feat: add strict TOML configuration validation
This commit is contained in:
@@ -0,0 +1,99 @@
|
||||
package config
|
||||
|
||||
const (
|
||||
HardMaxAgentEnvelopeBytes uint64 = 1 << 20
|
||||
HardMaxExecutionSpecBytes uint64 = 768 << 10
|
||||
HardMaxRawChunkBytes uint64 = 64 << 10
|
||||
HardMaxScriptBytes uint64 = 10 << 20
|
||||
HardMaxControlRequestBytes uint64 = 16 << 20
|
||||
HardMaxJSONRPCBodyBytes uint64 = 24 << 20
|
||||
HardMaxProtocolDetailBytes uint64 = 4 << 10
|
||||
)
|
||||
|
||||
func defaultServerFile() serverFile {
|
||||
return serverFile{
|
||||
Server: serverCoreFile{
|
||||
DataDir: "/var/lib/rvbox-server", AgentListen: "127.0.0.1:6899",
|
||||
AgentPath: "/v1/agent", ControlSocket: "/run/rvbox/server.sock", ShutdownGrace: "30s",
|
||||
},
|
||||
JSONRPC: jsonRPCFile{Listen: "127.0.0.1:6900"},
|
||||
Queue: serverQueueFile{DefaultTTL: "15m", MaxPerClient: 1000, MaxServer: 10000, RetryInitial: "1s", RetryMax: "30s"},
|
||||
Storage: serverStorageFile{
|
||||
CommandOutputLimitBytes: 10 << 20, CommandTotalLimitBytes: 32 << 20,
|
||||
ClientTotalLimitBytes: 256 << 20, ServerTotalLimitBytes: 4 << 30,
|
||||
TerminalRetention: "720h", AuditLimitBytes: 100 << 20, AuditRetention: "0s",
|
||||
TombstoneMaxEntries: 1_000_000, CommandCloseoutReserveBytes: 64 << 10,
|
||||
FreeSpaceFloorBytes: 256 << 20, SegmentTargetBytes: 256 << 10,
|
||||
DurabilityInterval: "100ms", SQLiteBusyTimeout: "5s",
|
||||
IncidentNoteMaxBytes: 4 << 10, ProtocolDetailMaxBytes: 4 << 10,
|
||||
},
|
||||
Flow: serverFlowFile{
|
||||
RawOutputHighBytes: 64 << 20, RawOutputLowBytes: 32 << 20,
|
||||
UnacknowledgedPerCommandBytes: 1 << 20, UnacknowledgedPerSessionBytes: 8 << 20,
|
||||
WriteDeadline: "10s",
|
||||
},
|
||||
Protocol: serverProtocolFile{
|
||||
HeartbeatIdle: "10s", LivenessTimeout: "30s", TakeoverTTL: "5m",
|
||||
MaxAgentEnvelopeBytes: 1 << 20, MaxExecutionSpecBytes: 768 << 10,
|
||||
MaxRawChunkBytes: 64 << 10, MaxScriptBytes: 10 << 20,
|
||||
MaxControlRequestBytes: 16 << 20, MaxJSONRPCBodyBytes: 24 << 20,
|
||||
},
|
||||
Observability: observabilityFile{
|
||||
Listen: "127.0.0.1:6901", LivenessPath: "/livez", ReadinessPath: "/readyz",
|
||||
MetricsPath: "/metrics", LogLevel: "info", LogFormat: "json",
|
||||
},
|
||||
}
|
||||
}
|
||||
|
||||
func defaultClientFile() clientFile {
|
||||
return clientFile{
|
||||
Client: clientCoreFile{
|
||||
ServerURL: "wss://rvbox.example.test/v1/agent", StateDir: "/var/lib/rvbox",
|
||||
DaemonCWD: "/", MaxRunningCommands: 16, MaxQueuedCommands: 100, ShutdownGrace: "30s",
|
||||
},
|
||||
Shells: shellsFile{
|
||||
DefaultUnix: "sh", DefaultWindows: "powershell", SH: "/bin/sh", Bash: "/bin/bash",
|
||||
CMD: `C:\Windows\System32\cmd.exe`,
|
||||
PowerShell: `C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe`,
|
||||
AllowedCWDRoots: []string{},
|
||||
},
|
||||
Network: clientNetworkFile{
|
||||
HeartbeatIdle: "10s", LivenessTimeout: "30s", ReconnectInitial: "1s", ReconnectMax: "60s",
|
||||
StableSessionReset: "60s", ConnectTimeout: "15s", WriteDeadline: "10s",
|
||||
},
|
||||
Storage: clientStorageFile{
|
||||
CommandOutputLimitBytes: 10 << 20, CommandTotalLimitBytes: 32 << 20,
|
||||
ClientTotalLimitBytes: 256 << 20, TombstoneMaxEntries: 1_000_000,
|
||||
CommandCloseoutReserveBytes: 64 << 10, FreeSpaceFloorBytes: 64 << 20,
|
||||
SegmentTargetBytes: 256 << 10, DurabilityInterval: "100ms",
|
||||
},
|
||||
Flow: clientFlowFile{
|
||||
RawOutputCommandHighBytes: 1 << 20, RawOutputCommandLowBytes: 256 << 10,
|
||||
RawOutputClientHighBytes: 8 << 20, RawOutputClientLowBytes: 4 << 20,
|
||||
UnacknowledgedPerCommandBytes: 1 << 20, UnacknowledgedPerSessionBytes: 8 << 20,
|
||||
},
|
||||
Execution: executionFile{
|
||||
DescendantDrainGrace: "5s", WindowsTermGrace: "10s", HungThreshold: "10m", DiagnosticInterval: "30s",
|
||||
MaxScriptBytes: 10 << 20, MaxExecutionSpecBytes: 768 << 10,
|
||||
MaxAgentEnvelopeBytes: 1 << 20, MaxRawChunkBytes: 64 << 10, ProtocolDetailMaxBytes: 4 << 10,
|
||||
},
|
||||
Observability: observabilityFile{
|
||||
Listen: "127.0.0.1:6902", LivenessPath: "/livez", ReadinessPath: "/readyz",
|
||||
MetricsPath: "/metrics", LogLevel: "info", LogFormat: "json",
|
||||
LogMaxBytes: 10 << 20, LogMaxFiles: 5,
|
||||
},
|
||||
Profiles: defaultProfilesFile(),
|
||||
}
|
||||
}
|
||||
|
||||
func defaultProfilesFile() profilesFile {
|
||||
return profilesFile{
|
||||
Light: profileFile{Enabled: true, RequiredControls: []string{"cpu", "memory", "pids"}, CPUPercent: 50, MemoryMaxBytes: 512 << 20, PIDsMax: 64, LinuxIOReadBPS: map[string]uint64{}, LinuxIOWriteBPS: map[string]uint64{}},
|
||||
CPUMedium: profileFile{Enabled: true, RequiredControls: []string{"cpu"}, CPUPercent: 200},
|
||||
CPUHeavy: profileFile{Enabled: true, RequiredControls: []string{"cpu"}, CPUPercent: 800},
|
||||
MemMedium: profileFile{Enabled: true, RequiredControls: []string{"memory"}, MemoryMaxBytes: 2 << 30},
|
||||
MemHeavy: profileFile{Enabled: true, RequiredControls: []string{"memory"}, MemoryMaxBytes: 8 << 30},
|
||||
DiskMedium: profileFile{RequiredControls: []string{"io"}, WindowsIOReadBPS: 100 << 20, WindowsIOWriteBPS: 50 << 20, LinuxIOReadBPS: map[string]uint64{"8:0": 100 << 20}, LinuxIOWriteBPS: map[string]uint64{"8:0": 50 << 20}},
|
||||
DiskHeavy: profileFile{RequiredControls: []string{"io"}, WindowsIOReadBPS: 500 << 20, WindowsIOWriteBPS: 250 << 20, LinuxIOReadBPS: map[string]uint64{"8:0": 500 << 20}, LinuxIOWriteBPS: map[string]uint64{"8:0": 250 << 20}},
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user