Documentation
¶
Overview ¶
Package audit 提供轻量审计日志:命令执行记录以 JSONL 追加写入本地文件, 写前惰性轮转(超阈值改名留档、删最老),磁盘占用有上限,无需定时器。
Index ¶
Constants ¶
View Source
const ( // DefaultMaxSize 触发轮转的文件大小阈值(字节)。 DefaultMaxSize int64 = 10 << 20 // 10 MiB // DefaultKeep 轮转后保留的历史文件份数(.1 最新 … .N 最老,超限删除)。 DefaultKeep = 5 )
默认轮转参数(单条记录约 300B,10MiB ≈ 3 万条,5 份封顶 ~50MiB)。
Variables ¶
This section is empty.
Functions ¶
Types ¶
type Record ¶
type Record struct {
TS string `json:"ts"` // ISO8601 本地时间
Action string `json:"action"` // exec / get / put / hosts / doctor
Host string `json:"host"` // 目标主机(hosts/doctor 可为空)
Cmd string `json:"cmd"` // 脱敏后的命令或操作描述
ExitCode int `json:"exit_code"` // 进程退出码
DurMs int64 `json:"dur_ms"` // 耗时(毫秒)
Truncated bool `json:"truncated,omitempty"` // 输出是否被截断
Err string `json:"err,omitempty"` // 错误消息(失败时)
}
Record 一条审计记录。字段对齐 response.Meta 的 snake_case JSON 风格; Cmd 必须为 Redact 后的脱敏命令,审计日志本身不落敏感原文。
Click to show internal directories.
Click to hide internal directories.