audit

package
v0.1.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 20, 2026 License: MIT Imports: 5 Imported by: 0

Documentation

Overview

Package audit 提供轻量审计日志:命令执行记录以 JSONL 追加写入本地文件, 写前惰性轮转(超阈值改名留档、删最老),磁盘占用有上限,无需定时器。

Index

Constants

View Source
const (
	// DefaultMaxSize 触发轮转的文件大小阈值(字节)。
	DefaultMaxSize int64 = 10 << 20 // 10 MiB
	// DefaultKeep 轮转后保留的历史文件份数(.1 最新 … .N 最老,超限删除)。
	DefaultKeep = 5
)

默认轮转参数(单条记录约 300B,10MiB ≈ 3 万条,5 份封顶 ~50MiB)。

Variables

This section is empty.

Functions

func Append

func Append(path string, rec Record, maxSize int64, keep int) error

Append 追加一条记录到 path(JSONL,一行一条)。 写入前惰性检查:当前文件超过 maxSize 即轮转(见 rotate), 语义:maxSize>0 才启用轮转(0=禁用,文件可无限增长);keep 为保留的历史 份数(.1 最新 … .N 最老,超限删除),keep=0 表示轮转时不保留历史。 默认值(DefaultMaxSize / DefaultKeep)由调用方显式传入,本函数不做隐式替换。

func Redact

func Redact(cmd string) string

Redact 对命令做保守脱敏:识别常见敏感词形态并替换值为 ***。 宁可多脱敏(审计只追溯,不依赖命令全文),但避免误伤通用词(--port、-p、keyfile)。 不命中任何规则时原样返回。

Types

type Record

type Record struct {
	TS        string `json:"ts"`                  // ISO8601 本地时间
	Action    string `json:"action"`              // exec / get / put / hosts / doctor
	Host      string `json:"host"`                // 目标主机(hosts/doctor 可为空)
	Cmd       string `json:"cmd"`                 // 脱敏后的命令或操作描述
	ExitCode  int    `json:"exit_code"`           // 进程退出码
	DurMs     int64  `json:"dur_ms"`              // 耗时(毫秒)
	Truncated bool   `json:"truncated,omitempty"` // 输出是否被截断
	Err       string `json:"err,omitempty"`       // 错误消息(失败时)
}

Record 一条审计记录。字段对齐 response.Meta 的 snake_case JSON 风格; Cmd 必须为 Redact 后的脱敏命令,审计日志本身不落敏感原文。

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL