ecluse:ecluse-core
Safe HaskellNone
LanguageGHC2021

Ecluse.Core.Server.Pipeline.Internal

Description

Integrity admission, metric projections, and the denial audit trail that the packument and tarball handlers share and their specs reach directly. Importing this module opts out of the stability promise of the public hub, Ecluse.Core.Server.Pipeline.

The module field on every line emitted here is pipelineInternalModule, a fixed operator filter key rather than the source module path.

Synopsis

The operator log-filter key

pipelineInternalModule :: Text Source #

The module field every line in this family carries. It is held stable as this value rather than the source module path, so an operator's saved filter keeps matching.

Integrity-floor admission (pure)

admitByIntegrity :: IntegrityFloor floor => floor -> ServeDecision -> ServeDecision -> PackageInfo -> (PackageInfo, [ServeDecision]) Source #

Keep each version's artifacts whose strongest digest meets the integrity floor, per artifact, so a version drops only when no file of it survives and the listing matches the download gate.

Metric-label projections (pure)

packumentServeDecision :: [ServeDecision] -> Decision Source #

Classify a no-survivors packument outcome into the bounded ecluse.serve.decision value: a forbidden set is a denial, any other non-served status a transient unavailability.

statusServeDecision :: PackumentStatus -> Decision Source #

packumentServeDecision over an already-folded status, so the no-survivors path pays for one traversal of the decision list rather than two.

serveDecisionClass :: ServeDecision -> Decision Source #

Classify a single artifact-path serve decision into the bounded metric decision.

denialLabels :: RejectReason -> (Maybe Text, ReasonClass) Source #

Map a reject reason to the ecluse.rule.denials labels: the deciding rule (only a policy denial names one) and the bounded reason class.

evalTier :: [PreparedRule] -> Tier Source #

The rule-evaluation tier a duration is attributed to: effectful when any prepared rule reads through a resilience policy.

transienceCause :: Transience -> Cause Source #

Map an undecidable verdict's transience to the bounded ecluse.rule.effectful.failures cause.

Metric emits (off a serve outcome)

recordDenials :: MetricsPort -> [ServeDecision] -> IO () Source #

Record the ecluse.rule.denials counter for each rejected decision, labelled by the bounded reason class and, for a policy denial, the deciding rule.

recordEffectfulFailures :: MetricsPort -> [Decision] -> IO () Source #

Count each Undecidable among a packument's per-version decisions, the signal that an effectful rule could not consult its source.

Denial audit trail (structured log)

data VersionVerdict Source #

A per-version serve outcome that keeps the version alongside its decision, so a denial's audit line can name the version it refused.

newtype Metadata Source #

An extensible bag of audit fields folded into a denial line's JSON at emit time. It lives at the audit boundary, never on the pure Decision.

Constructors

Metadata (Map Text Text) 

data DenialAudit Source #

Everything one denial audit line records. The advisory DbEtag is the one active at emit, which a shadow swap during the request can make differ from the one the decision read.

denialAuditPayload :: DenialAudit -> SimpleLogPayload Source #

Render a DenialAudit to the structured payload katip folds into the line's data object.

logDenials :: KatipContext m => PackageName -> Maybe DbEtag -> [VersionVerdict] -> m () Source #

Emit one audit log line per denied version, denials only. recordDenials counts the same denials as metrics.

logSkippedChecks :: KatipContext m => PackageName -> Text -> Maybe DbEtag -> [SkippedCheck] -> m () Source #

Emit one audit line per check the admission skipped for unavailability. An unreached check gets no line, and a trusted serve runs no rules, so it never reaches here.

logSkippedChecksOnce :: KatipContext m => (AdmissionIdentity -> IO Bool) -> PackageName -> Text -> Maybe DbEtag -> [SkippedCheck] -> m () Source #

logSkippedChecks once per admission identity (package, version, skipped rule set) for the life of the advisory source's outage, so a public serve that admits again repeats no line.