378 lines
12 KiB
Go
378 lines
12 KiB
Go
// Package config owns strict TOML decoding, defaulting, and static validation.
|
|
package config
|
|
|
|
import "time"
|
|
|
|
type Platform uint8
|
|
|
|
const (
|
|
PlatformUnix Platform = iota + 1
|
|
PlatformWindows
|
|
)
|
|
|
|
type Server struct {
|
|
Server ServerCore
|
|
JSONRPC JSONRPC
|
|
Queue ServerQueue
|
|
Storage ServerStorage
|
|
Flow ServerFlow
|
|
Protocol ServerProtocol
|
|
Observability Observability
|
|
}
|
|
|
|
type ServerCore struct {
|
|
DataDir string
|
|
AgentListen string
|
|
AgentPath string
|
|
ControlSocket string
|
|
ShutdownGrace time.Duration
|
|
}
|
|
|
|
type JSONRPC struct {
|
|
Enabled bool
|
|
Listen string
|
|
NonLoopbackBind bool
|
|
}
|
|
|
|
type ServerQueue struct {
|
|
DefaultTTL time.Duration
|
|
MaxPerClient uint32
|
|
MaxServer uint32
|
|
RetryInitial time.Duration
|
|
RetryMax time.Duration
|
|
}
|
|
|
|
type ServerStorage struct {
|
|
CommandOutputLimitBytes uint64
|
|
CommandTotalLimitBytes uint64
|
|
ClientTotalLimitBytes uint64
|
|
ServerTotalLimitBytes uint64
|
|
TerminalRetention time.Duration
|
|
AuditLimitBytes uint64
|
|
AuditRetention time.Duration
|
|
TombstoneMaxEntries uint64
|
|
CommandCloseoutReserveBytes uint64
|
|
FreeSpaceFloorBytes uint64
|
|
SegmentTargetBytes uint64
|
|
DurabilityInterval time.Duration
|
|
SQLiteBusyTimeout time.Duration
|
|
IncidentNoteMaxBytes uint64
|
|
ProtocolDetailMaxBytes uint64
|
|
}
|
|
|
|
type ServerFlow struct {
|
|
RawOutputHighBytes uint64
|
|
RawOutputLowBytes uint64
|
|
UnacknowledgedPerCommandBytes uint64
|
|
UnacknowledgedPerSessionBytes uint64
|
|
WriteDeadline time.Duration
|
|
}
|
|
|
|
type ServerProtocol struct {
|
|
HeartbeatIdle time.Duration
|
|
LivenessTimeout time.Duration
|
|
TakeoverTTL time.Duration
|
|
MaxAgentEnvelopeBytes uint64
|
|
MaxExecutionSpecBytes uint64
|
|
MaxRawChunkBytes uint64
|
|
MaxScriptBytes uint64
|
|
MaxControlRequestBytes uint64
|
|
MaxJSONRPCBodyBytes uint64
|
|
}
|
|
|
|
type Observability struct {
|
|
Listen string
|
|
LivenessPath string
|
|
ReadinessPath string
|
|
MetricsPath string
|
|
LogLevel string
|
|
LogFormat string
|
|
LogFile string
|
|
LogMaxBytes uint64
|
|
LogMaxFiles uint32
|
|
}
|
|
|
|
type Client struct {
|
|
Client ClientCore
|
|
TLS TLS
|
|
Shells Shells
|
|
Network ClientNetwork
|
|
Storage ClientStorage
|
|
Flow ClientFlow
|
|
Execution Execution
|
|
Observability Observability
|
|
Profiles Profiles
|
|
}
|
|
|
|
type ClientCore struct {
|
|
ServerURL string
|
|
StateDir string
|
|
ClientID string
|
|
DaemonCWD string
|
|
MaxRunningCommands uint32
|
|
MaxQueuedCommands uint32
|
|
ShutdownGrace time.Duration
|
|
}
|
|
|
|
type TLS struct {
|
|
CAFile string
|
|
ServerName string
|
|
}
|
|
|
|
type Shells struct {
|
|
DefaultUnix string
|
|
DefaultWindows string
|
|
SH string
|
|
Bash string
|
|
CMD string
|
|
PowerShell string
|
|
AllowedCWDRoots []string
|
|
Advertised map[string]string
|
|
}
|
|
|
|
type ClientNetwork struct {
|
|
HeartbeatIdle time.Duration
|
|
LivenessTimeout time.Duration
|
|
ReconnectInitial time.Duration
|
|
ReconnectMax time.Duration
|
|
StableSessionReset time.Duration
|
|
ConnectTimeout time.Duration
|
|
WriteDeadline time.Duration
|
|
}
|
|
|
|
type ClientStorage struct {
|
|
CommandOutputLimitBytes uint64
|
|
CommandTotalLimitBytes uint64
|
|
ClientTotalLimitBytes uint64
|
|
TombstoneMaxEntries uint64
|
|
CommandCloseoutReserveBytes uint64
|
|
FreeSpaceFloorBytes uint64
|
|
SegmentTargetBytes uint64
|
|
DurabilityInterval time.Duration
|
|
}
|
|
|
|
type ClientFlow struct {
|
|
RawOutputCommandHighBytes uint64
|
|
RawOutputCommandLowBytes uint64
|
|
RawOutputClientHighBytes uint64
|
|
RawOutputClientLowBytes uint64
|
|
UnacknowledgedPerCommandBytes uint64
|
|
UnacknowledgedPerSessionBytes uint64
|
|
}
|
|
|
|
type Execution struct {
|
|
DescendantDrainGrace time.Duration
|
|
WindowsTermGrace time.Duration
|
|
HungThreshold time.Duration
|
|
DiagnosticInterval time.Duration
|
|
MaxScriptBytes uint64
|
|
MaxExecutionSpecBytes uint64
|
|
MaxAgentEnvelopeBytes uint64
|
|
MaxRawChunkBytes uint64
|
|
ProtocolDetailMaxBytes uint64
|
|
}
|
|
|
|
type Profiles struct {
|
|
Light Profile
|
|
CPUMedium Profile
|
|
CPUHeavy Profile
|
|
MemMedium Profile
|
|
MemHeavy Profile
|
|
DiskMedium Profile
|
|
DiskHeavy Profile
|
|
}
|
|
|
|
type Profile struct {
|
|
Enabled bool
|
|
RequiredControls []string
|
|
CPUPercent uint64
|
|
MemoryMaxBytes uint64
|
|
PIDsMax uint64
|
|
WindowsIOReadBPS uint64
|
|
WindowsIOWriteBPS uint64
|
|
LinuxIOReadBPS map[string]uint64
|
|
LinuxIOWriteBPS map[string]uint64
|
|
}
|
|
|
|
type serverFile struct {
|
|
Server serverCoreFile `toml:"server"`
|
|
JSONRPC jsonRPCFile `toml:"json_rpc"`
|
|
Queue serverQueueFile `toml:"queue"`
|
|
Storage serverStorageFile `toml:"storage"`
|
|
Flow serverFlowFile `toml:"flow"`
|
|
Protocol serverProtocolFile `toml:"protocol"`
|
|
Observability observabilityFile `toml:"observability"`
|
|
}
|
|
|
|
type serverCoreFile struct {
|
|
DataDir string `toml:"data_dir"`
|
|
AgentListen string `toml:"agent_listen"`
|
|
AgentPath string `toml:"agent_path"`
|
|
ControlSocket string `toml:"control_socket"`
|
|
ShutdownGrace string `toml:"shutdown_grace"`
|
|
}
|
|
|
|
type jsonRPCFile struct {
|
|
Enabled bool `toml:"enabled"`
|
|
Listen string `toml:"listen"`
|
|
}
|
|
|
|
type serverQueueFile struct {
|
|
DefaultTTL string `toml:"default_ttl"`
|
|
MaxPerClient uint32 `toml:"max_per_client"`
|
|
MaxServer uint32 `toml:"max_server"`
|
|
RetryInitial string `toml:"retry_initial"`
|
|
RetryMax string `toml:"retry_max"`
|
|
}
|
|
|
|
type serverStorageFile struct {
|
|
CommandOutputLimitBytes uint64 `toml:"command_output_limit_bytes"`
|
|
CommandTotalLimitBytes uint64 `toml:"command_total_limit_bytes"`
|
|
ClientTotalLimitBytes uint64 `toml:"client_total_limit_bytes"`
|
|
ServerTotalLimitBytes uint64 `toml:"server_total_limit_bytes"`
|
|
TerminalRetention string `toml:"terminal_retention"`
|
|
AuditLimitBytes uint64 `toml:"audit_limit_bytes"`
|
|
AuditRetention string `toml:"audit_retention"`
|
|
TombstoneMaxEntries uint64 `toml:"tombstone_max_entries"`
|
|
CommandCloseoutReserveBytes uint64 `toml:"command_closeout_reserve_bytes"`
|
|
FreeSpaceFloorBytes uint64 `toml:"free_space_floor_bytes"`
|
|
SegmentTargetBytes uint64 `toml:"segment_target_bytes"`
|
|
DurabilityInterval string `toml:"durability_interval"`
|
|
SQLiteBusyTimeout string `toml:"sqlite_busy_timeout"`
|
|
IncidentNoteMaxBytes uint64 `toml:"incident_note_max_bytes"`
|
|
ProtocolDetailMaxBytes uint64 `toml:"protocol_detail_max_bytes"`
|
|
}
|
|
|
|
type serverFlowFile struct {
|
|
RawOutputHighBytes uint64 `toml:"raw_output_high_bytes"`
|
|
RawOutputLowBytes uint64 `toml:"raw_output_low_bytes"`
|
|
UnacknowledgedPerCommandBytes uint64 `toml:"unacknowledged_per_command_bytes"`
|
|
UnacknowledgedPerSessionBytes uint64 `toml:"unacknowledged_per_session_bytes"`
|
|
WriteDeadline string `toml:"write_deadline"`
|
|
}
|
|
|
|
type serverProtocolFile struct {
|
|
HeartbeatIdle string `toml:"heartbeat_idle"`
|
|
LivenessTimeout string `toml:"liveness_timeout"`
|
|
TakeoverTTL string `toml:"takeover_ttl"`
|
|
MaxAgentEnvelopeBytes uint64 `toml:"max_agent_envelope_bytes"`
|
|
MaxExecutionSpecBytes uint64 `toml:"max_execution_spec_bytes"`
|
|
MaxRawChunkBytes uint64 `toml:"max_raw_chunk_bytes"`
|
|
MaxScriptBytes uint64 `toml:"max_script_bytes"`
|
|
MaxControlRequestBytes uint64 `toml:"max_control_request_bytes"`
|
|
MaxJSONRPCBodyBytes uint64 `toml:"max_json_rpc_body_bytes"`
|
|
}
|
|
|
|
type clientFile struct {
|
|
Client clientCoreFile `toml:"client"`
|
|
TLS tlsFile `toml:"tls"`
|
|
Shells shellsFile `toml:"shells"`
|
|
Network clientNetworkFile `toml:"network"`
|
|
Storage clientStorageFile `toml:"storage"`
|
|
Flow clientFlowFile `toml:"flow"`
|
|
Execution executionFile `toml:"execution"`
|
|
Observability observabilityFile `toml:"observability"`
|
|
Profiles profilesFile `toml:"profiles"`
|
|
}
|
|
|
|
type clientCoreFile struct {
|
|
ServerURL string `toml:"server_url"`
|
|
StateDir string `toml:"state_dir"`
|
|
ClientID string `toml:"client_id"`
|
|
DaemonCWD string `toml:"daemon_cwd"`
|
|
MaxRunningCommands uint32 `toml:"max_running_commands"`
|
|
MaxQueuedCommands uint32 `toml:"max_queued_commands"`
|
|
ShutdownGrace string `toml:"shutdown_grace"`
|
|
}
|
|
|
|
type tlsFile struct {
|
|
CAFile string `toml:"ca_file"`
|
|
ServerName string `toml:"server_name"`
|
|
}
|
|
|
|
type shellsFile struct {
|
|
DefaultUnix string `toml:"default_unix"`
|
|
DefaultWindows string `toml:"default_windows"`
|
|
SH string `toml:"sh"`
|
|
Bash string `toml:"bash"`
|
|
CMD string `toml:"cmd"`
|
|
PowerShell string `toml:"powershell"`
|
|
AllowedCWDRoots []string `toml:"allowed_cwd_roots"`
|
|
}
|
|
|
|
type clientNetworkFile struct {
|
|
HeartbeatIdle string `toml:"heartbeat_idle"`
|
|
LivenessTimeout string `toml:"liveness_timeout"`
|
|
ReconnectInitial string `toml:"reconnect_initial"`
|
|
ReconnectMax string `toml:"reconnect_max"`
|
|
StableSessionReset string `toml:"stable_session_reset"`
|
|
ConnectTimeout string `toml:"connect_timeout"`
|
|
WriteDeadline string `toml:"write_deadline"`
|
|
}
|
|
|
|
type clientStorageFile struct {
|
|
CommandOutputLimitBytes uint64 `toml:"command_output_limit_bytes"`
|
|
CommandTotalLimitBytes uint64 `toml:"command_total_limit_bytes"`
|
|
ClientTotalLimitBytes uint64 `toml:"client_total_limit_bytes"`
|
|
TombstoneMaxEntries uint64 `toml:"tombstone_max_entries"`
|
|
CommandCloseoutReserveBytes uint64 `toml:"command_closeout_reserve_bytes"`
|
|
FreeSpaceFloorBytes uint64 `toml:"free_space_floor_bytes"`
|
|
SegmentTargetBytes uint64 `toml:"segment_target_bytes"`
|
|
DurabilityInterval string `toml:"durability_interval"`
|
|
}
|
|
|
|
type clientFlowFile struct {
|
|
RawOutputCommandHighBytes uint64 `toml:"raw_output_command_high_bytes"`
|
|
RawOutputCommandLowBytes uint64 `toml:"raw_output_command_low_bytes"`
|
|
RawOutputClientHighBytes uint64 `toml:"raw_output_client_high_bytes"`
|
|
RawOutputClientLowBytes uint64 `toml:"raw_output_client_low_bytes"`
|
|
UnacknowledgedPerCommandBytes uint64 `toml:"unacknowledged_per_command_bytes"`
|
|
UnacknowledgedPerSessionBytes uint64 `toml:"unacknowledged_per_session_bytes"`
|
|
}
|
|
|
|
type executionFile struct {
|
|
DescendantDrainGrace string `toml:"descendant_drain_grace"`
|
|
WindowsTermGrace string `toml:"windows_term_grace"`
|
|
HungThreshold string `toml:"hung_threshold"`
|
|
DiagnosticInterval string `toml:"diagnostic_interval"`
|
|
MaxScriptBytes uint64 `toml:"max_script_bytes"`
|
|
MaxExecutionSpecBytes uint64 `toml:"max_execution_spec_bytes"`
|
|
MaxAgentEnvelopeBytes uint64 `toml:"max_agent_envelope_bytes"`
|
|
MaxRawChunkBytes uint64 `toml:"max_raw_chunk_bytes"`
|
|
ProtocolDetailMaxBytes uint64 `toml:"protocol_detail_max_bytes"`
|
|
}
|
|
|
|
type observabilityFile struct {
|
|
Listen string `toml:"listen"`
|
|
LivenessPath string `toml:"liveness_path"`
|
|
ReadinessPath string `toml:"readiness_path"`
|
|
MetricsPath string `toml:"metrics_path"`
|
|
LogLevel string `toml:"log_level"`
|
|
LogFormat string `toml:"log_format"`
|
|
LogFile string `toml:"log_file"`
|
|
LogMaxBytes uint64 `toml:"log_max_bytes"`
|
|
LogMaxFiles uint32 `toml:"log_max_files"`
|
|
}
|
|
|
|
type profilesFile struct {
|
|
Light profileFile `toml:"light"`
|
|
CPUMedium profileFile `toml:"cpu_medium"`
|
|
CPUHeavy profileFile `toml:"cpu_heavy"`
|
|
MemMedium profileFile `toml:"mem_medium"`
|
|
MemHeavy profileFile `toml:"mem_heavy"`
|
|
DiskMedium profileFile `toml:"disk_medium"`
|
|
DiskHeavy profileFile `toml:"disk_heavy"`
|
|
}
|
|
|
|
type profileFile struct {
|
|
Enabled bool `toml:"enabled"`
|
|
RequiredControls []string `toml:"required_controls"`
|
|
CPUPercent uint64 `toml:"cpu_percent"`
|
|
MemoryMaxBytes uint64 `toml:"memory_max_bytes"`
|
|
PIDsMax uint64 `toml:"pids_max"`
|
|
WindowsIOReadBPS uint64 `toml:"windows_io_read_bps"`
|
|
WindowsIOWriteBPS uint64 `toml:"windows_io_write_bps"`
|
|
LinuxIOReadBPS map[string]uint64 `toml:"linux_io_read_bps"`
|
|
LinuxIOWriteBPS map[string]uint64 `toml:"linux_io_write_bps"`
|
|
}
|