the optional filters for ListVirtualMachines.

Name and Image are bounded substring filters (LIKE-escape applied at the SQL layer). CloudAccountName resolves via an inner subquery against the cloud_accounts UNIQUE index. Application is a JSONB containment filter matching any entry whose normalized product equals the given value.

type VirtualMachinePatch

type VirtualMachinePatch struct {
	DisplayName  *string
	Role         *string
	Owner        *string
	Criticality  *string
	Notes        *string
	RunbookURL   *string
	Annotations  *map[string]string
	Applications *[]VMApplication
	// ApplicationID / ApplicationName are the ADR-0029 row-level link
	// inputs. The handler resolves Name → ID via ResolveApplicationID
	// (id wins on conflict, mirrors ADR-0019) and strips ApplicationName
	// to nil before calling the store. Three-state merge-patch (RFC 7396):
	// a non-nil ApplicationID writes the link; ClearApplicationID=true
	// (an explicit `"application_id": null` in the body) unlinks; otherwise
	// the existing link is left untouched. An explicit id wins over null.
	ApplicationID      *uuid.UUID
	ApplicationName    *string
	ClearApplicationID bool
}

VirtualMachinePatch is the merge-patch for UpdateVirtualMachine. Curated-only — the collector path goes through UpsertVirtualMachine.

Applications has replace-not-merge semantics (ADR-0019 §4): a non-nil pointer replaces the entire list. The handler diffs the input against the stored list to preserve `added_at` / `added_by` on entries whose (product, version, name) key is unchanged, and stamps fresh values on new entries. The store sees the final list.

type VirtualMachineStore added in v1.6.2

type VirtualMachineStore interface {
	// UpsertVirtualMachine inserts a new VM or updates the existing row by
	// (cloud_account_id, provider_vm_id). Server-side dedup against
	// nodes.provider_id: returns ErrConflict if the provider_vm_id already
	// appears in any node's provider_id (the VM is already inventoried as
	// a Kubernetes node). The second return value classifies the operation
	// for audit filtering (ADR-0024): OutcomeInserted for a fresh insert,
	// OutcomeBusinessChanged when a business field changed, OutcomeNoChange
	// when only clock fields moved.
	UpsertVirtualMachine(ctx context.Context, in VirtualMachineUpsert) (VirtualMachine, UpsertOutcome, error)

	// GetVirtualMachine fetches by id. ErrNotFound when absent.
	GetVirtualMachine(ctx context.Context, id uuid.UUID) (VirtualMachine, error)

	// ListVirtualMachines returns paged VMs filtered by VirtualMachineListFilter.
	// terminated rows are excluded unless filter.IncludeTerminated.
	ListVirtualMachines(
		ctx context.Context,
		filter VirtualMachineListFilter,
		page ListPage,
	) (items []VirtualMachine, nextCursor string, err error)

	// UpdateVirtualMachine applies merge-patch on curated-only fields.
	UpdateVirtualMachine(ctx context.Context, id uuid.UUID, in VirtualMachinePatch) (VirtualMachine, error)

	// DeleteVirtualMachine soft-deletes by setting terminated_at,
	// power_state='terminated', ready=false. Hard delete is left to retention.
	DeleteVirtualMachine(ctx context.Context, id uuid.UUID) error

	// ReconcileVirtualMachines soft-deletes every row of the given account
	// whose provider_vm_id is not in keep AND terminated_at IS NULL.
	// Returns the count of rows tombstoned.
	ReconcileVirtualMachines(ctx context.Context, accountID uuid.UUID, keepProviderVMIDs []string) (tombstoned int64, err error)

	// ListDistinctVMApplications returns the distinct products and, for
	// each, the sorted list of distinct versions seen across every
	// non-terminated VM's applications array. Drives the cascading
	// product → version dropdown in the VM list UI (ADR-0019 §3).
	ListDistinctVMApplications(ctx context.Context) ([]VMApplicationDistinct, error)

	// ListVMsWithApplicationEntry returns every non-terminated VM that has
	// at least one applications[] JSONB entry whose per-entry
	// application_id matches the given application — regardless of the VM's
	// row-level application_id link. Used by the per-application EOL
	// aggregator (ADR-0029 §5 source 3) to surface VM-application entries
	// whose parent VM is not itself linked. The full VM is returned so the
	// caller can read its annotations and filter the matching entries.
	ListVMsWithApplicationEntry(ctx context.Context, appID uuid.UUID) ([]VirtualMachine, error)
}

VirtualMachineStore covers cloud VMs (ADR-0015): push-collector upsert, curated patches, and soft-delete reconcile.

type VirtualMachineUpsert

type VirtualMachineUpsert struct {
	CloudAccountID       uuid.UUID
	ProviderVMID         string
	Name                 string
	Role                 *string
	PrivateIP            *string
	PublicIP             *string
	PrivateDNSName       *string
	VPCID                *string
	SubnetID             *string
	NICs                 json.RawMessage
	SecurityGroups       json.RawMessage
	InstanceType         *string
	Architecture         *string
	Zone                 *string
	Region               *string
	ImageID              *string
	ImageName            *string
	KeypairName          *string
	BootMode             *string
	ProviderAccountID    *string
	ProviderCreationDate *time.Time
	PowerState           string
	StateReason          *string
	Ready                bool
	DeletionProtection   bool
	KernelVersion        *string
	OperatingSystem      *string
	CapacityCPU          *string
	CapacityMemory       *string
	BlockDevices         json.RawMessage
	RootDeviceType       *string
	RootDeviceName       *string
	Tags                 map[string]string
	Labels               map[string]string
}

VirtualMachineUpsert is the collector-side payload for upserting a VM. Mirrors VirtualMachine minus curated / lifecycle fields.

type Workload

type Workload struct {
	// ApplicationId Link to an Application (ADR-0029); operator-curated. Null when unlinked.
	ApplicationId *openapi_types.UUID `json:"application_id,omitempty"`

	// ApplicationName Denormalized `applications.name`. Null when unlinked. See ADR-0027 / ADR-0029.
	ApplicationName *string `json:"application_name,omitempty"`

	// ClusterId Denormalized `namespaces.cluster_id`. Null on orphans. See ADR-0027.
	ClusterId *openapi_types.UUID `json:"cluster_id,omitempty"`

	// ClusterName Denormalized `clusters.name`. Null on orphans. See ADR-0027.
	ClusterName *string `json:"cluster_name,omitempty"`

	// Containers Containers associated with the resource. For Pods this reflects the
	// live runtime (name, image, image_id from containerStatuses, init
	// flag); for Workloads it's the pod template's declared containers
	// (name, image, init). Opaque in v1: each entry's shape is additive,
	// so new collector-extracted fields don't require a spec bump.
	Containers *ContainerList `json:"containers,omitempty"`

	// ContainersVersions Map of container name to its latest-version info. Keys are absent when the image is not yet enriched (non-parseable tag, registry not in allowlist, or not yet processed).
	ContainersVersions *map[string]ContainerVersionInfo `json:"containers_versions,omitempty"`
	CreatedAt          *time.Time                       `json:"created_at,omitempty"`

	// EffectiveDict Read-only inherited DICT classification (ADR-0029 §6).
	// Computed at read time with application-wins precedence; never
	// accepted on PATCH/POST bodies.
	EffectiveDict *EffectiveDICT      `json:"effective_dict,omitempty"`
	Id            *openapi_types.UUID `json:"id,omitempty"`

	// Kind Kubernetes workload controller kind. Casing matches the `kind` field
	// Kubernetes itself emits. Additional kinds (Job, CronJob, ReplicaSet,
	// ReplicationController) may be introduced as new enum values without a
	// schema migration (see ADR-0003).
	Kind WorkloadKind `json:"kind"`

	// Labels Arbitrary user-supplied string key/value labels.
	Labels *map[string]string `json:"labels,omitempty"`

	// Layer Always `applicative` for Workload. Set by the server.
	Layer       *Layer             `json:"layer,omitempty"`
	Name        string             `json:"name"`
	NamespaceId openapi_types.UUID `json:"namespace_id"`

	// NamespaceName Denormalized `namespaces.name`. Null on orphans. See ADR-0027.
	NamespaceName *string `json:"namespace_name,omitempty"`

	// ReadyReplicas Observed ready replica count. Nullable until first status update.
	ReadyReplicas *int `json:"ready_replicas,omitempty"`

	// Replicas Desired replica count. Nullable; DaemonSet has no scalar desired count.
	Replicas *int `json:"replicas,omitempty"`

	// Spec Kind-specific fields the collector chooses to persist (e.g. strategy
	// for Deployment, service_name for StatefulSet). Open-ended; stored
	// as JSONB.
	Spec      *map[string]interface{} `json:"spec,omitempty"`
	UpdatedAt *time.Time              `json:"updated_at,omitempty"`
}

Workload defines model for Workload.

func BuildContainerFreshness added in v1.9.0

func BuildContainerFreshness(ctx context.Context, s Store) ([]Workload, error)

BuildContainerFreshness pages the full workload fleet via ListWorkloads and returns each Workload with its Containers and ContainersVersions populated.

Plain ListWorkloads does NOT fill ContainersVersions — that enrichment is opt-in (ADR-0022/0041). For each workload it calls EnrichContainersVersions(ctx, s, containers) and attaches the result. The Store interface satisfies EnrichContainersVersions' containerVersionLookup surface (GetImageOriginResolution + GetImageVersionsByRepo).

type WorkloadApplicationIdFilter added in v0.28.0

type WorkloadApplicationIdFilter = openapi_types.UUID

WorkloadApplicationIdFilter defines model for WorkloadApplicationIdFilter.

type WorkloadApplicationNameFilter added in v0.28.0

type WorkloadApplicationNameFilter = string

WorkloadApplicationNameFilter defines model for WorkloadApplicationNameFilter.

type WorkloadCreate

type WorkloadCreate struct {
	// Containers Containers associated with the resource. For Pods this reflects the
	// live runtime (name, image, image_id from containerStatuses, init
	// flag); for Workloads it's the pod template's declared containers
	// (name, image, init). Opaque in v1: each entry's shape is additive,
	// so new collector-extracted fields don't require a spec bump.
	Containers *ContainerList `json:"containers,omitempty"`

	// ContainersVersions Map of container name to its latest-version info. Keys are absent when the image is not yet enriched (non-parseable tag, registry not in allowlist, or not yet processed).
	ContainersVersions *map[string]ContainerVersionInfo `json:"containers_versions,omitempty"`

	// Kind Workload kind discriminator. Immutable after creation.
	Kind WorkloadKind `json:"kind"`

	// Labels Arbitrary user-supplied string key/value labels.
	Labels *map[string]string `json:"labels,omitempty"`

	// Name Kubernetes workload name (DNS-subdomain style). Unique per
	// (namespace, kind). Immutable after creation.
	Name string `json:"name"`

	// NamespaceId Parent namespace id. Immutable after creation; the namespace
	// must already exist or the create returns 404.
	NamespaceId openapi_types.UUID `json:"namespace_id"`

	// ReadyReplicas Observed ready replica count. Nullable until first status update.
	ReadyReplicas *int `json:"ready_replicas,omitempty"`

	// Replicas Desired replica count. Nullable; DaemonSet has no scalar desired count.
	Replicas *int `json:"replicas,omitempty"`

	// Spec Kind-specific fields the collector chooses to persist (e.g. strategy
	// for Deployment, service_name for StatefulSet). Open-ended; stored
	// as JSONB.
	Spec *map[string]interface{} `json:"spec,omitempty"`
}

WorkloadCreate defines model for WorkloadCreate.

type WorkloadExtractRow added in v0.22.0

type WorkloadExtractRow struct {
	Cluster       string              `json:"cluster"`
	Id            *openapi_types.UUID `json:"id,omitempty"`
	ImageMatches  *string             `json:"image_matches,omitempty"`
	Kind          string              `json:"kind"`
	Name          string              `json:"name"`
	Namespace     string              `json:"namespace"`
	ReadyReplicas *int                `json:"ready_replicas,omitempty"`
	Replicas      *int                `json:"replicas,omitempty"`
	UpdatedAt     *time.Time          `json:"updated_at,omitempty"`
}

WorkloadExtractRow defines model for WorkloadExtractRow.

type WorkloadId

type WorkloadId = openapi_types.UUID

WorkloadId defines model for WorkloadId.

type WorkloadImageFilter

type WorkloadImageFilter = string

WorkloadImageFilter defines model for WorkloadImageFilter.

type WorkloadKind

type WorkloadKind string

WorkloadKind Kubernetes workload controller kind. Casing matches the `kind` field Kubernetes itself emits. Additional kinds (Job, CronJob, ReplicaSet, ReplicationController) may be introduced as new enum values without a schema migration (see ADR-0003).

const (
	DaemonSet   WorkloadKind = "DaemonSet"
	Deployment  WorkloadKind = "Deployment"
	StatefulSet WorkloadKind = "StatefulSet"
)

Defines values for WorkloadKind.

func (WorkloadKind) Valid

func (e WorkloadKind) Valid() bool

Valid indicates whether the value is a known member of the WorkloadKind enum.

type WorkloadKindFilter

type WorkloadKindFilter = WorkloadKind

WorkloadKindFilter Kubernetes workload controller kind. Casing matches the `kind` field Kubernetes itself emits. Additional kinds (Job, CronJob, ReplicaSet, ReplicationController) may be introduced as new enum values without a schema migration (see ADR-0003).

type WorkloadList

type WorkloadList struct {
	Items []Workload `json:"items"`

	// NextCursor Opaque cursor to pass as `?cursor=` to fetch the next page.
	// Absent or null when no more pages remain.
	NextCursor *string `json:"next_cursor,omitempty"`
}

WorkloadList Paged list of workloads.

type WorkloadListFilter

type WorkloadListFilter struct {
	NamespaceID    *uuid.UUID
	Kind           *WorkloadKind
	ImageSubstring *string
	// IncludeTerminated, when true, returns soft-deleted workloads in addition
	// to live ones. Default (false) hides rows whose terminated_at is set.
	// ADR-0021 phase 1.
	IncludeTerminated bool
	// ApplicationID, ApplicationName, Unlinked — ADR-0029 link-aware filters.
	// ApplicationID wins on conflict with ApplicationName (the handler resolves
	// names server-side; the store layer also accepts a bare name for callers
	// that bypass the handler, e.g. MCP). Unlinked = true returns only rows
	// with application_id IS NULL.
	ApplicationID   *uuid.UUID
	ApplicationName *string
	Unlinked        *bool
	// ApplicationNameSubstring is a case-insensitive substring match on the
	// linked application's name, used by the cross-entity Search endpoint
	// (ADR-0029 §2.4). LIKE metacharacters are escaped at the SQL layer
	// (ESCAPE '\\'). Ignored when empty. AND-combined with the other
	// link-aware filters.
	ApplicationNameSubstring *string
	// Name is the uniform name= filter: ci substring, or anchored
	// glob when the term contains `*` (spec 2026-07-10).
	Name *string
}

WorkloadListFilter mirrors PodListFilter for ListWorkloads.

type WorkloadMutable

type WorkloadMutable struct {
	// Containers Containers associated with the resource. For Pods this reflects the
	// live runtime (name, image, image_id from containerStatuses, init
	// flag); for Workloads it's the pod template's declared containers
	// (name, image, init). Opaque in v1: each entry's shape is additive,
	// so new collector-extracted fields don't require a spec bump.
	Containers *ContainerList `json:"containers,omitempty"`

	// ContainersVersions Map of container name to its latest-version info. Keys are absent when the image is not yet enriched (non-parseable tag, registry not in allowlist, or not yet processed).
	ContainersVersions *map[string]ContainerVersionInfo `json:"containers_versions,omitempty"`

	// Labels Arbitrary user-supplied string key/value labels.
	Labels *map[string]string `json:"labels,omitempty"`

	// ReadyReplicas Observed ready replica count. Nullable until first status update.
	ReadyReplicas *int `json:"ready_replicas,omitempty"`

	// Replicas Desired replica count. Nullable; DaemonSet has no scalar desired count.
	Replicas *int `json:"replicas,omitempty"`

	// Spec Kind-specific fields the collector chooses to persist (e.g. strategy
	// for Deployment, service_name for StatefulSet). Open-ended; stored
	// as JSONB.
	Spec *map[string]interface{} `json:"spec,omitempty"`
}

WorkloadMutable Fields on a Workload that clients may set and later update.

type WorkloadNamespaceIdFilter

type WorkloadNamespaceIdFilter = openapi_types.UUID

WorkloadNamespaceIdFilter defines model for WorkloadNamespaceIdFilter.

type WorkloadStore added in v1.6.2

type WorkloadStore interface {
	// CreateWorkload inserts a new workload. Returns ErrNotFound when the
	// parent namespace does not exist; ErrConflict when (namespace_id, kind,
	// name) already has a workload.
	CreateWorkload(ctx context.Context, in WorkloadCreate) (Workload, error)

	// GetWorkload fetches a workload by id. Returns ErrNotFound if absent.
	GetWorkload(ctx context.Context, id uuid.UUID) (Workload, error)

	// ListWorkloads returns a paged list of workloads matching filter, sorted by
	// page.Sort/page.Order. Unknown sort keys → ErrInvalidSort; mismatched
	// cursor → ErrInvalidCursor.
	ListWorkloads(ctx context.Context, filter WorkloadListFilter, page ListPage) (items []Workload, nextCursor string, err error)

	// UpdateWorkload applies merge-patch on mutable fields. Returns
	// ErrNotFound if the workload does not exist. clearApplication carries the
	// three-state ADR-0029 link semantics the *uuid.UUID field can't express:
	// when true (explicit `"application_id": null` in the body) the link is
	// cleared; an explicit application_id value still wins over the null.
	UpdateWorkload(ctx context.Context, id uuid.UUID, in WorkloadUpdate, clearApplication bool) (Workload, error)

	// DeleteWorkload removes a workload by id.
	DeleteWorkload(ctx context.Context, id uuid.UUID) error

	// UpsertWorkload mirrors UpsertPod; keyed on (namespace_id, kind, name). The second
	// return value classifies the operation for audit filtering (ADR-0024):
	// OutcomeInserted for a fresh insert, OutcomeBusinessChanged when a
	// business field changed, OutcomeNoChange when only clock fields moved.
	UpsertWorkload(ctx context.Context, in WorkloadCreate) (Workload, UpsertOutcome, error)

	// DeleteWorkloadsNotIn removes workloads in the namespace whose
	// (kind, name) tuple is not in keep. An empty keep slice clears every
	// workload for that namespace. The two slices are parallel; callers
	// must ensure len(keepKinds) == len(keepNames).
	DeleteWorkloadsNotIn(ctx context.Context, namespaceID uuid.UUID, keepKinds, keepNames []string) (int64, error)
}

WorkloadStore covers workload CRUD, upsert, and reconcile.

type WorkloadUnlinkedFilter added in v0.28.0

type WorkloadUnlinkedFilter = bool

WorkloadUnlinkedFilter defines model for WorkloadUnlinkedFilter.

type WorkloadUpdate

type WorkloadUpdate struct {
	// ApplicationId Link this workload to an Application (ADR-0029). When both
	// application_id and application_name are set, application_id wins.
	// Setting to null unlinks (per merge-patch semantics, omit the field
	// entirely to leave the link unchanged).
	ApplicationId *openapi_types.UUID `json:"application_id,omitempty"`

	// ApplicationName Convenience: link by Application name; resolved server-side.
	// See application_id.
	ApplicationName *string `json:"application_name,omitempty"`

	// Containers Containers associated with the resource. For Pods this reflects the
	// live runtime (name, image, image_id from containerStatuses, init
	// flag); for Workloads it's the pod template's declared containers
	// (name, image, init). Opaque in v1: each entry's shape is additive,
	// so new collector-extracted fields don't require a spec bump.
	Containers *ContainerList `json:"containers,omitempty"`

	// ContainersVersions Map of container name to its latest-version info. Keys are absent when the image is not yet enriched (non-parseable tag, registry not in allowlist, or not yet processed).
	ContainersVersions *map[string]ContainerVersionInfo `json:"containers_versions,omitempty"`

	// Labels Arbitrary user-supplied string key/value labels.
	Labels *map[string]string `json:"labels,omitempty"`

	// ReadyReplicas Observed ready replica count. Nullable until first status update.
	ReadyReplicas *int `json:"ready_replicas,omitempty"`

	// Replicas Desired replica count. Nullable; DaemonSet has no scalar desired count.
	Replicas *int `json:"replicas,omitempty"`

	// Spec Kind-specific fields the collector chooses to persist (e.g. strategy
	// for Deployment, service_name for StatefulSet). Open-ended; stored
	// as JSONB.
	Spec *map[string]interface{} `json:"spec,omitempty"`
}

WorkloadUpdate defines model for WorkloadUpdate.

Directories

Path Synopsis
Package swagger embeds the Swagger UI 5.x distribution and the longue-vue OpenAPI spec, and exposes HTTP handlers for serving both (UIHandler for the shell, OpenAPISpecHandler for the spec).
Package swagger embeds the Swagger UI 5.x distribution and the longue-vue OpenAPI spec, and exposes HTTP handlers for serving both (UIHandler for the shell, OpenAPISpecHandler for the spec).

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL