| Safe Haskell | None |
|---|---|
| Language | GHC2021 |
Ecluse.Cve.Sync
Description
The advisory-sync plan: one CveSyncHandle per mount ecosystem (planCveSync), the
projections the composition root reads off it, and one supervised sync task per handle.
Synopsis
- data CveSyncHandle = CveSyncHandle {}
- data AdvisoryNeed = AdvisoryNeed {
- anEcosystem :: Ecosystem
- anMaxAge :: MaxAdvisoryAge
- anEpss :: EpssRequirement
- anDatabase :: DatabaseRequirement
- planCveSync :: LogEnv -> Maybe AwsEndpoint -> AppConfig -> [AdvisoryNeed] -> IO (Map Ecosystem CveSyncHandle)
- sweepStaleTemps :: LogEnv -> FilePath -> IO ()
- sweepStep :: LogEnv -> FilePath -> IO () -> IO ()
- cveRuleDepsFor :: Map Ecosystem CveSyncHandle -> BreakerReporter -> (Ecosystem -> OutageReport -> IO ()) -> Ecosystem -> RuleDeps
- advisoryFreshnessFor :: Map Ecosystem CveSyncHandle -> Ecosystem -> IO AdvisoryFreshness
- reportPushAge :: LogEnv -> Ecosystem -> CveSyncHandle -> IO ()
- katipOutageReporter :: LogEnv -> Ecosystem -> OutageReport -> IO ()
- outageReportPeriod :: NominalDiffTime
- cveSyncReadiness :: Map Ecosystem CveSyncHandle -> IO Readiness
- cveSyncScheduleFor :: AppConfig -> SyncSchedule
- cveSyncTasks :: LogEnv -> Metrics -> Telemetry -> SyncSchedule -> Map Ecosystem CveSyncHandle -> [IO ()]
- registerAdvisoryAges :: Metrics -> Map Ecosystem CveSyncHandle -> IO ()
Documentation
data CveSyncHandle Source #
One configured ecosystem's advisory-sync wiring.
Constructors
| CveSyncHandle | |
Fields
| |
data AdvisoryNeed Source #
What one vetted mount's rules ask of the advisory stack, read off its own policy at boot.
Constructors
| AdvisoryNeed | |
Fields
| |
planCveSync :: LogEnv -> Maybe AwsEndpoint -> AppConfig -> [AdvisoryNeed] -> IO (Map Ecosystem CveSyncHandle) Source #
Build the advisory-sync plan, one CveSyncHandle per vetted mount ecosystem, or nothing with
no store. A mount the build does not ship awaits an artifact that never comes, so it stays unready.
sweepStaleTemps :: LogEnv -> FilePath -> IO () Source #
Sweep the in-progress downloads an interrupted run left behind, which an emptyDir keeps
across a container restart. The sweep is best effort, per sweepStep.
sweepStep :: LogEnv -> FilePath -> IO () -> IO () Source #
Run one best-effort step of the stale-temp sweep. It logs and swallows an IOError, so a
read-only or mispermissioned data dir does not stop the boot, and any other exception propagates.
cveRuleDepsFor :: Map Ecosystem CveSyncHandle -> BreakerReporter -> (Ecosystem -> OutageReport -> IO ()) -> Ecosystem -> RuleDeps Source #
The rules' boot-bound capabilities for one mount ecosystem. A mount's rules read only their own ecosystem's advisory database. One the plan carries no handle for has none configured, and reports nowhere.
advisoryFreshnessFor :: Map Ecosystem CveSyncHandle -> Ecosystem -> IO AdvisoryFreshness Source #
How old one mount's serving artifact's push is. An ecosystem the plan carries no handle for has no advisory stack at all, so nothing ages and the absent-database path decides instead.
reportPushAge :: LogEnv -> Ecosystem -> CveSyncHandle -> IO () Source #
Report one ecosystem's push age when it passes half its maximum, once per crossing. The latch re-arms when a fresh push brings the age back under, so a long outage does not repeat every poll.
katipOutageReporter :: LogEnv -> Ecosystem -> OutageReport -> IO () Source #
Log one ecosystem's advisory-source outage reports: the start and each reminder at ERROR, the level an operator pages on, and the recovery at INFO. A fault's detail rides along and reaches no client.
outageReportPeriod :: NominalDiffTime Source #
How often a continuing outage reminds the operator: the unloaded-database report's own gap, so an outage costs the log one line per interval on either path.
cveSyncReadiness :: Map Ecosystem CveSyncHandle -> IO Readiness Source #
The readiness verdict over the sync plan. Only a mount whose rules deny on the database waits for its first sync, and one ecosystem's missing artifact leaves the others routable.
cveSyncScheduleFor :: AppConfig -> SyncSchedule Source #
The sync tasks' timing: the shipped boot burst over the configured poll interval. The microsecond
conversion cannot wrap: the config decoder bounds the interval to [1, maxBound div 1_000_000] seconds.
cveSyncTasks :: LogEnv -> Metrics -> Telemetry -> SyncSchedule -> Map Ecosystem CveSyncHandle -> [IO ()] Source #
One supervised sync task per configured ecosystem, each flipping its own one-way readiness flag once its first sync lands. Every role that evaluates rules runs these.
registerAdvisoryAges :: Metrics -> Map Ecosystem CveSyncHandle -> IO () Source #
Register once per role. Callbacks read the slots, so observations survive sync-task restarts.