Documentation
¶
Overview ¶
Package safety keeps Stampede from being pointed at systems the user does not own: target classification, ownership verification, load caps and a per-request host policy.
Index ¶
- Constants
- Variables
- func CheckPlan(p *scenario.Plan, c Caps) error
- func InstallSecret() ([]byte, error)
- func IsPrivateAddr(a netip.Addr) bool
- func IsPrivateHost(ctx context.Context, host string) (bool, error)
- func Token(secret []byte, host string) string
- func Verify(ctx context.Context, base *url.URL, token string) (string, error)
- type Caps
- type HostPolicy
Constants ¶
const TXTPrefix = "stampede-verify="
TXTPrefix starts the DNS TXT verification record.
const WellKnownPath = "/.well-known/stampede-verify.txt"
WellKnownPath is where a verification token can be served.
Variables ¶
var UnverifiedPublicCaps = Caps{MaxRate: 50, MaxVUs: 50, MaxDuration: 10 * time.Minute}
UnverifiedPublicCaps apply to public targets whose ownership has not been verified.
Functions ¶
func InstallSecret ¶
InstallSecret returns this machine's verification secret, creating it on first use under the user config directory.
func IsPrivateAddr ¶
IsPrivateAddr reports whether an address is loopback, private, link-local or unique-local.
func IsPrivateHost ¶
IsPrivateHost resolves host and reports whether every address it maps to is private. "localhost" and names under .localhost, .local, .internal and .test count as private without a lookup only if they resolve privately.
Types ¶
type Caps ¶
type Caps struct {
MaxRate float64 // iterations per second (rate mode)
MaxVUs int // virtual users
MaxDuration time.Duration // planned load duration
}
Caps bound the load a run may generate.
type HostPolicy ¶
type HostPolicy struct {
// contains filtered or unexported fields
}
HostPolicy decides which hosts requests may reach. The target host and private hosts are allowed; any other public host must be listed explicitly. This stops a scenario from sending load to third parties.
func NewHostPolicy ¶
func NewHostPolicy(targetHost string, extra []string) *HostPolicy
NewHostPolicy allows the target host plus extra hosts.