Documentation
¶
Overview ¶
Package asset contains the technical fleet Asset and business-level BusinessAsset models. It is pure domain: it imports only shared and the stdlib.
Tenancy invariant: every aggregate carries a NON-EMPTY TenantID. Under Row Level Security (migration 0057) the empty string means DENY, not the default tenant, so an empty tenant id is rejected at construction. The default single-tenant deployment supplies a non-empty tenant id.
Index ¶
- type Asset
- type BusinessAsset
- func (a BusinessAsset) AcceptsAssignments() bool
- func (a *BusinessAsset) Transition(to BusinessAssetLifecycle, expectedVersion int, actor string, now time.Time) error
- func (a *BusinessAsset) Update(name, description string, assetType BusinessAssetType, criticality Criticality, ...) error
- func (a *BusinessAsset) Validate() error
- type BusinessAssetLifecycle
- type BusinessAssetType
- type ComponentMembership
- type Criticality
- type Edge
- type EdgeConfidence
- type EdgeKind
- type Kind
- type MembershipRole
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Asset ¶
type Asset struct {
ID shared.ID
TenantID shared.ID
Kind Kind
Key string // deterministic natural key per kind (e.g. an image digest)
Name string
Attributes map[string]string
Audit shared.Audit
}
Asset is one canonical thing in the estate. (TenantID, Kind, Key) is its natural identity: the same real thing observed by two producers resolves to one asset via that tuple.
type BusinessAsset ¶
type BusinessAsset struct {
ID shared.ID
TenantID shared.ID
Key string
Name string
Description string
Type BusinessAssetType
Criticality Criticality
Lifecycle BusinessAssetLifecycle
Owner string
Metadata map[string]string
Version int
Audit shared.Audit
}
func NewBusinessAsset ¶
func NewBusinessAsset(id, tenantID shared.ID, key, name, description string, assetType BusinessAssetType, criticality Criticality, owner string, metadata map[string]string, actor string, now time.Time) (*BusinessAsset, error)
func (BusinessAsset) AcceptsAssignments ¶
func (a BusinessAsset) AcceptsAssignments() bool
func (*BusinessAsset) Transition ¶
func (a *BusinessAsset) Transition(to BusinessAssetLifecycle, expectedVersion int, actor string, now time.Time) error
func (*BusinessAsset) Update ¶
func (a *BusinessAsset) Update(name, description string, assetType BusinessAssetType, criticality Criticality, owner string, metadata map[string]string, expectedVersion int, actor string, now time.Time) error
func (*BusinessAsset) Validate ¶
func (a *BusinessAsset) Validate() error
type BusinessAssetLifecycle ¶
type BusinessAssetLifecycle string
const ( BusinessAssetDraft BusinessAssetLifecycle = "draft" BusinessAssetActive BusinessAssetLifecycle = "active" BusinessAssetDecommissioning BusinessAssetLifecycle = "decommissioning" BusinessAssetRetired BusinessAssetLifecycle = "retired" )
func (BusinessAssetLifecycle) Valid ¶
func (l BusinessAssetLifecycle) Valid() bool
type BusinessAssetType ¶
type BusinessAssetType string
const ( BusinessAssetProduct BusinessAssetType = "product" BusinessAssetApplication BusinessAssetType = "application" BusinessAssetSystem BusinessAssetType = "system" BusinessAssetBusinessService BusinessAssetType = "business_service" )
func (BusinessAssetType) Valid ¶
func (t BusinessAssetType) Valid() bool
type ComponentMembership ¶
type ComponentMembership struct {
TenantID shared.ID
AssetID shared.ID
ComponentID shared.ID
Role MembershipRole
Provenance string
}
func (ComponentMembership) Validate ¶
func (m ComponentMembership) Validate() error
type Criticality ¶
type Criticality string
const ( CriticalityCritical Criticality = "critical" CriticalityHigh Criticality = "high" CriticalityMedium Criticality = "medium" CriticalityLow Criticality = "low" )
func (Criticality) Valid ¶
func (c Criticality) Valid() bool
type Edge ¶
type Edge struct {
TenantID shared.ID
From shared.ID
To shared.ID
Kind EdgeKind
Provenance shared.ID
Confidence EdgeConfidence
}
Edge is a typed, provenance-carrying relationship. Provenance references the observation that produced the edge; an edge without provenance is invalid, because an unattributable edge cannot be trusted by the attack-path traversal that consumes it.
type EdgeConfidence ¶
type EdgeConfidence string
EdgeConfidence states whether an edge was directly observed or inferred from other evidence.
const ( EdgeObserved EdgeConfidence = "observed" EdgeInferred EdgeConfidence = "inferred" )
func (EdgeConfidence) Valid ¶
func (c EdgeConfidence) Valid() bool
Valid reports whether c is a known edge confidence.
type EdgeKind ¶
type EdgeKind string
EdgeKind is the closed set of typed relationships between assets.
const ( EdgeRuns EdgeKind = "runs" // host/cluster runs workload EdgeExposes EdgeKind = "exposes" // exposure exposes workload EdgeDependsOn EdgeKind = "depends_on" // workload depends on component EdgeCanAssume EdgeKind = "can_assume" // identity can assume identity EdgeReaches EdgeKind = "reaches" // reachability edge EdgeAffectedBy EdgeKind = "affected_by" // asset affected by a finding EdgeMounts EdgeKind = "mounts" // workload mounts identity/secret )
type Kind ¶
type Kind string
Kind is the closed set of asset kinds. It is extended deliberately, never by free string.
const ( KindHost Kind = "host" KindWorkload Kind = "workload" KindImage Kind = "image" KindCloudAccount Kind = "cloud_account" KindStorage Kind = "storage" KindExposure Kind = "exposure" KindIdentity Kind = "identity" KindNamespace Kind = "namespace" KindCluster Kind = "cluster" KindRepository Kind = "repository" )
type MembershipRole ¶
type MembershipRole string
const ( MembershipPrimary MembershipRole = "primary" MembershipSupporting MembershipRole = "supporting" MembershipDependency MembershipRole = "dependency" )
func (MembershipRole) Valid ¶
func (r MembershipRole) Valid() bool