feat: add strict TOML configuration validation
This commit is contained in:
@@ -0,0 +1,377 @@
|
||||
// Package config owns strict TOML decoding, defaulting, and static validation.
|
||||
package config
|
||||
|
||||
import "time"
|
||||
|
||||
type Platform uint8
|
||||
|
||||
const (
|
||||
PlatformUnix Platform = iota + 1
|
||||
PlatformWindows
|
||||
)
|
||||
|
||||
type Server struct {
|
||||
Server ServerCore
|
||||
JSONRPC JSONRPC
|
||||
Queue ServerQueue
|
||||
Storage ServerStorage
|
||||
Flow ServerFlow
|
||||
Protocol ServerProtocol
|
||||
Observability Observability
|
||||
}
|
||||
|
||||
type ServerCore struct {
|
||||
DataDir string
|
||||
AgentListen string
|
||||
AgentPath string
|
||||
ControlSocket string
|
||||
ShutdownGrace time.Duration
|
||||
}
|
||||
|
||||
type JSONRPC struct {
|
||||
Enabled bool
|
||||
Listen string
|
||||
NonLoopbackBind bool
|
||||
}
|
||||
|
||||
type ServerQueue struct {
|
||||
DefaultTTL time.Duration
|
||||
MaxPerClient uint32
|
||||
MaxServer uint32
|
||||
RetryInitial time.Duration
|
||||
RetryMax time.Duration
|
||||
}
|
||||
|
||||
type ServerStorage struct {
|
||||
CommandOutputLimitBytes uint64
|
||||
CommandTotalLimitBytes uint64
|
||||
ClientTotalLimitBytes uint64
|
||||
ServerTotalLimitBytes uint64
|
||||
TerminalRetention time.Duration
|
||||
AuditLimitBytes uint64
|
||||
AuditRetention time.Duration
|
||||
TombstoneMaxEntries uint64
|
||||
CommandCloseoutReserveBytes uint64
|
||||
FreeSpaceFloorBytes uint64
|
||||
SegmentTargetBytes uint64
|
||||
DurabilityInterval time.Duration
|
||||
SQLiteBusyTimeout time.Duration
|
||||
IncidentNoteMaxBytes uint64
|
||||
ProtocolDetailMaxBytes uint64
|
||||
}
|
||||
|
||||
type ServerFlow struct {
|
||||
RawOutputHighBytes uint64
|
||||
RawOutputLowBytes uint64
|
||||
UnacknowledgedPerCommandBytes uint64
|
||||
UnacknowledgedPerSessionBytes uint64
|
||||
WriteDeadline time.Duration
|
||||
}
|
||||
|
||||
type ServerProtocol struct {
|
||||
HeartbeatIdle time.Duration
|
||||
LivenessTimeout time.Duration
|
||||
TakeoverTTL time.Duration
|
||||
MaxAgentEnvelopeBytes uint64
|
||||
MaxExecutionSpecBytes uint64
|
||||
MaxRawChunkBytes uint64
|
||||
MaxScriptBytes uint64
|
||||
MaxControlRequestBytes uint64
|
||||
MaxJSONRPCBodyBytes uint64
|
||||
}
|
||||
|
||||
type Observability struct {
|
||||
Listen string
|
||||
LivenessPath string
|
||||
ReadinessPath string
|
||||
MetricsPath string
|
||||
LogLevel string
|
||||
LogFormat string
|
||||
LogFile string
|
||||
LogMaxBytes uint64
|
||||
LogMaxFiles uint32
|
||||
}
|
||||
|
||||
type Client struct {
|
||||
Client ClientCore
|
||||
TLS TLS
|
||||
Shells Shells
|
||||
Network ClientNetwork
|
||||
Storage ClientStorage
|
||||
Flow ClientFlow
|
||||
Execution Execution
|
||||
Observability Observability
|
||||
Profiles Profiles
|
||||
}
|
||||
|
||||
type ClientCore struct {
|
||||
ServerURL string
|
||||
StateDir string
|
||||
ClientID string
|
||||
DaemonCWD string
|
||||
MaxRunningCommands uint32
|
||||
MaxQueuedCommands uint32
|
||||
ShutdownGrace time.Duration
|
||||
}
|
||||
|
||||
type TLS struct {
|
||||
CAFile string
|
||||
ServerName string
|
||||
}
|
||||
|
||||
type Shells struct {
|
||||
DefaultUnix string
|
||||
DefaultWindows string
|
||||
SH string
|
||||
Bash string
|
||||
CMD string
|
||||
PowerShell string
|
||||
AllowedCWDRoots []string
|
||||
Advertised map[string]string
|
||||
}
|
||||
|
||||
type ClientNetwork struct {
|
||||
HeartbeatIdle time.Duration
|
||||
LivenessTimeout time.Duration
|
||||
ReconnectInitial time.Duration
|
||||
ReconnectMax time.Duration
|
||||
StableSessionReset time.Duration
|
||||
ConnectTimeout time.Duration
|
||||
WriteDeadline time.Duration
|
||||
}
|
||||
|
||||
type ClientStorage struct {
|
||||
CommandOutputLimitBytes uint64
|
||||
CommandTotalLimitBytes uint64
|
||||
ClientTotalLimitBytes uint64
|
||||
TombstoneMaxEntries uint64
|
||||
CommandCloseoutReserveBytes uint64
|
||||
FreeSpaceFloorBytes uint64
|
||||
SegmentTargetBytes uint64
|
||||
DurabilityInterval time.Duration
|
||||
}
|
||||
|
||||
type ClientFlow struct {
|
||||
RawOutputCommandHighBytes uint64
|
||||
RawOutputCommandLowBytes uint64
|
||||
RawOutputClientHighBytes uint64
|
||||
RawOutputClientLowBytes uint64
|
||||
UnacknowledgedPerCommandBytes uint64
|
||||
UnacknowledgedPerSessionBytes uint64
|
||||
}
|
||||
|
||||
type Execution struct {
|
||||
DescendantDrainGrace time.Duration
|
||||
WindowsTermGrace time.Duration
|
||||
HungThreshold time.Duration
|
||||
DiagnosticInterval time.Duration
|
||||
MaxScriptBytes uint64
|
||||
MaxExecutionSpecBytes uint64
|
||||
MaxAgentEnvelopeBytes uint64
|
||||
MaxRawChunkBytes uint64
|
||||
ProtocolDetailMaxBytes uint64
|
||||
}
|
||||
|
||||
type Profiles struct {
|
||||
Light Profile
|
||||
CPUMedium Profile
|
||||
CPUHeavy Profile
|
||||
MemMedium Profile
|
||||
MemHeavy Profile
|
||||
DiskMedium Profile
|
||||
DiskHeavy Profile
|
||||
}
|
||||
|
||||
type Profile struct {
|
||||
Enabled bool
|
||||
RequiredControls []string
|
||||
CPUPercent uint64
|
||||
MemoryMaxBytes uint64
|
||||
PIDsMax uint64
|
||||
WindowsIOReadBPS uint64
|
||||
WindowsIOWriteBPS uint64
|
||||
LinuxIOReadBPS map[string]uint64
|
||||
LinuxIOWriteBPS map[string]uint64
|
||||
}
|
||||
|
||||
type serverFile struct {
|
||||
Server serverCoreFile `toml:"server"`
|
||||
JSONRPC jsonRPCFile `toml:"json_rpc"`
|
||||
Queue serverQueueFile `toml:"queue"`
|
||||
Storage serverStorageFile `toml:"storage"`
|
||||
Flow serverFlowFile `toml:"flow"`
|
||||
Protocol serverProtocolFile `toml:"protocol"`
|
||||
Observability observabilityFile `toml:"observability"`
|
||||
}
|
||||
|
||||
type serverCoreFile struct {
|
||||
DataDir string `toml:"data_dir"`
|
||||
AgentListen string `toml:"agent_listen"`
|
||||
AgentPath string `toml:"agent_path"`
|
||||
ControlSocket string `toml:"control_socket"`
|
||||
ShutdownGrace string `toml:"shutdown_grace"`
|
||||
}
|
||||
|
||||
type jsonRPCFile struct {
|
||||
Enabled bool `toml:"enabled"`
|
||||
Listen string `toml:"listen"`
|
||||
}
|
||||
|
||||
type serverQueueFile struct {
|
||||
DefaultTTL string `toml:"default_ttl"`
|
||||
MaxPerClient uint32 `toml:"max_per_client"`
|
||||
MaxServer uint32 `toml:"max_server"`
|
||||
RetryInitial string `toml:"retry_initial"`
|
||||
RetryMax string `toml:"retry_max"`
|
||||
}
|
||||
|
||||
type serverStorageFile struct {
|
||||
CommandOutputLimitBytes uint64 `toml:"command_output_limit_bytes"`
|
||||
CommandTotalLimitBytes uint64 `toml:"command_total_limit_bytes"`
|
||||
ClientTotalLimitBytes uint64 `toml:"client_total_limit_bytes"`
|
||||
ServerTotalLimitBytes uint64 `toml:"server_total_limit_bytes"`
|
||||
TerminalRetention string `toml:"terminal_retention"`
|
||||
AuditLimitBytes uint64 `toml:"audit_limit_bytes"`
|
||||
AuditRetention string `toml:"audit_retention"`
|
||||
TombstoneMaxEntries uint64 `toml:"tombstone_max_entries"`
|
||||
CommandCloseoutReserveBytes uint64 `toml:"command_closeout_reserve_bytes"`
|
||||
FreeSpaceFloorBytes uint64 `toml:"free_space_floor_bytes"`
|
||||
SegmentTargetBytes uint64 `toml:"segment_target_bytes"`
|
||||
DurabilityInterval string `toml:"durability_interval"`
|
||||
SQLiteBusyTimeout string `toml:"sqlite_busy_timeout"`
|
||||
IncidentNoteMaxBytes uint64 `toml:"incident_note_max_bytes"`
|
||||
ProtocolDetailMaxBytes uint64 `toml:"protocol_detail_max_bytes"`
|
||||
}
|
||||
|
||||
type serverFlowFile struct {
|
||||
RawOutputHighBytes uint64 `toml:"raw_output_high_bytes"`
|
||||
RawOutputLowBytes uint64 `toml:"raw_output_low_bytes"`
|
||||
UnacknowledgedPerCommandBytes uint64 `toml:"unacknowledged_per_command_bytes"`
|
||||
UnacknowledgedPerSessionBytes uint64 `toml:"unacknowledged_per_session_bytes"`
|
||||
WriteDeadline string `toml:"write_deadline"`
|
||||
}
|
||||
|
||||
type serverProtocolFile struct {
|
||||
HeartbeatIdle string `toml:"heartbeat_idle"`
|
||||
LivenessTimeout string `toml:"liveness_timeout"`
|
||||
TakeoverTTL string `toml:"takeover_ttl"`
|
||||
MaxAgentEnvelopeBytes uint64 `toml:"max_agent_envelope_bytes"`
|
||||
MaxExecutionSpecBytes uint64 `toml:"max_execution_spec_bytes"`
|
||||
MaxRawChunkBytes uint64 `toml:"max_raw_chunk_bytes"`
|
||||
MaxScriptBytes uint64 `toml:"max_script_bytes"`
|
||||
MaxControlRequestBytes uint64 `toml:"max_control_request_bytes"`
|
||||
MaxJSONRPCBodyBytes uint64 `toml:"max_json_rpc_body_bytes"`
|
||||
}
|
||||
|
||||
type clientFile struct {
|
||||
Client clientCoreFile `toml:"client"`
|
||||
TLS tlsFile `toml:"tls"`
|
||||
Shells shellsFile `toml:"shells"`
|
||||
Network clientNetworkFile `toml:"network"`
|
||||
Storage clientStorageFile `toml:"storage"`
|
||||
Flow clientFlowFile `toml:"flow"`
|
||||
Execution executionFile `toml:"execution"`
|
||||
Observability observabilityFile `toml:"observability"`
|
||||
Profiles profilesFile `toml:"profiles"`
|
||||
}
|
||||
|
||||
type clientCoreFile struct {
|
||||
ServerURL string `toml:"server_url"`
|
||||
StateDir string `toml:"state_dir"`
|
||||
ClientID string `toml:"client_id"`
|
||||
DaemonCWD string `toml:"daemon_cwd"`
|
||||
MaxRunningCommands uint32 `toml:"max_running_commands"`
|
||||
MaxQueuedCommands uint32 `toml:"max_queued_commands"`
|
||||
ShutdownGrace string `toml:"shutdown_grace"`
|
||||
}
|
||||
|
||||
type tlsFile struct {
|
||||
CAFile string `toml:"ca_file"`
|
||||
ServerName string `toml:"server_name"`
|
||||
}
|
||||
|
||||
type shellsFile struct {
|
||||
DefaultUnix string `toml:"default_unix"`
|
||||
DefaultWindows string `toml:"default_windows"`
|
||||
SH string `toml:"sh"`
|
||||
Bash string `toml:"bash"`
|
||||
CMD string `toml:"cmd"`
|
||||
PowerShell string `toml:"powershell"`
|
||||
AllowedCWDRoots []string `toml:"allowed_cwd_roots"`
|
||||
}
|
||||
|
||||
type clientNetworkFile struct {
|
||||
HeartbeatIdle string `toml:"heartbeat_idle"`
|
||||
LivenessTimeout string `toml:"liveness_timeout"`
|
||||
ReconnectInitial string `toml:"reconnect_initial"`
|
||||
ReconnectMax string `toml:"reconnect_max"`
|
||||
StableSessionReset string `toml:"stable_session_reset"`
|
||||
ConnectTimeout string `toml:"connect_timeout"`
|
||||
WriteDeadline string `toml:"write_deadline"`
|
||||
}
|
||||
|
||||
type clientStorageFile struct {
|
||||
CommandOutputLimitBytes uint64 `toml:"command_output_limit_bytes"`
|
||||
CommandTotalLimitBytes uint64 `toml:"command_total_limit_bytes"`
|
||||
ClientTotalLimitBytes uint64 `toml:"client_total_limit_bytes"`
|
||||
TombstoneMaxEntries uint64 `toml:"tombstone_max_entries"`
|
||||
CommandCloseoutReserveBytes uint64 `toml:"command_closeout_reserve_bytes"`
|
||||
FreeSpaceFloorBytes uint64 `toml:"free_space_floor_bytes"`
|
||||
SegmentTargetBytes uint64 `toml:"segment_target_bytes"`
|
||||
DurabilityInterval string `toml:"durability_interval"`
|
||||
}
|
||||
|
||||
type clientFlowFile struct {
|
||||
RawOutputCommandHighBytes uint64 `toml:"raw_output_command_high_bytes"`
|
||||
RawOutputCommandLowBytes uint64 `toml:"raw_output_command_low_bytes"`
|
||||
RawOutputClientHighBytes uint64 `toml:"raw_output_client_high_bytes"`
|
||||
RawOutputClientLowBytes uint64 `toml:"raw_output_client_low_bytes"`
|
||||
UnacknowledgedPerCommandBytes uint64 `toml:"unacknowledged_per_command_bytes"`
|
||||
UnacknowledgedPerSessionBytes uint64 `toml:"unacknowledged_per_session_bytes"`
|
||||
}
|
||||
|
||||
type executionFile struct {
|
||||
DescendantDrainGrace string `toml:"descendant_drain_grace"`
|
||||
WindowsTermGrace string `toml:"windows_term_grace"`
|
||||
HungThreshold string `toml:"hung_threshold"`
|
||||
DiagnosticInterval string `toml:"diagnostic_interval"`
|
||||
MaxScriptBytes uint64 `toml:"max_script_bytes"`
|
||||
MaxExecutionSpecBytes uint64 `toml:"max_execution_spec_bytes"`
|
||||
MaxAgentEnvelopeBytes uint64 `toml:"max_agent_envelope_bytes"`
|
||||
MaxRawChunkBytes uint64 `toml:"max_raw_chunk_bytes"`
|
||||
ProtocolDetailMaxBytes uint64 `toml:"protocol_detail_max_bytes"`
|
||||
}
|
||||
|
||||
type observabilityFile struct {
|
||||
Listen string `toml:"listen"`
|
||||
LivenessPath string `toml:"liveness_path"`
|
||||
ReadinessPath string `toml:"readiness_path"`
|
||||
MetricsPath string `toml:"metrics_path"`
|
||||
LogLevel string `toml:"log_level"`
|
||||
LogFormat string `toml:"log_format"`
|
||||
LogFile string `toml:"log_file"`
|
||||
LogMaxBytes uint64 `toml:"log_max_bytes"`
|
||||
LogMaxFiles uint32 `toml:"log_max_files"`
|
||||
}
|
||||
|
||||
type profilesFile struct {
|
||||
Light profileFile `toml:"light"`
|
||||
CPUMedium profileFile `toml:"cpu_medium"`
|
||||
CPUHeavy profileFile `toml:"cpu_heavy"`
|
||||
MemMedium profileFile `toml:"mem_medium"`
|
||||
MemHeavy profileFile `toml:"mem_heavy"`
|
||||
DiskMedium profileFile `toml:"disk_medium"`
|
||||
DiskHeavy profileFile `toml:"disk_heavy"`
|
||||
}
|
||||
|
||||
type profileFile struct {
|
||||
Enabled bool `toml:"enabled"`
|
||||
RequiredControls []string `toml:"required_controls"`
|
||||
CPUPercent uint64 `toml:"cpu_percent"`
|
||||
MemoryMaxBytes uint64 `toml:"memory_max_bytes"`
|
||||
PIDsMax uint64 `toml:"pids_max"`
|
||||
WindowsIOReadBPS uint64 `toml:"windows_io_read_bps"`
|
||||
WindowsIOWriteBPS uint64 `toml:"windows_io_write_bps"`
|
||||
LinuxIOReadBPS map[string]uint64 `toml:"linux_io_read_bps"`
|
||||
LinuxIOWriteBPS map[string]uint64 `toml:"linux_io_write_bps"`
|
||||
}
|
||||
Reference in New Issue
Block a user