Documentation
¶
Overview ¶
Package diagnostics provides bounded, redacted operational log storage.
Index ¶
Constants ¶
const ( DefaultMaxBytes = 10 << 20 DefaultMaxAge = 7 * 24 * time.Hour DefaultLimit = 100 HardMaxLimit = 1000 )
Variables ¶
This section is empty.
Functions ¶
func RedactText ¶
RedactText removes common credential-bearing forms before text is allowed into durable diagnostics. This is intentionally conservative: structured attributes are allowlisted separately by Handler, while messages receive masking and a hard size bound at the store boundary.
Types ¶
type AuditSink ¶
type AuditSink interface {
RecordDiagnosticsQuery(context.Context, QueryAudit) error
}
type Event ¶
type Event struct {
ID string `json:"id"`
Timestamp time.Time `json:"timestamp"`
Level string `json:"level"`
Component string `json:"component,omitempty"`
Message string `json:"message"`
Pool string `json:"pool,omitempty"`
Agent string `json:"agent,omitempty"`
Resource string `json:"resource,omitempty"`
Request string `json:"request,omitempty"`
}
Event is the safe, structured representation exposed by diagnostics. Fields not represented here must never cross the diagnostics boundary.
type FileAuditStore ¶
type FileAuditStore struct {
// contains filtered or unexported fields
}
func NewFileAuditStore ¶
func NewFileAuditStore(path string) (*FileAuditStore, error)
func (*FileAuditStore) RecordDiagnosticsQuery ¶
func (s *FileAuditStore) RecordDiagnosticsQuery(ctx context.Context, audit QueryAudit) error
func (*FileAuditStore) RecordResourceCleanup ¶ added in v0.1.59
func (s *FileAuditStore) RecordResourceCleanup(ctx context.Context, audit ResourceCleanupAudit) error
type FileStore ¶
type FileStore struct {
// contains filtered or unexported fields
}
FileStore is a bounded JSONL store. It reads the file for each query so a second daemon process or a restart sees the same durable snapshot.
func NewFileStore ¶
type Handler ¶
type Handler struct {
// contains filtered or unexported fields
}
Handler forwards records to the normal slog handler and independently stores a safe diagnostics projection. Storage failures are deliberately ignored so an observability disk problem cannot break the application.
type MemoryStore ¶
type MemoryStore struct {
// contains filtered or unexported fields
}
MemoryStore provides the same bounded query semantics for tests and embedders that do not need restart persistence.
func NewMemoryStore ¶
func NewMemoryStore() *MemoryStore
type Query ¶
type Query struct {
Since time.Time
Level string
Component string
Pool string
Agent string
Resource string
Limit int
Cursor string
}
Query selects a bounded page of diagnostic events. Cursor values are opaque to callers and are produced by Page.NextCursor.
type QueryAudit ¶
type QueryAudit struct {
Actor string
Since string
Level string
Component string
Pool string
Agent string
Resource string
Limit int
ResultCount int
}
QueryAudit is deliberately limited to safe query metadata.
type ResourceCleanupAudit ¶ added in v0.1.59
type ResourceCleanupAudit struct {
Actor string `json:"actor"`
Mode string `json:"mode"`
Force bool `json:"force"`
State string `json:"state"`
Unreferenced bool `json:"unreferenced"`
OlderThan string `json:"older_than,omitempty"`
CandidateCount int `json:"candidate_count"`
CleanedCount int `json:"cleaned_count"`
SkippedCount int `json:"skipped_count"`
ErrorCount int `json:"error_count"`
}
ResourceCleanupAudit describes safe metadata for an administrator cleanup mutation. It intentionally contains counts and IDs only; callers must not attach resource properties or provider credentials.
type ResourceCleanupAuditSink ¶ added in v0.1.59
type ResourceCleanupAuditSink interface {
RecordResourceCleanup(context.Context, ResourceCleanupAudit) error
}
ResourceCleanupAuditSink is optional so existing embedders with an audit sink that predates cleanup remain source-compatible.