openwatch

module
v0.5.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Jul 14, 2026 License: Apache-2.0

README

OpenWatch

The Compliance Operating System — See Everything, Continuously.

Go CI Documentation GitHub Discussions


An auditor asks: "Were these 200 servers compliant with STIG on January 15th?"

With manual processes, that question takes a week to answer. With point-in-time scanning tools, you can only answer if you happened to scan that day. With OpenWatch, it is a query — executed in seconds, backed by machine-verifiable evidence, exportable as CSV, JSON, or PDF.

OpenWatch is the compliance operating system for teams managing Linux infrastructure under STIG, CIS, NIST 800-53, PCI-DSS, and FedRAMP. It connects to your servers over SSH, runs 630 compliance checks via the Kensa engine, and provides continuous visibility into compliance posture — not just what's passing now, but what was passing last Tuesday, what drifted since your last assessment, and what needs attention before your next one.

Project status — Go rebuild, generally available. OpenWatch is a single Go binary that serves both the REST API and the embedded React UI (the original Python/FastAPI implementation was archived out of the repo on 2026-06-05). The Go tree lives at the repo root: Go 1.26 backend (cmd/, internal/), React 19 + TanStack frontend (frontend/), PostgreSQL-only. The current version is 0.4.0, on the general-availability line that opened with 0.2.0.

The Problem with Point-in-Time Compliance

Most compliance tools scan your systems and tell you what's passing today. That's useful, but it is not enough:

  • The posture decays immediately. A server that passed STIG on Monday can drift by Wednesday. Without continuous monitoring, you won't know until the next audit.
  • Historical questions are unanswerable. "Were we compliant during the assessment window?" requires re-scanning, which only tells you about now, not then.
  • Exceptions live in spreadsheets. Approved deviations from policy are tracked in email threads and shared drives, disconnected from the scanning tool.
  • Drift is invisible. When a rule that was passing starts failing, no one notices until an assessor finds it.
  • Evidence is assembled, not generated. Teams spend days before an audit compiling screenshots and command outputs into binders.

OpenWatch solves all five problems.

What OpenWatch Does

Continuous Compliance Posture

Scan your fleet on a schedule, or let OpenWatch adapt the cadence to each host's compliance state: worse posture scans more often. The defaults run from every 4 hours for a critical host to every 48 hours for a fully compliant one, and are operator-tunable per band. The posture dashboard updates in real time.

Temporal Compliance Queries

Ask "What was our STIG compliance on February 1st?" and get an answer backed by historical scan data. OpenWatch captures daily posture snapshots and stores the full history. Compliance posture is not a snapshot; it is a timeline.

Compliance Drift Detection

When a rule that was passing starts failing, OpenWatch raises an alert automatically. Track drift events through acknowledgment to resolution. Know the moment your posture degrades — not weeks later when an assessor tells you.

Governance and Exception Management

Some controls require approved exceptions. OpenWatch provides structured exception workflows: request, approve, reject, time-limit, revoke — all with an audit trail. No more tracking waivers in spreadsheets.

Audit-Ready Evidence and Exports

Every check captures the exact command executed, the system's raw output, the expected value, and the actual value. Export compliance data as CSV, JSON, or PDF. Build saved queries for recurring audit requests. The evidence is generated by the scan, not assembled after the fact.

Multi-Framework, Single Scan

One scan maps findings to STIG, CIS, NIST 800-53, PCI-DSS, and FedRAMP simultaneously. The same evidence satisfies multiple assessors. No duplicate scans, no duplicate reports.

How It Compares

OpenWatch is a compliance platform — it manages the lifecycle of compliance across a fleet, not just the scan itself. This table compares approaches to managing ongoing compliance posture:

OpenWatch Manual Processes Point-in-Time Scanners Enterprise Platforms (Tenable, etc.)
Multi-host scanning One click, 100+ hosts SSH into each server Script it yourself Agent or credentialed scan
Dashboard and history Built-in Spreadsheets None Commercial dashboard
Temporal compliance Query any date Impossible Not available Limited
Drift detection Automatic alerts Manual discovery Not available Partial
Exception workflows Structured with audit trail Spreadsheets and email Not available Not available
Framework coverage STIG + CIS + NIST + PCI + FedRAMP Whatever you check Per-benchmark profiles CIS/STIG/PCI
Remediation 23 typed mechanisms with rollback Run commands by hand Basic scripts Not available
Evidence model Structured JSON per check Screenshots Varies by tool PDF reports
Setup time 10 minutes N/A Varies Days + licensing
Cost Free (Community) / Paid (Pro) Labor Free - varies $50K+/year

Note: OpenWatch's scanning engine is Kensa, which takes a different architectural approach than SCAP-based tools. Kensa separates rules from implementations, treats frameworks as metadata, and detects host capabilities at runtime. Organizations with SCAP mandate requirements can use SCAP tools for assessment alongside OpenWatch for remediation, governance, and continuous monitoring.

Deploy in 10 minutes

Requirements: a Linux host (RHEL/Rocky/Fedora/Oracle or Ubuntu/Debian), PostgreSQL, and 4 GB RAM. No Docker, Podman, or containers are required.

sudo dnf install ./openwatch-*.rpm     # RHEL / Rocky / Fedora / Oracle
sudo apt install ./openwatch_*.deb     # Ubuntu / Debian

sudo openwatch migrate                 # apply database migrations
sudo openwatch create-admin \          # create the first admin user
  --username admin --email you@example.com --password '...'
sudo systemctl enable --now openwatch  # start at boot

Open https://localhost:8443 and sign in with the admin user you created.

Run your first scan
  1. Add credentials — Settings > System Credentials > add your SSH user/key
  2. Add a host — Hosts > Add Host > enter IP, select credentials
  3. Scan — Click Scan on the host card

Results appear in under a minute. OpenWatch ships with 630 built-in Kensa rules — human-readable YAML, not XML — ready to go.

Architecture

┌─────────────────────────────────────────────────────────────┐
│                       You / Your Team                       │
└──────────────────────────┬──────────────────────────────────┘
                           │
┌──────────────────────────▼──────────────────────────────────┐
│  OpenWatch UI (React 19 · TanStack Router/Query · MUI)      │
│  Dashboard · Posture · Alerts · Exceptions · Reports        │
├─────────────────────────────────────────────────────────────┤
│  OpenWatch API (Go 1.26 · REST)                             │
│  Auth · RBAC · Scheduling · Audit · Exports                 │
├────────────────────────┬────────────────────────────────────┤
│  Kensa Engine          │  Worker (Go)                       │
│  630 YAML rules        │  Async scanning                   │
│  23 remediation types  │  Adaptive scheduling              │
│  Evidence capture      │  Drift detection                  │
├────────────────────────┴────────────────────────────────────┤
│  PostgreSQL                                                 │
│  All persistent data + native job queue (SKIP LOCKED)      │
└─────────────────────────────────────────────────────────────┘
                           │
                      SSH (port 22)
                           │
┌──────────────────────────▼──────────────────────────────────┐
│   Your Linux servers (RHEL, Rocky, Alma, Oracle, Ubuntu)   │
└─────────────────────────────────────────────────────────────┘

Security

OpenWatch is built for environments where security is the requirement, not an afterthought:

Control Implementation
Encryption at rest AES-256-GCM for stored credentials and sensitive data
Authentication RS256 JWT with Argon2id password hashing
Multi-factor auth TOTP (Google Authenticator, Authy) with backup codes
FIPS 140-3 Optional FIPS build (make build-fips) using the Go-native FIPS module
Authorization RBAC with 5 built-in roles (viewer, auditor, ops_lead, security_admin, admin) and 67 permissions; custom roles supported
Audit logging All authentication, authorization, and compliance events logged
Rate limiting Per-IP sliding window on the auth endpoints (login, MFA verify): 20 attempts/min, then 429
Transport TLS 1.2+ with FIPS cipher suites in production
Target security No agents — scans over SSH, nothing installed on targets

Report vulnerabilities to security@hanalyx.com.

API-First Design

OpenWatch exposes a versioned REST API under /api/v1/. The contract lives in api/openapi.yaml (the source of truth). Everything you can do in the UI, you can automate:

# Authenticate
TOKEN=$(curl -sk -X POST https://localhost:8443/api/v1/auth/login \
  -H "Content-Type: application/json" \
  -d '{"username":"admin","password":"..."}' | jq -r '.access_token')

# Add a host
HOST_ID=$(curl -sk -X POST https://localhost:8443/api/v1/hosts \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"hostname":"web-01","ip_address":"192.168.1.10","port":22}' | jq -r '.id')

# List hosts
curl -sk https://localhost:8443/api/v1/hosts \
  -H "Authorization: Bearer $TOKEN" | jq '.'

Integrate compliance scanning into CI/CD pipelines, SIEM platforms, or custom dashboards.

Administration

OpenWatch is a single binary. Service lifecycle is managed by systemd; admin operations are subcommands of the openwatch binary itself:

# Service lifecycle (systemd unit installed by the RPM/DEB)
systemctl start openwatch        # start the service
systemctl status openwatch       # service status
journalctl -u openwatch -f       # follow logs

# Admin operations (openwatch subcommands)
openwatch migrate                # apply pending database migrations
openwatch create-admin \         # create the first admin user
  --username admin --email admin@example.com --password '...'
openwatch check-config           # validate and print the resolved config
openwatch --version              # build metadata

# Health
curl -k https://localhost:8443/api/v1/health

Production Deployment

The native package (installed above) lays down the openwatch binary (API + embedded UI), a hardened systemd unit, default config under /etc/openwatch/, and a dedicated system user. Before production use, replace the demo TLS cert under /etc/openwatch/tls/ with your own; FIPS 140-3 builds come from make build-fips. See docs/guides/PRODUCTION_DEPLOYMENT.md and docs/guides/SECURITY_HARDENING.md.

Monitoring

OpenWatch exposes a health endpoint for external liveness checks. It returns 200 when healthy and 503 when a dependency (such as the database) is down:

curl -k https://localhost:8443/api/v1/health
# {"status":"healthy","db_connected":true,"version":"..."}

See docs/guides/MONITORING_SETUP.md for the health/version endpoints, fleet liveness, and audit-event monitoring. (A Prometheus /metrics endpoint is on the roadmap, not in the current build.)

Documentation

Topic Link
API contract api/openapi.yaml (source of truth)
API guide docs/guides/API_GUIDE.md
Full documentation hanalyx.github.io/OpenWatch
Quickstart docs/guides/QUICKSTART.md
Production deployment docs/guides/PRODUCTION_DEPLOYMENT.md
Security hardening docs/guides/SECURITY_HARDENING.md
Behavioral specs (engineering SSOT) specs/, registered in specter.yaml

Part of the Hanalyx Compliance Platform

OpenWatch is the compliance operating system — the dashboard, the scheduler, the governance layer. Kensa is the compliance engine underneath — 630 rules, 27 remediation mechanisms, automatic rollback, all over SSH.

If you want a CLI that integrates into scripts and pipelines, start with Kensa. If you want a platform for your team with a dashboard, scheduling, and audit workflows, start here.

Community

Have a question, idea, or want to share how you're using OpenWatch?

Join the Discussion

  • Q&A — Get help with setup, scanning, and configuration
  • Ideas — Propose features and integrations
  • Show and Tell — Share your compliance workflows

Found a bug? Open an issue.

Contributing

The Go tree lives at the repo root:

# Backend (Go 1.26)
go build ./...
go test ./internal/... -count=1
specter check          # spec schema validation

# Frontend (React 19 + TanStack + Vite)
cd frontend
npm install
npm run dev            # http://localhost:5173
npx vitest run

The legacy Python implementation is archived outside the repo and is no longer built or tested here. See CONTRIBUTING.md before submitting a PR.

License

OpenWatch is licensed under the Apache License 2.0 (see LICENSE and NOTICE).

  • Free to use, modify, self-host, and redistribute under Apache 2.0.
  • The compiled binary statically links the Kensa compliance engine, which is BSL-1.1, so a binary distribution is a combined Apache/BSL work (see NOTICE).

Third-party dependency licenses: THIRD-PARTY-NOTICES.md. Commercial inquiries: legal@hanalyx.com

Directories

Path Synopsis
cmd
openwatch command
openwatch is the OpenWatch backend daemon (Go rebuild).
openwatch is the OpenWatch backend daemon (Go rebuild).
internal
accountpolicy
Background password-expiry sweep, wired in serve.
Background password-expiry sweep, wired in serve.
activity
Package activity merges alerts + transactions + intelligence_events + audit_events into a single time-ordered feed, with per-source RBAC and seek-cursor pagination.
Package activity merges alerts + transactions + intelligence_events + audit_events into a single time-ordered feed, with per-source RBAC and seek-cursor pagination.
alertrouter
Package alertrouter is the bridge between OpenWatch's in-process event bus (internal/eventbus) and external notification channels (Slack, email, webhook, PagerDuty).
Package alertrouter is the bridge between OpenWatch's in-process event bus (internal/eventbus) and external notification channels (Slack, email, webhook, PagerDuty).
alertrouter/channels/stdout
Package stdout implements an alertrouter.Channel that logs alerts to the structured slog default logger at INFO level.
Package stdout implements an alertrouter.Channel that logs alerts to the structured slog default logger at INFO level.
alerts
Package alerts owns the lifecycle service for persisted alerts — acknowledge / silence / resolve / dismiss transitions plus the auto-resolve hook that closes host_unreachable when host_recovered arrives.
Package alerts owns the lifecycle service for persisted alerts — acknowledge / silence / resolve / dismiss transitions plus the auto-resolve hook that closes host_unreachable when host_recovered arrives.
apitoken
Package apitoken manages API service-account tokens for automation (CI, scripts) that call the REST API without an interactive session.
Package apitoken manages API service-account tokens for automation (CI, scripts) that call the REST API without an interactive session.
audit
Package audit emits and stores audit events per the contract in app/docs/audit_event_taxonomy.md and app/specs/system/audit-emission.spec.yaml.
Package audit emits and stores audit events per the contract in app/docs/audit_event_taxonomy.md and app/specs/system/audit-emission.spec.yaml.
auth
Package auth provides RBAC: a codegen-typed permission registry, built-in roles, and the RequirePermission middleware that combines RBAC and license-gate checks in one pass.
Package auth provides RBAC: a codegen-typed permission registry, built-in roles, and the RequirePermission middleware that combines RBAC and license-gate checks in one pass.
authpolicy
Package authpolicy manages the workspace-wide authentication policy: the require-MFA flag and the session idle/absolute timeout windows.
Package authpolicy manages the workspace-wide authentication policy: the require-MFA flag and the session idle/absolute timeout windows.
config
Package config loads OpenWatch runtime configuration.
Package config loads OpenWatch runtime configuration.
connprofile
Package connprofile is the per-host "last known good" SSH connection memory shared by every path that talks to a managed host (the liveness privilege probe, OS discovery, OS intelligence collection, and the compliance scan).
Package connprofile is the per-host "last known good" SSH connection memory shared by every path that talks to a managed host (the liveness privilege probe, OS discovery, OS intelligence collection, and the compliance scan).
correlation
Package correlation propagates a request-scoped correlation ID across HTTP entry, audit emission, log lines, and outbound calls.
Package correlation propagates a request-scoped correlation ID across HTTP entry, audit emission, log lines, and outbound calls.
credential
Package credential owns SSH credential storage and the system→host resolver.
Package credential owns SSH credential storage and the system→host resolver.
cron
Package cron is the minimal Stage-0 cron scheduler.
Package cron is the minimal Stage-0 cron scheduler.
db
Package db owns PostgreSQL connectivity for the openwatch binary.
Package db owns PostgreSQL connectivity for the openwatch binary.
db/dbtest
Package dbtest gives each test BINARY (i.e.
Package dbtest gives each test BINARY (i.e.
db/migrations
Package migrations embeds the SQL migration files and exposes the goose runner that applies them.
Package migrations embeds the SQL migration files and exposes the goose runner that applies them.
dbbackup
Package dbbackup creates a plain-SQL pg_dump of the OpenWatch database, used as the pre-upgrade restore point before migrations run.
Package dbbackup creates a plain-SQL pg_dump of the OpenWatch database, used as the pre-upgrade restore point before migrations run.
drift
Package drift implements OpenWatch's compliance drift detector.
Package drift implements OpenWatch's compliance drift detector.
eventbus
Package eventbus implements OpenWatch's in-process typed pub/sub.
Package eventbus implements OpenWatch's in-process typed pub/sub.
exception
Background expiry sweep, wired in serve.
Background expiry sweep, wired in serve.
fleetrollup
Package fleetrollup answers "how is my fleet doing right now?" via read-only aggregations over the Slice B persistence layer (host_rule_state, transactions, host_liveness).
Package fleetrollup answers "how is my fleet doing right now?" via read-only aggregations over the Slice B persistence layer (host_rule_state, transactions, host_liveness).
framework
Package framework groups the corpus's per-rule framework reference keys (host_rule_state.framework_refs) into user-facing FAMILIES and lists them for the "default compliance lens" picker.
Package framework groups the corpus's per-rule framework reference keys (host_rule_state.framework_refs) into user-facing FAMILIES and lists them for the "default compliance lens" picker.
group
Package group implements host groups: operator-curated SITES (manual membership) and OS CATEGORIES (auto membership derived from hosts.os_family, or manual workload groups).
Package group implements host groups: operator-curated SITES (manual membership) and OS CATEGORIES (auto membership derived from hosts.os_family, or manual workload groups).
host
Package host owns the hosts table — the inventory of machines the platform can talk to.
Package host owns the hosts table — the inventory of machines the platform can talk to.
httpclient
Package httpclient is the outbound HTTP wrapper that forwards the correlation ID from request context as X-Correlation-Id on every call.
Package httpclient is the outbound HTTP wrapper that forwards the correlation ID from request context as X-Correlation-Id on every call.
idempotency
Package idempotency provides the middleware that makes mutating HTTP requests safely retryable.
Package idempotency provides the middleware that makes mutating HTTP requests safely retryable.
identity
Package identity owns the auth primitives: password hashing (Argon2id), NIST SP 800-63B password-policy validation, breach-corpus checking, session token lifecycle, RS256 JWT mint/verify, and TOTP MFA.
Package identity owns the auth primitives: password hashing (Argon2id), NIST SP 800-63B password-policy validation, breach-corpus checking, session token lifecycle, RS256 JWT mint/verify, and TOTP MFA.
intelligence/collector
Package collector implements OS Intelligence — the recurring, write-on-change counterpart to OS Discovery.
Package collector implements OS Intelligence — the recurring, write-on-change counterpart to OS Discovery.
intelligence/discovery
Package discovery owns the one-shot SSH OS-fingerprint flow that captures os_family, os_version, kernel, architecture, hostname / FQDN, SELinux + AppArmor + firewall posture, and a hardware summary for each host on first contact + on-demand.
Package discovery owns the one-shot SSH OS-fingerprint flow that captures os_family, os_version, kernel, architecture, hostname / FQDN, SELinux + AppArmor + firewall posture, and a hardware summary for each host on first contact + on-demand.
intelligence/discovery/scheduler
Package scheduler is the recurring driver for OS discovery — the loop that finds hosts whose hosts.os_discovered_at column is stale (NULL or older than the policy interval) and enqueues host.discovery jobs through internal/queue so the worker pool picks them up and runs discovery.Service.Discover on them.
Package scheduler is the recurring driver for OS discovery — the loop that finds hosts whose hosts.os_discovered_at column is stale (NULL or older than the policy interval) and enqueues host.discovery jobs through internal/queue so the worker pool picks them up and runs discovery.Service.Discover on them.
intelligence/probe
Package probe holds pure parsers for the OS-fingerprint commands the Discovery service runs over SSH.
Package probe holds pure parsers for the OS-fingerprint commands the Discovery service runs over SSH.
intelligence/scheduler
Package scheduler is the recurring driver for OS Intelligence collection — the cron-like loop that turns the one-shot collector.Service.RunCycle into a continuous per-host cadence.
Package scheduler is the recurring driver for OS Intelligence collection — the cron-like loop that turns the one-shot collector.Service.RunCycle into a continuous per-host cadence.
internalrace
Package internalrace exposes a single helper for adjusting performance budgets when the race detector is on.
Package internalrace exposes a single helper for adjusting performance budgets when the race detector is on.
kensa
RuleCatalog — in-memory kensa rule id -> {title, category, severity} lookup for read-path endpoints (the failed-rules listing resolves titles through it).
RuleCatalog — in-memory kensa rule id -> {title, category, severity} lookup for read-path endpoints (the failed-rules listing resolves titles through it).
knownhosts
Package knownhosts is a PostgreSQL-backed ssh.KnownHostsStore.
Package knownhosts is a PostgreSQL-backed ssh.KnownHostsStore.
license
Package license owns license file loading, JWT validation, atomic state for hot-path IsEnabled checks, the RequireFeature HTTP middleware, and the license.* audit emissions.
Package license owns license file loading, JWT validation, atomic state for hot-path IsEnabled checks, the RequireFeature HTTP middleware, and the license.* audit emissions.
liveness
Package liveness implements OpenWatch's periodic host reachability probe loop.
Package liveness implements OpenWatch's periodic host reachability probe loop.
log
Package log provides the slog handler that automatically tags every log record with the correlation_id from context.
Package log provides the slog handler that automatically tags every log record with the correlation_id from context.
notification
Package notification manages operator-configured alert-delivery channels (Slack, generic webhook).
Package notification manages operator-configured alert-delivery channels (Slack, generic webhook).
notifyfeed
Package notifyfeed is the durable, per-user in-app notification feed — the data layer behind the bell.
Package notifyfeed is the durable, per-user in-app notification feed — the data layer behind the bell.
perftest
Package perftest gates latency-budget assertions behind an explicit opt-in.
Package perftest gates latency-budget assertions behind an explicit opt-in.
policy
Package policy is the Stage-0 policies-as-data framework.
Package policy is the Stage-0 policies-as-data framework.
posture
Package posture maintains daily per-host compliance posture snapshots and serves the trend reads built on them.
Package posture maintains daily per-host compliance posture snapshots and serves the trend reads built on them.
queue
Package queue is the PostgreSQL-native async job queue.
Package queue is the PostgreSQL-native async job queue.
remediation
Remediation execution lifecycle (Phase 7, Tier A free-core).
Remediation execution lifecycle (Phase 7, Tier A free-core).
report
Package report implements the Reports library: point-in-time, immutable, Ed25519-signed compliance artifacts.
Package report implements the Reports library: point-in-time, immutable, Ed25519-signed compliance artifacts.
reportschedule
Package reportschedule recurs report generation on a daily/weekly/monthly cadence and delivers the rendered PDF by email.
Package reportschedule recurs report generation on a daily/weekly/monthly cadence and delivers the rendered PDF by email.
scanresult
Package scanresult persists and reads durable, point-in-time per-scan compliance results plus content-addressed evidence.
Package scanresult persists and reads durable, point-in-time per-scan compliance results plus content-addressed evidence.
scanruns
Package scanruns owns the scan_runs table — the operational record ("logbook") of compliance-scan attempts.
Package scanruns owns the scan_runs table — the operational record ("logbook") of compliance-scan attempts.
scheduler
Package scheduler implements the adaptive compliance scan scheduler.
Package scheduler implements the adaptive compliance scan scheduler.
secretkey
Package secretkey owns the AES-256-GCM data encryption key (DEK) used to encrypt at-rest secrets.
Package secretkey owns the AES-256-GCM data encryption key (DEK) used to encrypt at-rest secrets.
server
Per-host failing-rule listing — GET /hosts/{id}/compliance/failed-rules.
Per-host failing-rule listing — GET /hosts/{id}/compliance/failed-rules.
server/api
Package api provides primitives to interact with the openapi HTTP API.
Package api provides primitives to interact with the openapi HTTP API.
ssh
Package ssh is the OpenWatch SSH dial layer.
Package ssh is the OpenWatch SSH dial layer.
sshprivilege
Package sshprivilege implements liveness.PrivilegeProbeFunc: dial SSH with the host's resolved credential, run `sudo -n true`, and report whether passwordless privilege escalation is configured.
Package sshprivilege implements liveness.PrivilegeProbeFunc: dial SSH with the host's resolved credential, run `sudo -n true`, and report whether passwordless privilege escalation is configured.
sso
Package sso implements single sign-on via OpenID Connect: admin-managed providers (config plane) and the authorization-code sign-in flow (runtime plane).
Package sso implements single sign-on via OpenID Connect: admin-managed providers (config plane) and the authorization-code sign-in flow (runtime plane).
systemconfig
Package systemconfig is the runtime config store.
Package systemconfig is the runtime config store.
transactionlog
Package transactionlog implements OpenWatch's compliance write-on-change persistence layer.
Package transactionlog implements OpenWatch's compliance write-on-change persistence layer.
userpref
Package userpref owns per-user UI preferences, stored as the JSONB users.preferences column (migration 0040).
Package userpref owns per-user UI preferences, stored as the JSONB users.preferences column (migration 0040).
users
Package users owns the users + user_roles tables.
Package users owns the users + user_roles tables.
version
Package version exposes build-time metadata for the openwatch binary.
Package version exposes build-time metadata for the openwatch binary.
worker
JSONB payload + HMAC signing for remediation jobs.
JSONB payload + HMAC signing for remediation jobs.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL