validate

package
v0.2.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 13, 2026 License: MIT Imports: 2 Imported by: 0

Documentation

Overview

Package validate applies profile-conditional rules to a sas.Architecture. A profile declares which optional semantics in the core graph become mandatory for a given use case (development, deployment, security, threat-model, sre); the core schema itself never branches on profile.

This package is a consumer of the sas package's semantic model, not part of it: which rules exist and what they require is a use-case requirement layered on top of the graph, not a fact about the graph itself.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Finding

type Finding struct {
	// RuleID identifies the rule that produced this finding, e.g.
	// "core.relationship-endpoints-resolve".
	RuleID string `json:"ruleId"`

	// Severity classifies how serious this finding is.
	Severity Severity `json:"severity"`

	// Profile names which profile required this check. Empty means the
	// rule is always-on (core referential integrity), independent of any
	// requested profile.
	Profile Profile `json:"profile,omitempty"`

	// Message is a human-readable explanation.
	Message string `json:"message"`

	// Path locates the offending element, e.g. "nodes[2]" or
	// "relationships[0]".
	Path string `json:"path"`
}

Finding is a single validation result: something Validate checked, where it applies, and whether it passed. Only failures are returned by Validate — a clean run produces an empty slice.

func Validate

func Validate(arch *sas.Architecture, profiles ...Profile) []Finding

Validate checks arch against the always-on referential-integrity rules plus the rules for every requested profile, and returns every finding. A clean architecture returns an empty (non-nil-length-zero) slice. Unrecognized profiles are ignored by the check dispatch below but reported as findings themselves, so a typo'd profile name is visible rather than silently a no-op.

type Profile

type Profile string

Profile names a use case that requires additional semantics beyond the core graph shape. Requesting a profile does not change what an Architecture document is allowed to contain — the schema is the same for every profile — it changes which optional fields become mandatory for Validate to consider the document conformant.

const (
	// ProfileDevelopment is the base profile: nodes and relationships
	// only. It adds no rules beyond the always-on referential-integrity
	// checks — a minimal architecture file is already conformant to it.
	ProfileDevelopment Profile = "development"

	// ProfileDeployment requires deployment-relevant facts: node
	// technology, membership in an account/region/network boundary, and
	// relationship transport.
	ProfileDeployment Profile = "deployment"

	// ProfileSecurity requires identity and encryption on boundary
	// crossings, entitlements on relationships that write, and — for
	// internet-facing relationships (traffic entering the architecture
	// from a human actor or an external system, not the architecture
	// calling out) — TLS, identity, data classification, and an owner on
	// the target node. This is the go-live gate: `sas validate --profile
	// security` is meant to be the single command a launch checklist
	// runs before a portfolio web app ships to production.
	ProfileSecurity Profile = "security"

	// ProfileThreatModel requires data classifications on relationships
	// touching a node outside every boundary the source node belongs to
	// (an external dependency), so a threat model always knows what data
	// leaves a trust zone.
	ProfileThreatModel Profile = "threat-model"

	// ProfileSRE requires owner, an SRE extension with an availability
	// target, and assurance metrics on tier0/tier1 nodes.
	ProfileSRE Profile = "sre"
)

func KnownProfiles

func KnownProfiles() []Profile

KnownProfiles lists every profile Validate recognizes, in a stable order suitable for CLI help text and error messages.

func (Profile) IsKnown

func (p Profile) IsKnown() bool

IsKnown reports whether p is one of KnownProfiles.

type Severity

type Severity string

Severity classifies how serious a Finding is.

const (
	SeverityError   Severity = "error"
	SeverityWarning Severity = "warning"
)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL