forward/

directory
v0.0.0-...-db0462e Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 6, 2026 License: MIT

Directories

Path Synopsis
Package driver is the boundary between a node's forwarding state and the engines that run it (docs/architecture/forward-sdk.md section 6).
Package driver is the boundary between a node's forwarding state and the engines that run it (docs/architecture/forward-sdk.md section 6).
anixops
Package anixops is the forward driver for ENGINE_ANIXOPS (docs/architecture/anixops-protocol.md section 6.1, phase A3): it runs the anixops hops of a node's state in the relay process of sdk/forward/driver/anixops/relayd, the `anixops-relay` unit the Agent's package ships, under its own systemd unit anixops-relay.service (decision P1), so restarting or upgrading the Agent keeps forwarding.
Package anixops is the forward driver for ENGINE_ANIXOPS (docs/architecture/anixops-protocol.md section 6.1, phase A3): it runs the anixops hops of a node's state in the relay process of sdk/forward/driver/anixops/relayd, the `anixops-relay` unit the Agent's package ships, under its own systemd unit anixops-relay.service (decision P1), so restarting or upgrading the Agent keeps forwarding.
anixops/anixopstest
Package anixopstest runs the anixops relay inside the test process, so the driver (sdk/forward/driver/anixops) is tested against a real relay, real sockets and real files without privileges, a network namespace or systemd: Host is a relay supervisor that starts and stops a relayd.Relay on a control socket in a temporary directory, shares it between driver instances (an Agent restart is a new driver on the same host) and can crash it, fail its next apply or redirect its dials to a local target.
Package anixopstest runs the anixops relay inside the test process, so the driver (sdk/forward/driver/anixops) is tested against a real relay, real sockets and real files without privileges, a network namespace or systemd: Host is a relay supervisor that starts and stops a relayd.Relay on a control socket in a temporary directory, shares it between driver instances (an Agent restart is a new driver on the same host) and can crash it, fail its next apply or redirect its dials to a local target.
anixops/relayctl
Package relayctl is the contract between the anixops forward driver (sdk/forward/driver/anixops, which runs in the Agent) and the relay process it controls (sdk/forward/driver/anixops/relayd, the `anixops-relay` unit): the relay's configuration document, which the driver renders and the relay loads, and the control API the driver reaches the relay with over a unix socket (docs/architecture/anixops-protocol.md section 6.1).
Package relayctl is the contract between the anixops forward driver (sdk/forward/driver/anixops, which runs in the Agent) and the relay process it controls (sdk/forward/driver/anixops/relayd, the `anixops-relay` unit): the relay's configuration document, which the driver renders and the relay loads, and the control API the driver reaches the relay with over a unix socket (docs/architecture/anixops-protocol.md section 6.1).
anixops/relayd
Package relayd is the relay process of the anixops forward engine (docs/architecture/anixops-protocol.md section 6): the hop runtime that the `anixops-relay` unit runs and the driver (sdk/forward/driver/anixops) controls over a unix socket.
Package relayd is the relay process of the anixops forward engine (docs/architecture/anixops-protocol.md section 6): the hop runtime that the `anixops-relay` unit runs and the driver (sdk/forward/driver/anixops) controls over a unix socket.
conformance
Package conformance is the forward driver conformance suite (docs/architecture/forward-sdk.md section 13): one list of scenarios that every driver in sdk/forward/driver must pass: the in-memory fake, the nftables driver (on a real kernel in a network namespace, nftables.TestNetnsConformance) and the gost driver (against the pinned gost in a network namespace, gost.TestNetnsConformance; on a simulated host, gost.TestConformanceFakeHost).
Package conformance is the forward driver conformance suite (docs/architecture/forward-sdk.md section 13): one list of scenarios that every driver in sdk/forward/driver must pass: the in-memory fake, the nftables driver (on a real kernel in a network namespace, nftables.TestNetnsConformance) and the gost driver (against the pinned gost in a network namespace, gost.TestNetnsConformance; on a simulated host, gost.TestConformanceFakeHost).
fake
Package fake is an in-memory forward driver (sdk/forward/driver) for tests: the conformance suite's reference implementation and, later, the Agent's forward component tests.
Package fake is an in-memory forward driver (sdk/forward/driver) for tests: the conformance suite's reference implementation and, later, the Agent's forward component tests.
gost
Package gost is the forward driver for ENGINE_GOST (docs/architecture/forward-sdk.md section 6.2): it runs the gost hops of a node's state in one gost v3 process, the pinned release the Agent ships (PinnedVersion, owner decision H20), under its own systemd unit anixops-gost.service, so restarting or upgrading the Agent keeps forwarding.
Package gost is the forward driver for ENGINE_GOST (docs/architecture/forward-sdk.md section 6.2): it runs the gost hops of a node's state in one gost v3 process, the pinned release the Agent ships (PinnedVersion, owner decision H20), under its own systemd unit anixops-gost.service, so restarting or upgrading the Agent keeps forwarding.
nftables
Package nftables is the forward driver for ENGINE_NFTABLES (docs/architecture/forward-sdk.md section 6.1): kernel DNAT, masquerade, counters per direction, balancing maps, named quotas and connection limits in one table, "inet anixops_fwd", which is the only nftables object it ever touches (owner decision H13).
Package nftables is the forward driver for ENGINE_NFTABLES (docs/architecture/forward-sdk.md section 6.1): kernel DNAT, masquerade, counters per direction, balancing maps, named quotas and connection limits in one table, "inet anixops_fwd", which is the only nftables object it ever touches (owner decision H13).
Package e2e is the forwarding SDK's multi-namespace end-to-end suite (docs/architecture/forward-sdk.md section 13, F2d).
Package e2e is the forwarding SDK's multi-namespace end-to-end suite (docs/architecture/forward-sdk.md section 13, F2d).
Package leastconn approximates LEAST_CONN balancing (forward-sdk.md section 7.1, L1).
Package leastconn approximates LEAST_CONN balancing (forward-sdk.md section 7.1, L1).
Package model holds the Go domain types of the forwarding contract (anixops.forward.v1, sdk/api/forward/v1): a Route is a chain of Hops from an entry node through optional relays to an exit, and on to Targets, with a Policy (balancing, health checks, circuit breaker, direct mode, target policy) and Limits enforced on the entry.
Package model holds the Go domain types of the forwarding contract (anixops.forward.v1, sdk/api/forward/v1): a Route is a chain of Hops from an entry node through optional relays to an exit, and on to Targets, with a Policy (balancing, health checks, circuit breaker, direct mode, target policy) and Limits enforced on the entry.
Package planner turns forwarding routes into the desired state of every node (docs/architecture/forward-sdk.md section 5).
Package planner turns forwarding routes into the desired state of every node (docs/architecture/forward-sdk.md section 5).
Package relay is the transport library of the AnixOps relay protocol (docs/architecture/anixops-protocol.md, owner decision H22): the frame format, the stream multiplexer, the QUIC carrier with native UDP, carrier selection and the rules that keep a carrier from outliving its owner, between two nodes of one AnixOps deployment.
Package relay is the transport library of the AnixOps relay protocol (docs/architecture/anixops-protocol.md, owner decision H22): the frame format, the stream multiplexer, the QUIC carrier with native UDP, carrier selection and the rules that keep a carrier from outliving its owner, between two nodes of one AnixOps deployment.
link
Package link makes the connections of the AnixOps relay protocol (docs/architecture/anixops-protocol.md, owner decision H22): the TLS 1.3 connection between two nodes with mutual authentication and per-identity pinning, over TCP or inside QUIC, the plaintext connection of a trusted link, and what guards a listener before and during the handshake.
Package link makes the connections of the AnixOps relay protocol (docs/architecture/anixops-protocol.md, owner decision H22): the TLS 1.3 connection between two nodes with mutual authentication and per-identity pinning, over TCP or inside QUIC, the plaintext connection of a trusted link, and what guards a listener before and during the handshake.
relaytest
Package relaytest builds the credentials the relay packages' tests need without the kernel: a link CA shaped like the one internal/agentpki issues (a self-signed ECDSA P-256 root, name-constrained to spiffe://anixops URIs, signing nothing but link certificates) and node certificates of the H28 shape (the node's identity name as CN and only DNS name, its SPIFFE ID as only URI, serverAuth and clientAuth).
Package relaytest builds the credentials the relay packages' tests need without the kernel: a link CA shaped like the one internal/agentpki issues (a self-signed ECDSA P-256 root, name-constrained to spiffe://anixops URIs, signing nothing but link certificates) and node certificates of the H28 shape (the node's identity name as CN and only DNS name, its SPIFFE ID as only URI, serverAuth and clientAuth).
Package validate holds the forwarding route rules that Control (before it stores a route), the planner (before it plans one) and the Agent (for what it can see) all run, so every side refuses the same routes for the same reasons.
Package validate holds the forwarding route rules that Control (before it stores a route), the planner (before it plans one) and the Agent (for what it can see) all run, so every side refuses the same routes for the same reasons.
Package wire is how forwarding rides the Agent Control stream (anix.agent.v1; docs/architecture/forward-sdk.md section 8 and sdk/api/agent/v1/PROTOCOL.md, "Forwarding").
Package wire is how forwarding rides the Agent Control stream (anix.agent.v1; docs/architecture/forward-sdk.md section 8 and sdk/api/agent/v1/PROTOCOL.md, "Forwarding").

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL