Compare commits

..
Author SHA1 Message Date
dependabot[bot]andGitHub 8f73489578 chore(deps): bump cryptography from 48.0.0 to 48.0.1 in /detmir-mcp
CI / Rust checks (push) Canceled after 0s
CI / Docs and registry checks (push) Canceled after 0s
CI / Smoke checks (push) Canceled after 0s
Coverage / Coverage baseline (push) Canceled after 0s
Security / Cargo audit (push) Canceled after 0s
Security / Cargo deny (push) Canceled after 0s
Security / Secret pattern check (push) Canceled after 0s
Security / Dependency review (push) Canceled after 0s
Bumps [cryptography](https://github.com/pyca/cryptography) from 48.0.0 to 48.0.1.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pyca/cryptography/compare/48.0.0...48.0.1)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 48.0.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-01 13:35:49 +00:00
33 changed files with 282 additions and 3075 deletions
+7 -3
View File
@@ -122,9 +122,9 @@ dependencies = [
[[package]]
name = "anyhow"
version = "1.0.103"
version = "1.0.102"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "2a4385e2e34eb35d6b3efe798b9eb88096925d87726c0798709bf56d9ed84af3"
checksum = "7f202df86484c868dbad7eaa557ef785d5c66295e41b460ef922eca0723b842c"
[[package]]
name = "arbitrary"
@@ -198,10 +198,12 @@ name = "aw-contour-smoke"
version = "0.1.0"
dependencies = [
"anyhow",
"chrono",
"clap",
"reqwest",
"serde_json",
"tempfile",
"url",
]
[[package]]
@@ -737,7 +739,6 @@ dependencies = [
"sha2",
"tempfile",
"tiny_http",
"url",
]
[[package]]
@@ -775,6 +776,7 @@ dependencies = [
"anyhow",
"clap",
"detmir-state",
"serde",
"serde_json",
]
@@ -1254,6 +1256,7 @@ dependencies = [
"serde",
"serde_json",
"tempfile",
"urlencoding",
]
[[package]]
@@ -3289,6 +3292,7 @@ dependencies = [
"tempfile",
"tiny_http",
"url",
"urlencoding",
]
[[package]]
@@ -8,9 +8,11 @@ publish.workspace = true
[dependencies]
anyhow.workspace = true
chrono.workspace = true
clap.workspace = true
reqwest.workspace = true
serde_json.workspace = true
url.workspace = true
[dev-dependencies]
tempfile.workspace = true
+8 -78
View File
@@ -6,7 +6,7 @@ use std::path::{Path, PathBuf};
use std::process::{Command, Stdio};
use std::time::{Duration, Instant};
use anyhow::{Context, Result, anyhow};
use anyhow::{Context, Result};
use chrono::{DateTime, Duration as ChronoDuration, SecondsFormat, Utc};
use clap::Parser;
use detmir_core::{exit_codes, parse_utc_rfc3339};
@@ -25,10 +25,10 @@ struct Cli {
#[arg(long, default_value = "http://127.0.0.1:5610")]
worktime_api: String,
#[arg(long, default_value = "")]
#[arg(long, default_value = "198.51.100.18")]
rdp_host: String,
#[arg(long, default_value = "")]
#[arg(long, default_value = "HOST-EXAMPLE")]
rdp_hostname: String,
#[arg(long, default_value = "/var/lib/activitywatch/health")]
@@ -61,9 +61,6 @@ struct Cli {
#[arg(long, default_value_t = 3.0)]
tcp_timeout_seconds: f64,
#[arg(long, default_value_t = true)]
rdp_tcp_required: bool,
#[arg(long)]
json: bool,
}
@@ -132,10 +129,6 @@ impl Cli {
self.tcp_timeout_seconds,
);
}
if !cli_arg_present("--rdp-tcp-required") {
self.rdp_tcp_required =
env_bool_default("AW_RUS_HEALTH_RDP_TCP_REQUIRED", self.rdp_tcp_required);
}
self
}
}
@@ -228,42 +221,9 @@ fn env_f64(name: &str, fallback: f64) -> f64 {
}
fn env_bool(name: &str) -> bool {
env_bool_default(name, false)
}
fn env_bool_default(name: &str, fallback: bool) -> bool {
env_string(name)
.map(|value| match value.to_ascii_lowercase().as_str() {
"1" | "true" | "yes" | "on" => true,
"0" | "false" | "no" | "off" => false,
_ => fallback,
})
.unwrap_or(fallback)
}
fn validate_cli_config(cli: &Cli) -> Result<()> {
validate_prod_host("rdp_host", &cli.rdp_host)?;
validate_prod_host("rdp_hostname", &cli.rdp_hostname)?;
Ok(())
}
fn validate_prod_host(name: &str, value: &str) -> Result<()> {
let value = value.trim();
if value.is_empty() {
return Err(anyhow!("invalid config {name}: value is empty"));
}
let lowered = value.to_ascii_lowercase();
if lowered == "host-example"
|| lowered.ends_with(".example")
|| lowered.starts_with("192.0.2.")
|| lowered.starts_with("198.51.100.")
|| lowered.starts_with("203.0.113.")
{
return Err(anyhow!(
"invalid config {name}: placeholder/documentation host is not allowed"
));
}
Ok(())
.map(|value| matches!(value.to_ascii_lowercase().as_str(), "1" | "true" | "yes"))
.unwrap_or(false)
}
fn load_env_file(path: &Path) {
@@ -721,16 +681,6 @@ fn normalize_aw_api_base(aw_server: &str) -> String {
}
}
fn tcp_check_status(ok: bool, required: bool) -> &'static str {
if ok {
"ok"
} else if required {
"fail"
} else {
"warn"
}
}
fn validation_check(report: &mut ReportBuilder, validation_dir: &Path, max_age_seconds: i64) {
let Some(path) = latest_validation_report(validation_dir) else {
report.add(
@@ -862,18 +812,15 @@ fn run(cli: &Cli) -> Result<HealthReport> {
for (port, label) in [(5985_u16, "winrm"), (3389_u16, "rdp")] {
let (ok, message) = tcp_connect(&cli.rdp_host, port, cli.tcp_timeout_seconds);
let status = tcp_check_status(ok, cli.rdp_tcp_required);
report.add(
format!("tcp:{label}"),
status,
if ok { "ok" } else { "fail" },
if ok {
message
} else if cli.rdp_tcp_required {
format!("unreachable: {message}")
} else {
format!("optional unreachable: {message}")
format!("unreachable: {message}")
},
json!({"host": cli.rdp_host, "port": port, "required": cli.rdp_tcp_required}),
json!({"host": cli.rdp_host, "port": port}),
);
}
@@ -1002,7 +949,6 @@ fn run(cli: &Cli) -> Result<HealthReport> {
fn main() -> Result<()> {
let cli = Cli::parse().apply_env();
validate_cli_config(&cli)?;
let report = run(&cli)?;
let json_text = serde_json::to_string_pretty(&report)? + "\n";
let text = render_text(&report) + "\n";
@@ -1083,20 +1029,4 @@ mod tests {
"http://127.0.0.1:5600/api/0"
);
}
#[test]
fn optional_rdp_tcp_downgrades_unreachable_to_warn() {
assert_eq!(tcp_check_status(false, true), "fail");
assert_eq!(tcp_check_status(false, false), "warn");
assert_eq!(tcp_check_status(true, false), "ok");
}
#[test]
fn healthd_rejects_placeholder_hosts() {
assert!(validate_prod_host("rdp_host", "192.168.100.19").is_ok());
assert!(validate_prod_host("rdp_hostname", "SHARKON2025").is_ok());
assert!(validate_prod_host("rdp_host", "198.51.100.18").is_err());
assert!(validate_prod_host("rdp_hostname", "HOST-EXAMPLE").is_err());
assert!(validate_prod_host("rdp_host", "").is_err());
}
}
-1
View File
@@ -18,7 +18,6 @@ serde_json.workspace = true
serde_yaml.workspace = true
sha2.workspace = true
tiny_http.workspace = true
url.workspace = true
[dev-dependencies]
tempfile.workspace = true
File diff suppressed because it is too large Load Diff
@@ -11,7 +11,6 @@ use anyhow::{Result, anyhow};
use chrono::NaiveDate;
use serde_json::{Value, json};
use tiny_http::StatusCode;
use url::Url;
use crate::{
Cli, MAX_ALLOWED_PAGE_SIZE, MAX_ALLOWED_REPORT_DATE_RANGE_DAYS, MAX_ALLOWED_REQUEST_BODY_BYTES,
@@ -78,11 +77,6 @@ pub(crate) fn validate_portal_config(args: &Cli) -> Result<()> {
"invalid config max_request_body_bytes: expected 1024..={MAX_ALLOWED_REQUEST_BODY_BYTES}"
));
}
validate_runtime_url("worktime_url", &args.worktime_url)?;
validate_runtime_url("one_c_url", &args.one_c_url)?;
validate_probe_command("status_cmd", &args.status_cmd)?;
validate_probe_command("check_cmd", &args.check_cmd)?;
validate_probe_command("failed_units_cmd", &args.failed_units_cmd)?;
// SECURITY: environment and module names can reach metrics/log labels.
// Restrict them to short ASCII tokens to avoid label injection and runaway
@@ -118,46 +112,6 @@ pub(crate) fn validate_portal_config(args: &Cli) -> Result<()> {
Ok(())
}
fn validate_runtime_url(name: &str, value: &str) -> Result<()> {
let url = Url::parse(value).map_err(|err| anyhow!("invalid config {name}: {err}"))?;
if !matches!(url.scheme(), "http" | "https") {
return Err(anyhow!("invalid config {name}: expected http or https URL"));
}
let Some(host) = url.host_str() else {
return Err(anyhow!("invalid config {name}: missing host"));
};
if is_placeholder_host(host) {
return Err(anyhow!(
"invalid config {name}: placeholder/documentation host is not allowed in production"
));
}
Ok(())
}
fn is_placeholder_host(host: &str) -> bool {
let host = host.trim().to_ascii_lowercase();
host.is_empty()
|| host == "host-example"
|| host.ends_with(".example")
|| host.starts_with("192.0.2.")
|| host.starts_with("198.51.100.")
|| host.starts_with("203.0.113.")
}
fn validate_probe_command(name: &str, command: &str) -> Result<()> {
let command = command.trim();
if command.is_empty() {
return Err(anyhow!("invalid config {name}: command is empty"));
}
let forbidden = ['\n', '\r', '\0', ';', '|', '&', '<', '>', '`'];
if command.contains("$(") || command.chars().any(|ch| forbidden.contains(&ch)) {
return Err(anyhow!(
"invalid config {name}: shell control operators are not allowed"
));
}
Ok(())
}
fn is_safe_environment_name(value: &str) -> bool {
let value = value.trim();
!value.is_empty()
@@ -276,7 +230,6 @@ mod tests {
slow_request_log_ms: DEFAULT_SLOW_REQUEST_LOG_MS,
environment: "test".to_string(),
enabled_modules: "executive,workforce,security,forensics,admin".to_string(),
dlp_module_enabled: true,
state_dir: dir.join("state"),
dlp_db_path: dir.join("dlp.sqlite"),
evidence_root: dir.to_path_buf(),
@@ -340,39 +293,6 @@ mod tests {
);
}
#[test]
fn config_validation_rejects_placeholder_endpoints_and_shell_operators() {
let dir = tempfile::tempdir().unwrap();
let args = test_cli(dir.path());
let mut invalid = args.clone();
invalid.worktime_url = "http://192.0.2.13:5610".to_string();
assert!(
validate_portal_config(&invalid)
.unwrap_err()
.to_string()
.contains("placeholder")
);
let mut invalid = args.clone();
invalid.one_c_url = "http://198.51.100.2:8710".to_string();
assert!(
validate_portal_config(&invalid)
.unwrap_err()
.to_string()
.contains("placeholder")
);
let mut invalid = args.clone();
invalid.check_cmd = "detmir-check --json; curl http://127.0.0.1".to_string();
assert!(
validate_portal_config(&invalid)
.unwrap_err()
.to_string()
.contains("shell control")
);
}
#[test]
fn query_limits_reject_page_size_and_report_range() {
let dir = tempfile::tempdir().unwrap();
@@ -34,10 +34,6 @@ struct HttpMetricValue {
#[derive(Clone, Debug, Default)]
struct PortalMetrics {
http: BTreeMap<HttpMetricKey, HttpMetricValue>,
report_requests_total: u64,
report_cache_hits_total: u64,
report_cache_misses_total: u64,
report_cache_stale_hits_total: u64,
reports_generated_total: u64,
ingestion_records_total: u64,
ingestion_rejected_total: u64,
@@ -74,32 +70,6 @@ pub(crate) fn record_report_generated() {
}
}
pub(crate) fn record_report_request() {
if let Ok(mut metrics) = portal_metrics().lock() {
metrics.report_requests_total = metrics.report_requests_total.saturating_add(1);
}
}
pub(crate) fn record_report_cache_hit() {
if let Ok(mut metrics) = portal_metrics().lock() {
metrics.report_cache_hits_total = metrics.report_cache_hits_total.saturating_add(1);
}
}
pub(crate) fn record_report_cache_stale_hit() {
if let Ok(mut metrics) = portal_metrics().lock() {
metrics.report_cache_hits_total = metrics.report_cache_hits_total.saturating_add(1);
metrics.report_cache_stale_hits_total =
metrics.report_cache_stale_hits_total.saturating_add(1);
}
}
pub(crate) fn record_report_cache_miss() {
if let Ok(mut metrics) = portal_metrics().lock() {
metrics.report_cache_misses_total = metrics.report_cache_misses_total.saturating_add(1);
}
}
pub(crate) fn record_ingestion_accepted() {
if let Ok(mut metrics) = portal_metrics().lock() {
metrics.ingestion_records_total = metrics.ingestion_records_total.saturating_add(1);
@@ -179,26 +149,6 @@ pub(crate) fn render_prometheus_metrics(args: &Cli) -> String {
.ok();
}
for (name, help, value) in [
(
"awatch_report_requests_total",
"Report payload requests handled by the portal cache layer",
metrics.report_requests_total,
),
(
"awatch_report_cache_hits_total",
"Report payload requests served from the in-process cache",
metrics.report_cache_hits_total,
),
(
"awatch_report_cache_misses_total",
"Report payload requests that triggered report regeneration",
metrics.report_cache_misses_total,
),
(
"awatch_report_cache_stale_hits_total",
"Report payload requests served from stale cache while refresh runs",
metrics.report_cache_stale_hits_total,
),
(
"awatch_reports_generated_total",
"Reports generated by the portal",
@@ -22,8 +22,7 @@ pub(crate) use limits::{is_limited_api_route, validate_api_query_limits, validat
pub(crate) use logging::log_http_request;
pub(crate) use metrics::{
record_http_metric, record_ingestion_accepted, record_ingestion_rejected,
record_report_cache_hit, record_report_cache_miss, record_report_cache_stale_hit,
record_report_generated, record_report_request, render_prometheus_metrics,
record_report_generated, render_prometheus_metrics,
};
pub(crate) use readiness::build_readyz;
pub(crate) use request_context::{http_request_metadata, mark_request_started};
@@ -6,20 +6,13 @@
use std::collections::BTreeMap;
use std::sync::{Arc, Mutex};
use std::thread;
use std::time::{Duration, Instant};
use crate::{Cli, HealthResponse, Snapshot, build_health, build_snapshot, now};
const SNAPSHOT_CACHE_TTL: Duration = Duration::from_secs(120);
pub(crate) type SnapshotCache = Arc<Mutex<SnapshotCacheState>>;
#[derive(Clone, Debug, Default)]
pub(crate) struct SnapshotCacheState {
pub(crate) entry: Option<CachedSnapshot>,
pub(crate) refresh_in_progress: bool,
}
pub(crate) type SnapshotCache = Arc<Mutex<Option<CachedSnapshot>>>;
#[derive(Clone, Debug)]
pub(crate) struct CachedSnapshot {
@@ -28,7 +21,7 @@ pub(crate) struct CachedSnapshot {
}
pub(crate) fn new_snapshot_cache() -> SnapshotCache {
Arc::new(Mutex::new(SnapshotCacheState::default()))
Arc::new(Mutex::new(None))
}
pub(crate) fn clone_snapshot_cache(cache: &SnapshotCache) -> SnapshotCache {
@@ -36,76 +29,23 @@ pub(crate) fn clone_snapshot_cache(cache: &SnapshotCache) -> SnapshotCache {
}
pub(crate) fn cached_snapshot(args: &Cli, cache: &SnapshotCache) -> Snapshot {
{
let guard = cache.lock().expect("snapshot cache mutex poisoned");
if let Some(cached) = guard.entry.as_ref() {
if cached.created.elapsed() <= SNAPSHOT_CACHE_TTL {
return cached.snapshot.clone();
}
let mut guard = cache.lock().expect("snapshot cache mutex poisoned");
if let Some(cached) = guard.as_ref() {
if cached.created.elapsed() <= SNAPSHOT_CACHE_TTL {
return cached.snapshot.clone();
}
}
let snapshot = build_snapshot(args);
let mut guard = cache.lock().expect("snapshot cache mutex poisoned");
guard.entry = Some(CachedSnapshot {
*guard = Some(CachedSnapshot {
created: Instant::now(),
snapshot: snapshot.clone(),
});
guard.refresh_in_progress = false;
snapshot
}
pub(crate) fn cached_snapshot_or_refresh(args: &Cli, cache: &SnapshotCache) -> Option<Snapshot> {
let mut should_spawn = false;
let mut snapshot_to_return = None;
{
let mut guard = cache.lock().expect("snapshot cache mutex poisoned");
if let Some(cached) = guard.entry.as_ref() {
let snapshot = cached.snapshot.clone();
if cached.created.elapsed() <= SNAPSHOT_CACHE_TTL {
return Some(snapshot);
}
if !guard.refresh_in_progress {
guard.refresh_in_progress = true;
should_spawn = true;
}
snapshot_to_return = Some(snapshot);
} else if !guard.refresh_in_progress {
guard.refresh_in_progress = true;
should_spawn = true;
}
}
if should_spawn {
spawn_snapshot_refresh(args.clone(), clone_snapshot_cache(cache));
}
snapshot_to_return
}
fn spawn_snapshot_refresh(args: Cli, cache: SnapshotCache) {
thread::spawn(move || {
let result =
std::panic::catch_unwind(std::panic::AssertUnwindSafe(|| build_snapshot(&args)));
let mut guard = cache.lock().expect("snapshot cache mutex poisoned");
match result {
Ok(snapshot) => {
guard.entry = Some(CachedSnapshot {
created: Instant::now(),
snapshot,
});
}
Err(_) => {
eprintln!("detmir-portal snapshot cache refresh panicked");
}
}
guard.refresh_in_progress = false;
});
}
pub(crate) fn build_fast_health(cache: &SnapshotCache) -> HealthResponse {
match cache.try_lock() {
Ok(guard) => guard
.entry
.as_ref()
.map(|cached| build_health(&cached.snapshot))
.unwrap_or_else(lightweight_health),
@@ -549,7 +549,6 @@ mod tests {
};
Snapshot {
generated_at_utc: "2026-06-07T10:00:00Z".to_string(),
dlp_module_enabled: true,
detmir_status: SourceStatus {
ok: true,
status: "OK".to_string(),
+6 -47
View File
@@ -18,9 +18,7 @@ const DEFAULT_AW_ENV_FILE: &str = "/etc/activitywatch/aw-server.env";
const DEFAULT_GRAFANA_ENV_FILE: &str = "/etc/detmir-grafana-check.env";
const DEFAULT_GRAFANA_URL: &str = "http://127.0.0.1:3000";
const DEFAULT_GRAFANA_DATASOURCE_UID: &str = "influxdb_aw";
const DEFAULT_SYSTEMD_SERVICES: &str =
"activitywatch-server,aw-worktime-api,aw-worktime-influx-exporter.timer";
const DEFAULT_DLP_SYSTEMD_SERVICES: &str = "aw-dlp-influx-exporter.timer";
const DEFAULT_SYSTEMD_SERVICES: &str = "activitywatch-server,aw-worktime-api,aw-worktime-influx-exporter.timer,aw-dlp-influx-exporter.timer";
const DEFAULT_RETENTION_DAYS: i64 = 30;
#[derive(Debug, Parser)]
@@ -220,26 +218,14 @@ fn run(cli: &Cli) -> Result<Report> {
let mut checks = Vec::new();
let worktime = influx_config(&aw_env, "AW_WORKTIME_INFLUX");
let dlp = influx_config(&aw_env, "AW_DLP_INFLUX");
let dlp_enabled = env_bool(&aw_env, "AW_DLP_ENABLED", true);
checks.push(check_influx_env(&worktime, cli.allow_disabled_influx));
if dlp_enabled {
checks.push(check_influx_env(&dlp, cli.allow_disabled_influx));
} else {
checks.push(warn(
"env:AW_DLP_INFLUX",
"DLP Influx runtime disabled by AW_DLP_ENABLED=false",
json!({"enabled": false, "mode": "disabled"}),
));
}
checks.push(check_influx_env(&dlp, cli.allow_disabled_influx));
if cli.skip_systemd {
checks.push(warn("systemd", "systemd checks skipped", json!({})));
} else {
checks.extend(check_systemd_services(&systemd_services_for_mode(
&cli.systemd_services,
dlp_enabled,
)));
checks.extend(check_systemd_services(&cli.systemd_services));
}
if cli.skip_influx_write {
@@ -250,15 +236,7 @@ fn run(cli: &Cli) -> Result<Report> {
));
} else {
checks.push(check_influx_write(&client, "worktime", &worktime));
if dlp_enabled {
checks.push(check_influx_write(&client, "dlp", &dlp));
} else {
checks.push(warn(
"influx:write:dlp",
"DLP write probe skipped because DLP is disabled",
json!({"enabled": false, "mode": "disabled"}),
));
}
checks.push(check_influx_write(&client, "dlp", &dlp));
}
if cli.skip_grafana {
@@ -292,7 +270,7 @@ fn run(cli: &Cli) -> Result<Report> {
git_commit: cli.git_commit.clone(),
counts,
checks,
limitations: build_limitations(cli, dlp_enabled),
limitations: build_limitations(cli),
})
}
@@ -360,20 +338,6 @@ fn split_csv(value: &str) -> Vec<String> {
.collect()
}
fn systemd_services_for_mode(csv: &str, dlp_enabled: bool) -> String {
let mut services = split_csv(csv);
if dlp_enabled {
for service in split_csv(DEFAULT_DLP_SYSTEMD_SERVICES) {
if !services.iter().any(|item| item == &service) {
services.push(service);
}
}
} else {
services.retain(|service| !service.contains("dlp"));
}
services.into_iter().collect::<Vec<_>>().join(",")
}
fn hostname() -> String {
Command::new("hostname")
.output()
@@ -384,7 +348,7 @@ fn hostname() -> String {
.unwrap_or_else(|| "unknown".to_string())
}
fn build_limitations(cli: &Cli, dlp_enabled: bool) -> Vec<String> {
fn build_limitations(cli: &Cli) -> Vec<String> {
let mut limitations = Vec::new();
limitations.push(
"Проверка подтверждает состояние runtime на момент формирования акта и не заменяет аудит конфигурации, нагрузочное тестирование или приемочные испытания заказчика.".to_string(),
@@ -413,11 +377,6 @@ fn build_limitations(cli: &Cli, dlp_enabled: bool) -> Vec<String> {
.to_string(),
);
}
if !dlp_enabled {
limitations.push(
"DLP runtime отключен штатно через AW_DLP_ENABLED=false; readiness не считает DLP services/timers и DLP Influx write обязательными.".to_string(),
);
}
limitations
}
+1
View File
@@ -19,4 +19,5 @@ adk-rust.workspace = true
anyhow.workspace = true
clap.workspace = true
detmir-state.workspace = true
serde.workspace = true
serde_json.workspace = true
@@ -31,6 +31,7 @@ regex.workspace = true
reqwest.workspace = true
serde.workspace = true
serde_json.workspace = true
urlencoding.workspace = true
[dev-dependencies]
tempfile.workspace = true
+1
View File
@@ -15,6 +15,7 @@ serde.workspace = true
serde_json.workspace = true
tiny_http.workspace = true
url.workspace = true
urlencoding.workspace = true
regex.workspace = true
[dev-dependencies]
+58 -294
View File
@@ -19,22 +19,6 @@
aw_db_vacuum_timer_enabled: false
tasks:
- name: Refuse inconsistent DLP resource profile
ansible.builtin.assert:
that:
- aw_dlp_profile | default('core_only') in ['core_only', 'light', 'on_demand', 'full']
- (aw_dlp_profile | default('core_only') == 'core_only') or (aw_dlp_enabled | default(false) | bool)
- (aw_dlp_enabled | default(false) | bool) or not (
aw_dlp_influx_enabled | default(false) | bool
or aw_dlp_ioc_enabled | default(false) | bool
or aw_dlp_policy_engine_enabled | default(false) | bool
or aw_dlp_content_analysis_enabled | default(false) | bool
or aw_dlp_integrations_enabled | default(false) | bool
or aw_dlp_case_management_enabled | default(false) | bool
or aw_dlp_compliance_enabled | default(false) | bool
)
fail_msg: "Inconsistent DLP profile: keep aw_dlp_enabled=false with all DLP component flags false, or explicitly choose aw_dlp_enabled=true and aw_dlp_profile=light|on_demand|full."
- name: Установить базовые пакеты
ansible.builtin.apt:
name:
@@ -94,7 +78,6 @@
- "{{ aw_server_data_dir }}/backups"
- "{{ aw_server_data_dir }}/slo"
- "{{ aw_server_data_dir }}/browser-smoke"
- "{{ aw_security_finding_executor_work_dir | default(aw_server_data_dir ~ '/security-finding-executor') }}"
- "{{ aw_rus_health_state_dir }}"
- "{{ aw_rus_health_validation_dir }}"
- "{{ aw_server_log_dir }}"
@@ -125,7 +108,6 @@
- "{{ aw_server_data_dir }}/backups"
- "{{ aw_server_data_dir }}/slo"
- "{{ aw_server_data_dir }}/browser-smoke"
- "{{ aw_security_finding_executor_work_dir | default(aw_server_data_dir ~ '/security-finding-executor') }}"
- "{{ aw_rus_health_state_dir }}"
- "{{ aw_rus_health_validation_dir }}"
- "{{ aw_server_log_dir }}"
@@ -731,9 +713,7 @@
- aw_effective_dlp_influx_token | length > 0
- (aw_effective_dlp_influx_token | string | lower | regex_search('^(change_me|changeme|replace-me|replace_me|token|secret|password|api_key|influx_token|write_token|your_.*|<.*>)$')) is none
fail_msg: "aw_dlp_influx_enabled=true, но token пуст и в локальном env, и в текущем /etc/activitywatch/aw-server.env. Exporter будет падать и Grafana не получит DLP-ряды."
when:
- aw_dlp_enabled | default(false) | bool
- aw_dlp_influx_enabled | default(false) | bool
when: aw_dlp_influx_enabled | default(false) | bool
- name: Проверить destination для AW worktime Influx exporter
ansible.builtin.assert:
@@ -765,9 +745,7 @@
- (aw_dlp_influx_hosts | default('') | string | length) > 0
- "'WINDOWS_USER_EXAMPLE' not in (aw_dlp_influx_hosts | default('') | string)"
fail_msg: "aw_dlp_influx_enabled=true, но URL/org/bucket/hosts похожи на public example/TEST-NET значения. Задайте live значения в private inventory/env, не в public repo."
when:
- aw_dlp_enabled | default(false) | bool
- aw_dlp_influx_enabled | default(false) | bool
when: aw_dlp_influx_enabled | default(false) | bool
- name: Записать /etc/activitywatch/aw-server.env перед хотфиксами
ansible.builtin.copy:
@@ -786,7 +764,7 @@
AW_SERVER_GROUP={{ aw_server_group }}
AW_WORKTIME_REPORT_BASE={{ aw_worktime_report_base }}
AW_WORKTIME_TZ={{ aw_worktime_timezone }}
AW_WORKTIME_HOST={{ aw_effective_worktime_host | default(aw_effective_monitored_windows_hostname | default('HOST-EXAMPLE')) }}
AW_WORKTIME_HOST={{ aw_effective_worktime_host | default(aw_effective_monitored_windows_hostname | default('SHARKON2025')) }}
AW_WORKTIME_EVENTS_LIMIT={{ aw_worktime_events_limit | default(5000) }}
AW_WORKTIME_AW_HTTP_TIMEOUT_SECONDS={{ aw_worktime_aw_http_timeout_seconds | default(6) }}
AW_WORKTIME_EVENTS_CACHE_TTL_SECONDS={{ aw_worktime_events_cache_ttl_seconds | default(300) }}
@@ -809,7 +787,7 @@
AW_WORKTIME_INFLUX_URL={{ aw_worktime_influx_url | default('') }}
AW_WORKTIME_INFLUX_ORG={{ aw_worktime_influx_org | default('proxmox') }}
AW_WORKTIME_INFLUX_BUCKET={{ aw_worktime_influx_bucket | default('aw_metrics') }}
AW_WORKTIME_INFLUX_HOSTS={{ aw_worktime_influx_hosts | default(aw_effective_monitored_windows_hostname | default('HOST-EXAMPLE')) }}
AW_WORKTIME_INFLUX_HOSTS={{ aw_worktime_influx_hosts | default('SHARKON2025') }}
AW_WORKTIME_INFLUX_DAYS={{ aw_worktime_influx_days | default('today,yesterday') }}
AW_WORKTIME_INFLUX_TOKEN={{ aw_effective_worktime_influx_token | default('') }}
AW_WORKTIME_MANAGEMENT_HISTORY_DIR={{ aw_worktime_management_history_dir | default(aw_server_data_dir ~ '/worktime-management-history') }}
@@ -820,28 +798,11 @@
AW_WORKTIME_MANAGER_TREND_DELTA_PCT={{ aw_worktime_manager_trend_delta_pct | default(10) }}
AW_WORKTIME_MANAGER_OFF_HOURS_THRESHOLD_SECONDS={{ aw_worktime_manager_off_hours_threshold_seconds | default(1800) }}
AW_WORKTIME_MANAGER_INTERPRETATION_POLICY={{ aw_worktime_interpretation_policy_path | default('/etc/activitywatch/worktime-interpretation-policy.json') }}
AW_DLP_ENABLED={{ 'true' if (aw_dlp_enabled | default(false) | bool) else 'false' }}
AW_DLP_PROFILE={{ aw_dlp_profile | default('core_only') }}
AW_DLP_DISABLED_REASON={{ aw_dlp_disabled_reason | default('') }}
AW_DLP_DISABLED_SINCE={{ aw_dlp_disabled_since | default('') }}
AW_DLP_GUARD_ENABLED={{ 'true' if (aw_dlp_light_guard_enabled | default(true) | bool) else 'false' }}
AW_DLP_GUARD_STATE_DIR={{ aw_dlp_light_guard_state_dir | default(aw_server_data_dir ~ '/health') }}
AW_DLP_GUARD_LOAD_RATIO={{ aw_dlp_light_guard_load_ratio | default('1.50') }}
AW_DLP_GUARD_MEM_AVAILABLE_PCT_MIN={{ aw_dlp_light_guard_mem_available_pct_min | default('15') }}
AW_DLP_GUARD_IOWAIT_PCT_MAX={{ aw_dlp_light_guard_iowait_pct_max | default('20') }}
AW_DLP_GUARD_STRIKES_REQUIRED={{ aw_dlp_light_guard_strikes_required | default(3) }}
AW_DLP_CONTROL_BIN=/usr/local/bin/detmir-dlp-runtime-control
AW_CONTAINMENT_ENABLED={{ 'true' if (aw_containment_enabled | default(false) | bool) else 'false' }}
AW_CONTAINMENT_MODE={{ aw_containment_mode | default('shadow') }}
AW_CONTAINMENT_POLICY={{ aw_containment_policy_path | default('/etc/activitywatch/containment-policy.json') }}
AW_CONTAINMENT_DEFAULT_TTL_MINUTES={{ aw_containment_default_ttl_minutes | default(60) }}
AW_CONTAINMENT_REQUIRE_ADMIN_CHANNEL_CHECK={{ 'true' if (aw_containment_require_admin_channel_check | default(true) | bool) else 'false' }}
AW_CONTAINMENT_ALLOW_AUTO_FOR_SERVERS={{ 'true' if (aw_containment_allow_auto_for_servers | default(false) | bool) else 'false' }}
AW_DLP_INFLUX_ENABLED={{ 'true' if ((aw_dlp_enabled | default(false) | bool) and (aw_dlp_influx_enabled | default(false) | bool)) else 'false' }}
AW_DLP_INFLUX_ENABLED={{ 'true' if (aw_dlp_influx_enabled | default(false) | bool) else 'false' }}
AW_DLP_INFLUX_URL={{ aw_dlp_influx_url | default('') }}
AW_DLP_INFLUX_ORG={{ aw_dlp_influx_org | default('proxmox') }}
AW_DLP_INFLUX_BUCKET={{ aw_dlp_influx_bucket | default('aw_metrics') }}
AW_DLP_INFLUX_HOSTS={{ aw_dlp_influx_hosts | default(aw_effective_monitored_windows_hostname | default('HOST-EXAMPLE')) }}
AW_DLP_INFLUX_HOSTS={{ aw_dlp_influx_hosts | default('SHARKON2025') }}
AW_DLP_INFLUX_LOOKBACK_DAYS={{ aw_dlp_influx_lookback_days | default(30) }}
AW_DLP_INFLUX_EVENT_LIMIT={{ aw_dlp_influx_event_limit | default(2000) }}
AW_DLP_INFLUX_TOKEN={{ aw_effective_dlp_influx_token | default('') }}
@@ -859,7 +820,6 @@
AW_RUS_HEALTH_SESSION_EVENTS_MAX_AGE_SECONDS={{ aw_rus_health_session_events_max_age_seconds | default(86400) }}
AW_RUS_HEALTH_GUARD_MAX_AGE_SECONDS={{ aw_rus_health_guard_max_age_seconds | default(300) }}
AW_RUS_HEALTH_GUARD_REQUIRED={{ 1 if (aw_rus_health_guard_required | default(true) | bool) else 0 }}
AW_RUS_HEALTH_RDP_TCP_REQUIRED={{ 'true' if (aw_rus_health_rdp_tcp_required | default(true) | bool) else 'false' }}
AW_RUS_SLO_STATE_DIR={{ aw_server_data_dir }}/slo
AW_RUS_SLO_AW_BASE=http://127.0.0.1:5600
AW_RUS_SLO_WORKTIME_BASE={{ aw_rus_health_worktime_api_base | default('http://127.0.0.1:5610') }}
@@ -877,104 +837,6 @@
AW_HAYABUSA_TELEGRAM_MIN_SEVERITY={{ aw_hayabusa_telegram_min_severity | default('high') }}
AW_HAYABUSA_TELEGRAM_BOT_TOKEN={{ aw_hayabusa_telegram_bot_token | default('') }}
AW_HAYABUSA_TELEGRAM_CHAT_IDS={{ aw_hayabusa_telegram_chat_ids | default('') }}
AW_SECURITY_FINDING_INBOX_ENABLED={{ 'true' if (aw_security_finding_inbox_enabled | default(false) | bool) else 'false' }}
AW_SECURITY_FINDING_INBOX_REQUIRED={{ 'true' if (aw_security_finding_inbox_required | default(false) | bool) else 'false' }}
AW_SECURITY_FINDING_INBOX_BIN={{ aw_security_finding_inbox_bin | default('/usr/local/bin/security-finding-inbox') }}
AW_SECURITY_FINDING_INBOX_MIN_SEVERITY={{ aw_security_finding_inbox_min_severity | default('medium') }}
AW_SECURITY_FINDING_EXECUTOR_WORK_DIR={{ aw_security_finding_executor_work_dir | default(aw_server_data_dir ~ '/security-finding-executor') }}
AW_SECURITY_FINDING_EXECUTOR_LOCK={{ aw_security_finding_executor_lock | default('/var/lock/aw-security-finding-executor.lock') }}
AW_CONTAINMENT_ENGINE_BIN={{ aw_containment_engine_bin | default('/usr/local/bin/containment-engine') }}
AW_CONTAINMENT_MANAGEMENT_ALLOWLIST={{ aw_containment_management_allowlist | default('') }}
AW_CONTAINMENT_BLOCKED_REMOTE_ADDRESSES={{ aw_containment_blocked_remote_addresses | default('') }}
- name: Установить runtime control для optional DLP контура
ansible.builtin.copy:
src: "{{ aw_repo_root }}/scripts/detmir_dlp_runtime_control.sh"
dest: /usr/local/bin/detmir-dlp-runtime-control
owner: root
group: root
mode: "0755"
- name: Установить load guard для lightweight DLP контура
ansible.builtin.copy:
src: "{{ aw_repo_root }}/scripts/detmir_dlp_load_guard.sh"
dest: /usr/local/bin/detmir-dlp-load-guard
owner: root
group: root
mode: "0755"
- name: Установить systemd unit DLP load guard
ansible.builtin.copy:
dest: /etc/systemd/system/detmir-dlp-load-guard.service
owner: root
group: root
mode: "0644"
content: |
[Unit]
Description=DetMir lightweight DLP load guard
After=activitywatch-server.service
[Service]
Type=oneshot
EnvironmentFile=-/etc/activitywatch/aw-server.env
ExecStart=/usr/local/bin/detmir-dlp-load-guard
Nice=10
IOSchedulingClass=best-effort
IOSchedulingPriority=7
TimeoutStartSec=45
- name: Установить systemd timer DLP load guard
ansible.builtin.copy:
dest: /etc/systemd/system/detmir-dlp-load-guard.timer
owner: root
group: root
mode: "0644"
content: |
[Unit]
Description=Run DetMir lightweight DLP load guard
[Timer]
OnBootSec=3min
OnUnitActiveSec=1min
AccuracySec=30s
Persistent=false
[Install]
WantedBy=timers.target
- name: Включить DLP load guard timer
ansible.builtin.systemd:
name: detmir-dlp-load-guard.timer
enabled: true
state: started
daemon_reload: true
when: aw_dlp_light_guard_enabled | default(true) | bool
- name: Отключить DLP load guard timer, если guard явно выключен
ansible.builtin.systemd:
name: detmir-dlp-load-guard.timer
enabled: false
state: stopped
daemon_reload: true
failed_when: false
when: not (aw_dlp_light_guard_enabled | default(true) | bool)
- name: Создать каталог containment policy
ansible.builtin.file:
path: "{{ (aw_containment_policy_path | default('/etc/activitywatch/containment-policy.json')) | dirname }}"
state: directory
owner: root
group: root
mode: "0755"
- name: Установить default containment policy, если live policy отсутствует
ansible.builtin.copy:
src: "{{ aw_repo_root }}/configs/containment-policy.example.json"
dest: "{{ aw_containment_policy_path | default('/etc/activitywatch/containment-policy.json') }}"
owner: root
group: root
mode: "0644"
force: false
- name: Создать каталог DLP policy engine
ansible.builtin.file:
@@ -983,9 +845,7 @@
owner: "{{ aw_server_user }}"
group: "{{ aw_server_group }}"
mode: "0755"
when:
- aw_dlp_enabled | default(false) | bool
- aw_dlp_policy_engine_enabled | default(false) | bool
when: aw_dlp_policy_engine_enabled | default(false) | bool
- name: Установить systemd unit DLP policy engine
ansible.builtin.copy:
@@ -994,9 +854,7 @@
owner: root
group: root
mode: "0644"
when:
- aw_dlp_enabled | default(false) | bool
- aw_dlp_policy_engine_enabled | default(false) | bool
when: aw_dlp_policy_engine_enabled | default(false) | bool
- name: Проверить локальный Rust DLP policy engine
ansible.builtin.stat:
@@ -1031,7 +889,7 @@
owner: "{{ aw_server_user }}"
group: "{{ aw_server_group }}"
mode: "0755"
when: aw_dlp_content_analysis_enabled | default(false) | bool
when: aw_dlp_content_analysis_enabled | default(true) | bool
- name: Скопировать файлы DLP content analysis
ansible.builtin.copy:
@@ -1040,7 +898,7 @@
owner: "{{ aw_server_user }}"
group: "{{ aw_server_group }}"
mode: "0644"
when: aw_dlp_content_analysis_enabled | default(false) | bool
when: aw_dlp_content_analysis_enabled | default(true) | bool
- name: Установить wrapper запуска DLP content analysis через virtualenv
ansible.builtin.copy:
@@ -1049,7 +907,7 @@
owner: root
group: root
mode: "0755"
when: aw_dlp_content_analysis_enabled | default(false) | bool
when: aw_dlp_content_analysis_enabled | default(true) | bool
- name: Проверить локальный Rust DLP content analyzer
ansible.builtin.stat:
@@ -1057,7 +915,7 @@
delegate_to: localhost
register: dlp_content_analyzer_rust_binary
become: false
when: aw_dlp_content_analysis_enabled | default(false) | bool
when: aw_dlp_content_analysis_enabled | default(true) | bool
- name: Установить Rust DLP content analyzer
ansible.builtin.copy:
@@ -1067,7 +925,7 @@
group: root
mode: "0755"
when:
- aw_dlp_content_analysis_enabled | default(false) | bool
- aw_dlp_content_analysis_enabled | default(true) | bool
- dlp_content_analyzer_rust_binary.stat.exists | default(false)
- name: Создать virtualenv DLP content analysis
@@ -1075,13 +933,13 @@
cmd: python3 -m venv /opt/activitywatch/dlp-content-analysis/.venv
args:
creates: /opt/activitywatch/dlp-content-analysis/.venv/bin/python
when: aw_dlp_content_analysis_enabled | default(false) | bool
when: aw_dlp_content_analysis_enabled | default(true) | bool
- name: Установить зависимости DLP content analysis
ansible.builtin.pip:
requirements: /opt/activitywatch/dlp-content-analysis/requirements.txt
virtualenv: /opt/activitywatch/dlp-content-analysis/.venv
when: aw_dlp_content_analysis_enabled | default(false) | bool
when: aw_dlp_content_analysis_enabled | default(true) | bool
- name: Создать каталог DLP integrations
ansible.builtin.file:
@@ -1090,9 +948,7 @@
owner: "{{ aw_server_user }}"
group: "{{ aw_server_group }}"
mode: "0755"
when:
- aw_dlp_enabled | default(false) | bool
- aw_dlp_integrations_enabled | default(false) | bool
when: aw_dlp_integrations_enabled | default(true) | bool
- name: Скопировать файлы DLP integrations
ansible.builtin.copy:
@@ -1105,9 +961,7 @@
- cef-config.yaml
- syslog-forwarder-config.yaml
- webhook-config.yaml
when:
- aw_dlp_enabled | default(false) | bool
- aw_dlp_integrations_enabled | default(false) | bool
when: aw_dlp_integrations_enabled | default(true) | bool
- name: Создать state каталог DLP integrations
ansible.builtin.file:
@@ -1116,9 +970,7 @@
owner: "{{ aw_server_user }}"
group: "{{ aw_server_group }}"
mode: "0755"
when:
- aw_dlp_enabled | default(false) | bool
- aw_dlp_integrations_enabled | default(false) | bool
when: aw_dlp_integrations_enabled | default(true) | bool
- name: Установить systemd unit CEF exporter
ansible.builtin.copy:
@@ -1127,9 +979,7 @@
owner: root
group: root
mode: "0644"
when:
- aw_dlp_enabled | default(false) | bool
- aw_dlp_integrations_enabled | default(false) | bool
when: aw_dlp_integrations_enabled | default(true) | bool
- name: Установить systemd timer CEF exporter
ansible.builtin.copy:
@@ -1138,9 +988,7 @@
owner: root
group: root
mode: "0644"
when:
- aw_dlp_enabled | default(false) | bool
- aw_dlp_integrations_enabled | default(false) | bool
when: aw_dlp_integrations_enabled | default(true) | bool
- name: Проверить локальный Rust CEF exporter
ansible.builtin.stat:
@@ -1148,16 +996,14 @@
delegate_to: localhost
register: dlp_cef_exporter_rust_binary
become: false
when:
- aw_dlp_enabled | default(false) | bool
- aw_dlp_integrations_enabled | default(false) | bool
when: aw_dlp_integrations_enabled | default(true) | bool
- name: Требовать Rust CEF exporter artifact
ansible.builtin.assert:
that:
- dlp_cef_exporter_rust_binary.stat.exists | default(false)
fail_msg: "Missing Rust artifact: {{ aw_rust_release_dir }}/dlp-cef-exporter"
when: aw_dlp_integrations_enabled | default(false) | bool
when: aw_dlp_integrations_enabled | default(true) | bool
- name: Установить Rust CEF exporter
ansible.builtin.copy:
@@ -1167,7 +1013,7 @@
group: root
mode: "0755"
when:
- aw_dlp_integrations_enabled | default(false) | bool
- aw_dlp_integrations_enabled | default(true) | bool
- dlp_cef_exporter_rust_binary.stat.exists | default(false)
- name: Установить systemd unit syslog forwarder
@@ -1177,7 +1023,7 @@
owner: root
group: root
mode: "0644"
when: aw_dlp_integrations_enabled | default(false) | bool
when: aw_dlp_integrations_enabled | default(true) | bool
- name: Установить systemd timer syslog forwarder
ansible.builtin.copy:
@@ -1186,7 +1032,7 @@
owner: root
group: root
mode: "0644"
when: aw_dlp_integrations_enabled | default(false) | bool
when: aw_dlp_integrations_enabled | default(true) | bool
- name: Проверить локальный Rust syslog forwarder
ansible.builtin.stat:
@@ -1194,14 +1040,14 @@
delegate_to: localhost
register: dlp_syslog_forwarder_rust_binary
become: false
when: aw_dlp_integrations_enabled | default(false) | bool
when: aw_dlp_integrations_enabled | default(true) | bool
- name: Требовать Rust syslog forwarder artifact
ansible.builtin.assert:
that:
- dlp_syslog_forwarder_rust_binary.stat.exists | default(false)
fail_msg: "Missing Rust artifact: {{ aw_rust_release_dir }}/dlp-syslog-forwarder"
when: aw_dlp_integrations_enabled | default(false) | bool
when: aw_dlp_integrations_enabled | default(true) | bool
- name: Установить Rust syslog forwarder
ansible.builtin.copy:
@@ -1211,7 +1057,7 @@
group: root
mode: "0755"
when:
- aw_dlp_integrations_enabled | default(false) | bool
- aw_dlp_integrations_enabled | default(true) | bool
- dlp_syslog_forwarder_rust_binary.stat.exists | default(false)
- name: Установить systemd unit webhook sender
@@ -1221,7 +1067,7 @@
owner: root
group: root
mode: "0644"
when: aw_dlp_integrations_enabled | default(false) | bool
when: aw_dlp_integrations_enabled | default(true) | bool
- name: Установить systemd timer webhook sender
ansible.builtin.copy:
@@ -1230,7 +1076,7 @@
owner: root
group: root
mode: "0644"
when: aw_dlp_integrations_enabled | default(false) | bool
when: aw_dlp_integrations_enabled | default(true) | bool
- name: Проверить локальный Rust webhook sender
ansible.builtin.stat:
@@ -1238,14 +1084,14 @@
delegate_to: localhost
register: dlp_webhook_sender_rust_binary
become: false
when: aw_dlp_integrations_enabled | default(false) | bool
when: aw_dlp_integrations_enabled | default(true) | bool
- name: Требовать Rust webhook sender artifact
ansible.builtin.assert:
that:
- dlp_webhook_sender_rust_binary.stat.exists | default(false)
fail_msg: "Missing Rust artifact: {{ aw_rust_release_dir }}/dlp-webhook-sender"
when: aw_dlp_integrations_enabled | default(false) | bool
when: aw_dlp_integrations_enabled | default(true) | bool
- name: Установить Rust webhook sender
ansible.builtin.copy:
@@ -1255,7 +1101,7 @@
group: root
mode: "0755"
when:
- aw_dlp_integrations_enabled | default(false) | bool
- aw_dlp_integrations_enabled | default(true) | bool
- dlp_webhook_sender_rust_binary.stat.exists | default(false)
- name: Создать каталог DLP case management
@@ -1265,9 +1111,7 @@
owner: "{{ aw_server_user }}"
group: "{{ aw_server_group }}"
mode: "0755"
when:
- aw_dlp_enabled | default(false) | bool
- aw_dlp_case_management_enabled | default(false) | bool
when: aw_dlp_case_management_enabled | default(true) | bool
- name: Установить systemd unit DLP case management
ansible.builtin.copy:
@@ -1276,9 +1120,7 @@
owner: root
group: root
mode: "0644"
when:
- aw_dlp_enabled | default(false) | bool
- aw_dlp_case_management_enabled | default(false) | bool
when: aw_dlp_case_management_enabled | default(true) | bool
- name: Проверить локальный Rust DLP case management
ansible.builtin.stat:
@@ -1286,14 +1128,14 @@
delegate_to: localhost
register: aw_dlp_case_management_rust_binary
become: false
when: aw_dlp_case_management_enabled | default(false) | bool
when: aw_dlp_case_management_enabled | default(true) | bool
- name: Требовать Rust DLP case management artifact
ansible.builtin.assert:
that:
- aw_dlp_case_management_rust_binary.stat.exists | default(false)
fail_msg: "Missing Rust artifact: {{ aw_rust_release_dir }}/dlp-case-management"
when: aw_dlp_case_management_enabled | default(false) | bool
when: aw_dlp_case_management_enabled | default(true) | bool
- name: Установить Rust DLP case management
ansible.builtin.copy:
@@ -1303,7 +1145,7 @@
group: root
mode: "0755"
when:
- aw_dlp_case_management_enabled | default(false) | bool
- aw_dlp_case_management_enabled | default(true) | bool
- aw_dlp_case_management_rust_binary.stat.exists | default(false)
- name: Создать каталоги DLP compliance
@@ -1317,9 +1159,7 @@
- /opt/activitywatch/dlp-compliance
- /opt/activitywatch/dlp-compliance/templates
- "{{ aw_dlp_compliance_report_dir }}"
when:
- aw_dlp_enabled | default(false) | bool
- aw_dlp_compliance_enabled | default(false) | bool
when: aw_dlp_compliance_enabled | default(true) | bool
- name: Скопировать файлы DLP compliance
ansible.builtin.copy:
@@ -1333,9 +1173,7 @@
- { src: "templates/pci-dss-report.html", dest: "/opt/activitywatch/dlp-compliance/templates/pci-dss-report.html", mode: "0644" }
- { src: "report-scheduler.service", dest: "/etc/systemd/system/aw-dlp-report-scheduler.service", mode: "0644" }
- { src: "report-scheduler.timer", dest: "/etc/systemd/system/aw-dlp-report-scheduler.timer", mode: "0644" }
when:
- aw_dlp_enabled | default(false) | bool
- aw_dlp_compliance_enabled | default(false) | bool
when: aw_dlp_compliance_enabled | default(true) | bool
- name: Проверить локальный Rust DLP compliance
ansible.builtin.stat:
@@ -1343,18 +1181,14 @@
delegate_to: localhost
register: aw_dlp_compliance_rust_binary
become: false
when:
- aw_dlp_enabled | default(false) | bool
- aw_dlp_compliance_enabled | default(false) | bool
when: aw_dlp_compliance_enabled | default(true) | bool
- name: Требовать Rust DLP compliance artifact
ansible.builtin.assert:
that:
- aw_dlp_compliance_rust_binary.stat.exists | default(false)
fail_msg: "Missing Rust artifact: {{ aw_rust_release_dir }}/dlp-compliance"
when:
- aw_dlp_enabled | default(false) | bool
- aw_dlp_compliance_enabled | default(false) | bool
when: aw_dlp_compliance_enabled | default(true) | bool
- name: Установить Rust DLP compliance
ansible.builtin.copy:
@@ -1364,7 +1198,7 @@
group: root
mode: "0755"
when:
- aw_dlp_compliance_enabled | default(false) | bool
- aw_dlp_compliance_enabled | default(true) | bool
- aw_dlp_compliance_rust_binary.stat.exists | default(false)
- name: Проверить локальный Rust dlp-admin-cli
@@ -1603,47 +1437,6 @@
mode: "0755"
when: dlp_health_check_rust_binary.stat.exists | default(false)
- name: Проверить локальный Rust containment-engine
ansible.builtin.stat:
path: "{{ aw_rust_release_dir }}/containment-engine"
delegate_to: localhost
register: containment_engine_rust_binary
become: false
- name: Установить Rust containment-engine
ansible.builtin.copy:
src: "{{ aw_rust_release_dir }}/containment-engine"
dest: /usr/local/bin/containment-engine
owner: root
group: root
mode: "0755"
when: containment_engine_rust_binary.stat.exists | default(false)
- name: Проверить локальный Rust security-finding-inbox
ansible.builtin.stat:
path: "{{ aw_rust_release_dir }}/security-finding-inbox"
delegate_to: localhost
register: security_finding_inbox_rust_binary
become: false
- name: Установить Rust security-finding-inbox
ansible.builtin.copy:
src: "{{ aw_rust_release_dir }}/security-finding-inbox"
dest: /usr/local/bin/security-finding-inbox
owner: root
group: root
mode: "0755"
when: security_finding_inbox_rust_binary.stat.exists | default(false)
- name: Установить systemd unit Security Finding Inbox executor
ansible.builtin.copy:
src: "{{ aw_repo_root }}/ops/systemd/aw-security-finding-executor.service"
dest: /etc/systemd/system/aw-security-finding-executor.service
owner: root
group: root
mode: "0644"
notify: Перезагрузить systemd
- name: Проверить локальный Rust AW-RUS healthd
ansible.builtin.stat:
path: "{{ aw_rust_release_dir }}/aw-rus-healthd"
@@ -1851,9 +1644,7 @@
owner: root
group: root
mode: "0644"
when:
- aw_dlp_enabled | default(false) | bool
- aw_dlp_influx_enabled | default(false) | bool
when: aw_dlp_influx_enabled | default(false) | bool
- name: Проверить локальный Rust AW DLP Influx exporter
ansible.builtin.stat:
@@ -1861,18 +1652,14 @@
delegate_to: localhost
register: aw_dlp_influx_exporter_rust_binary
become: false
when:
- aw_dlp_enabled | default(false) | bool
- aw_dlp_influx_enabled | default(false) | bool
when: aw_dlp_influx_enabled | default(false) | bool
- name: Требовать Rust AW DLP Influx exporter artifact
ansible.builtin.assert:
that:
- aw_dlp_influx_exporter_rust_binary.stat.exists | default(false)
fail_msg: "Missing Rust artifact: {{ aw_rust_release_dir }}/dlp-influx-exporter"
when:
- aw_dlp_enabled | default(false) | bool
- aw_dlp_influx_enabled | default(false) | bool
when: aw_dlp_influx_enabled | default(false) | bool
- name: Установить Rust AW DLP Influx exporter
ansible.builtin.copy:
@@ -1892,9 +1679,7 @@
owner: root
group: root
mode: "0644"
when:
- aw_dlp_enabled | default(false) | bool
- aw_dlp_influx_enabled | default(false) | bool
when: aw_dlp_influx_enabled | default(false) | bool
- name: Проверить локальный Rust DetMir readiness checker
ansible.builtin.stat:
@@ -2046,42 +1831,42 @@
name: aw-dlp-cef-exporter.timer
enabled: true
state: restarted
when: aw_dlp_integrations_enabled | default(false) | bool
when: aw_dlp_integrations_enabled | default(true) | bool
- name: Включить и перезапустить timer syslog forwarder
ansible.builtin.systemd:
name: aw-dlp-syslog-forwarder.timer
enabled: true
state: restarted
when: aw_dlp_integrations_enabled | default(false) | bool
when: aw_dlp_integrations_enabled | default(true) | bool
- name: Включить и перезапустить timer webhook sender
ansible.builtin.systemd:
name: aw-dlp-webhook-sender.timer
enabled: true
state: restarted
when: aw_dlp_integrations_enabled | default(false) | bool
when: aw_dlp_integrations_enabled | default(true) | bool
- name: Включить и перезапустить DLP case management
ansible.builtin.systemd:
name: aw-dlp-case-management.service
enabled: true
state: restarted
when: aw_dlp_case_management_enabled | default(false) | bool
when: aw_dlp_case_management_enabled | default(true) | bool
- name: Включить и перезапустить timer DLP compliance report
ansible.builtin.systemd:
name: aw-dlp-report-scheduler.timer
enabled: true
state: restarted
when: aw_dlp_compliance_enabled | default(false) | bool
when: aw_dlp_compliance_enabled | default(true) | bool
- name: Выполнить разовый прогон DLP compliance report
ansible.builtin.systemd:
name: aw-dlp-report-scheduler.service
state: started
failed_when: false
when: aw_dlp_compliance_enabled | default(false) | bool
when: aw_dlp_compliance_enabled | default(true) | bool
- name: Включить и перезапустить AW worktime API
ansible.builtin.systemd:
@@ -2448,11 +2233,6 @@
mode: "0755"
when: dlp_aggregator_rust_binary.stat.exists | default(false)
- name: Удалить stale drop-in, переопределяющий lightweight DLP aggregator
ansible.builtin.file:
path: /etc/systemd/system/activitywatch-dlp-aggregator.service.d/20-rust-switch.conf
state: absent
- name: Установить systemd unit для агрегатора
ansible.builtin.copy:
dest: /etc/systemd/system/activitywatch-dlp-aggregator.service
@@ -2461,7 +2241,7 @@
mode: "0644"
content: |
[Unit]
Description=ActivityWatch Lightweight DLP Event Aggregator
Description=ActivityWatch DLP Event Aggregator
After=activitywatch-server.service
[Service]
@@ -2471,18 +2251,7 @@
ExecStart=/usr/local/bin/dlp-aggregator-rust \
--aw-url http://127.0.0.1:{{ aw_server_port }}/api/0 \
--sqlite-path {{ aw_server_data_dir }}/dlp_warehouse.sqlite \
--state-path {{ aw_server_data_dir }}/dlp-aggregator-state.json \
--bucket-prefixes {{ aw_dlp_aggregator_bucket_prefixes | default('aw-file-operations_,aw-dlp-incidents_') }} \
--lookback-hours {{ aw_dlp_aggregator_lookback_hours | default(2) }} \
--overlap-seconds {{ aw_dlp_aggregator_overlap_seconds | default(60) }} \
--limit {{ aw_dlp_aggregator_limit | default(500) }} \
--timeout {{ aw_dlp_aggregator_timeout_seconds | default(8) }}
Nice=10
IOSchedulingClass=best-effort
IOSchedulingPriority=7
CPUQuota={{ aw_dlp_aggregator_cpu_quota | default('10%') }}
MemoryMax={{ aw_dlp_aggregator_memory_max | default('256M') }}
TimeoutStartSec={{ (aw_dlp_aggregator_timeout_seconds | default(8) | int) + 15 }}
--state-path {{ aw_server_data_dir }}/dlp-aggregator-state.json
[Install]
WantedBy=multi-user.target
@@ -2492,10 +2261,10 @@
dest: /etc/systemd/system/activitywatch-dlp-aggregator.timer
content: |
[Unit]
Description=Run ActivityWatch Lightweight DLP Aggregator
Description=Run ActivityWatch DLP Aggregator every 5 minutes
[Timer]
OnCalendar={{ aw_dlp_aggregator_on_calendar | default('*:3/15:10') }}
OnCalendar=*:3/10:10
AccuracySec=30s
RandomizedDelaySec=30s
Persistent=false
@@ -2509,14 +2278,9 @@
enabled: true
state: started
daemon_reload: true
when:
- aw_dlp_enabled | default(false) | bool
- aw_dlp_light_collector_enabled | default(false) | bool
- name: Настроить IOC enrichment из Hayabusa Sigma
when:
- aw_dlp_enabled | default(false) | bool
- aw_dlp_ioc_enabled | default(false) | bool
when: aw_dlp_ioc_enabled | default(false) | bool
block:
- name: Создать каталог IOC enrichment
ansible.builtin.file:
-76
View File
@@ -15,16 +15,8 @@
detmir_portal_workforce_policy_path: "/etc/detmir-portal-workforce-policy.json"
detmir_portal_ueba_policy_path: "/etc/detmir-portal-ueba-policy.yaml"
detmir_portal_readiness_bundle_dir: "{{ detmir_portal_readiness_bundle_dir_override | default('/var/lib/activitywatch/health/readiness-bundle', true) }}"
detmir_portal_dlp_module_enabled: "{{ detmir_portal_dlp_module_enabled_override | default(false) }}"
tasks:
- name: Refuse inconsistent DetMir portal DLP profile
ansible.builtin.assert:
that:
- detmir_portal_dlp_profile | default('core_only') in ['core_only', 'light', 'on_demand', 'full']
- (detmir_portal_dlp_profile | default('core_only') != 'core_only') or not (detmir_portal_dlp_module_enabled | bool)
fail_msg: "Inconsistent DetMir portal DLP profile: core_only must keep DETMIR_PORTAL_DLP_MODULE_ENABLED=false."
- name: Check local detmir-portal binary
ansible.builtin.stat:
path: "{{ aw_rust_release_dir }}/detmir-portal"
@@ -62,8 +54,6 @@
DETMIR_PORTAL_UEBA_POLICY_PATH={{ detmir_portal_ueba_policy_path }}
DETMIR_PORTAL_TIMEOUT_SECONDS=25
DETMIR_PORTAL_STATE_DIR=/var/lib/detmir-portal
DETMIR_PORTAL_DLP_MODULE_ENABLED={{ detmir_portal_dlp_module_enabled | bool | ternary('true', 'false') }}
DETMIR_PORTAL_DLP_PROFILE={{ detmir_portal_dlp_profile | default('core_only') }}
DETMIR_PORTAL_DLP_DB_PATH=/var/lib/activitywatch/dlp_warehouse.sqlite
DETMIR_PORTAL_EVIDENCE_ROOT=/var/lib/detmir-portal/evidence
DETMIR_PORTAL_READINESS_BUNDLE_DIR={{ detmir_portal_readiness_bundle_dir }}
@@ -75,65 +65,6 @@
CLICKHOUSE_USER={{ detmir_clickhouse_user | default('default') }}
CLICKHOUSE_PASSWORD={{ detmir_clickhouse_password | default('') }}
- name: Install lightweight DLP warehouse sync helper
ansible.builtin.copy:
src: "{{ aw_repo_root }}/scripts/detmir_dlp_warehouse_sync.sh"
dest: /usr/local/bin/detmir-dlp-warehouse-sync
owner: root
group: root
mode: "0755"
- name: Install lightweight DLP warehouse sync service
ansible.builtin.copy:
dest: /etc/systemd/system/detmir-dlp-warehouse-sync.service
owner: root
group: root
mode: "0644"
content: |
[Unit]
Description=Sync lightweight DetMir DLP SQLite warehouse for portal
After=network-online.target
Wants=network-online.target
[Service]
Type=oneshot
Environment=AW_DLP_WAREHOUSE_SOURCE_HOST={{ detmir_portal_dlp_warehouse_source_host | default('igor@10.10.10.13') }}
Environment=AW_DLP_WAREHOUSE_SOURCE_PATH={{ detmir_portal_dlp_warehouse_source_path | default('/var/lib/activitywatch/dlp_warehouse.sqlite') }}
Environment=AW_DLP_WAREHOUSE_DEST_PATH={{ detmir_portal_dlp_warehouse_dest_path | default('/var/lib/activitywatch/dlp_warehouse.sqlite') }}
Environment=AW_DLP_WAREHOUSE_SYNC_STATE_DIR={{ detmir_portal_dlp_warehouse_sync_state_dir | default('/var/lib/activitywatch/health') }}
ExecStart=/usr/local/bin/detmir-dlp-warehouse-sync
Nice=10
IOSchedulingClass=best-effort
IOSchedulingPriority=7
TimeoutStartSec=60
- name: Install lightweight DLP warehouse sync timer
ansible.builtin.copy:
dest: /etc/systemd/system/detmir-dlp-warehouse-sync.timer
owner: root
group: root
mode: "0644"
content: |
[Unit]
Description=Run lightweight DetMir DLP SQLite warehouse sync
[Timer]
OnBootSec=4min
OnUnitActiveSec={{ detmir_portal_dlp_warehouse_sync_interval | default('2min') }}
AccuracySec=30s
Persistent=false
[Install]
WantedBy=timers.target
- name: Enable lightweight DLP warehouse sync timer
ansible.builtin.systemd:
name: detmir-dlp-warehouse-sync.timer
enabled: true
state: started
daemon_reload: true
when: detmir_portal_dlp_module_enabled | bool
- name: Preserve local ClickHouse security-events settings when available
ansible.builtin.shell: |
set -euo pipefail
@@ -186,9 +117,7 @@
state: absent
loop:
- /etc/systemd/system/detmir-portal.service.d/20-timeouts.conf
- /etc/systemd/system/detmir-portal.service.d/20-prod-timeout.conf
- /etc/systemd/system/detmir-portal.service.d/30-warm-cache.conf
- /etc/systemd/system/detmir-portal.service.d/30-prewarm-after-start.conf
register: detmir_portal_stale_overrides
- name: Install initial workforce policy when absent
@@ -245,11 +174,6 @@
WantedBy=multi-user.target
register: detmir_portal_service_unit
- name: Remove stale detmir-portal timeout override
ansible.builtin.file:
path: /etc/systemd/system/detmir-portal.service.d/10-detmir-check-env.conf
state: absent
- name: Reload systemd
ansible.builtin.systemd:
daemon_reload: true
+7 -35
View File
@@ -33,10 +33,7 @@ aw_worktime_manager_trend_min_points: 3
aw_worktime_manager_trend_delta_pct: 10
aw_worktime_manager_off_hours_threshold_seconds: 1800
aw_worktime_interpretation_policy_path: "/etc/activitywatch/worktime-interpretation-policy.json"
aw_dlp_profile: "core_only"
detmir_portal_dlp_profile: "light"
detmir_portal_dlp_module_enabled_override: true
aw_dlp_influx_enabled: false
aw_dlp_influx_enabled: true
aw_dlp_influx_url: "http://192.0.2.10:8086"
aw_dlp_influx_org: "proxmox"
aw_dlp_influx_bucket: "aw_metrics"
@@ -50,7 +47,6 @@ aw_worktime_host: "{{ aw_monitored_windows_hostname }}"
aw_rus_health_worktime_api_base: "http://127.0.0.1:5610"
aw_rus_health_state_dir: "{{ aw_server_data_dir }}/health"
aw_rus_health_validation_dir: "{{ aw_rus_health_state_dir }}/windows-validation"
aw_rus_health_rdp_tcp_required: false
aw_hayabusa_auto_case_enabled: true
aw_hayabusa_auto_case_min_severity: "medium"
aw_hayabusa_telegram_enabled: true
@@ -69,46 +65,22 @@ aw_server_cors_origins:
aw_apply_worktime_settings: true
aw_dlp_ioc_enabled: false
aw_dlp_enabled: false
aw_dlp_disabled_reason: ""
aw_dlp_disabled_since: ""
aw_dlp_light_collector_enabled: false
aw_dlp_light_guard_enabled: true
aw_dlp_light_guard_load_ratio: "1.50"
aw_dlp_light_guard_mem_available_pct_min: "15"
aw_dlp_light_guard_iowait_pct_max: "20"
aw_dlp_light_guard_strikes_required: 3
aw_dlp_light_guard_state_dir: "{{ aw_server_data_dir }}/health"
aw_dlp_aggregator_bucket_prefixes: "aw-file-operations_,aw-dlp-incidents_"
aw_dlp_aggregator_limit: 500
aw_dlp_aggregator_lookback_hours: 2
aw_dlp_aggregator_overlap_seconds: 60
aw_dlp_aggregator_timeout_seconds: 8
aw_dlp_aggregator_on_calendar: "*:3/15:10"
aw_dlp_aggregator_cpu_quota: "10%"
aw_dlp_aggregator_memory_max: "256M"
aw_containment_enabled: false
aw_containment_mode: "shadow"
aw_containment_policy_path: "/etc/activitywatch/containment-policy.json"
aw_containment_default_ttl_minutes: 60
aw_containment_require_admin_channel_check: true
aw_containment_allow_auto_for_servers: false
aw_dlp_ioc_enabled: true
aw_dlp_ioc_workdir: "/opt/activitywatch/dlp-ioc"
aw_dlp_ioc_rules_zip_url: "https://github.com/Yamato-Security/hayabusa-rules/archive/refs/heads/main.zip"
aw_dlp_ioc_refresh_on_boot_sec: "5min"
aw_dlp_ioc_refresh_interval: "6h"
aw_dlp_policy_engine_enabled: false
aw_dlp_policy_engine_enabled: true
aw_dlp_policy_engine_bind_host: "0.0.0.0"
aw_dlp_policy_engine_port: 5601
aw_dlp_policy_engine_db_path: "{{ aw_server_data_dir }}/dlp-policy-engine.sqlite"
aw_dlp_content_analysis_enabled: false
aw_dlp_integrations_enabled: false
aw_dlp_case_management_enabled: false
aw_dlp_content_analysis_enabled: true
aw_dlp_integrations_enabled: true
aw_dlp_case_management_enabled: true
aw_dlp_case_bind_host: "0.0.0.0"
aw_dlp_case_port: 5602
aw_dlp_case_db_path: "/opt/activitywatch/dlp-case-management/cases.db"
aw_dlp_compliance_enabled: false
aw_dlp_compliance_enabled: true
aw_dlp_compliance_report_dir: "/opt/activitywatch/dlp-compliance/reports"
aw_dlp_compliance_template_path: "/opt/activitywatch/dlp-compliance/templates/152-fz-report.html"
aw_server_post_deploy_health_check_enabled: true
+4 -25
View File
@@ -16,7 +16,7 @@ AW_SERVER_GROUP=activitywatch
AW_SERVER_PUBLIC_HOST=aw-server
AW_WORKTIME_REPORT_BASE=http://aw-server:5610
AW_WORKTIME_TZ=Europe/Moscow
AW_WORKTIME_HOST=HOST-EXAMPLE
AW_WORKTIME_HOST=SHARKON2025
AW_WORKTIME_EVENTS_LIMIT=5000
AW_WORKTIME_AW_HTTP_TIMEOUT_SECONDS=6
AW_WORKTIME_EVENTS_CACHE_TTL_SECONDS=300
@@ -33,16 +33,6 @@ AW_WORKTIME_MANAGEMENT_WARM_URL=http://127.0.0.1:5610/reports/worktime/managemen
AW_WORKTIME_MANAGEMENT_WARM_TIMEOUT_SECONDS=70
# DLP IOC Configuration
AW_DLP_ENABLED=false
AW_DLP_PROFILE=core_only
AW_DLP_DISABLED_REASON=detmir_prod_resource_guardrail
AW_DLP_DISABLED_SINCE=
AW_CONTAINMENT_ENABLED=false
AW_CONTAINMENT_MODE=shadow
AW_CONTAINMENT_POLICY=/etc/activitywatch/containment-policy.json
AW_CONTAINMENT_DEFAULT_TTL_MINUTES=60
AW_CONTAINMENT_REQUIRE_ADMIN_CHANNEL_CHECK=true
AW_CONTAINMENT_ALLOW_AUTO_FOR_SERVERS=false
AW_DLP_IOC_DIR=/opt/activitywatch/dlp-ioc/output
# DLP Policy Engine Configuration
@@ -60,24 +50,22 @@ AW_HEALTH_CHECK_ENABLED=true
AW_HEALTH_CHECK_INTERVAL=60
AW_EXPECT_START_OF_DAY=00:00
AW_EXPECT_ALWAYS_ACTIVE_PATTERN=aw-watcher-window
AW_EXPECT_LANDINGPAGE=/#/activity/HOST-EXAMPLE/view/
AW_EXPECT_LANDINGPAGE=/#/activity/SHARKON2025/view/
AW_HEALTH_STRICT_FILEOPS=0
AW_MONITORED_WINDOWS_HOST=<WINDOWS_HOST>
AW_MONITORED_WINDOWS_HOSTNAME=HOST-EXAMPLE
AW_MONITORED_WINDOWS_HOSTNAME=SHARKON2025
AW_RUS_HEALTH_WORKTIME_API=http://127.0.0.1:5610
AW_RUS_HEALTH_STATE_DIR=/var/lib/activitywatch/health
AW_RUS_HEALTH_VALIDATION_DIR=/var/lib/activitywatch/health/windows-validation
AW_RUS_HEALTH_SESSION_EVENTS_MAX_AGE_SECONDS=86400
AW_RUS_HEALTH_GUARD_MAX_AGE_SECONDS=300
AW_RUS_HEALTH_GUARD_REQUIRED=1
AW_RUS_HEALTH_RDP_TCP_REQUIRED=true
AW_RUS_HEALTH_WRAPPER_TIMEOUT_SECONDS=90
AW_RUS_SLO_AW_BASE=http://127.0.0.1:5600
AW_RUS_SLO_WORKTIME_BASE=http://127.0.0.1:5610
AW_RUS_SLO_TARGET_PERCENT=99.97
AW_BROWSER_SMOKE_AW_BASE=http://127.0.0.1:5600
AW_BROWSER_SMOKE_WORKTIME_BASE=http://127.0.0.1:5610
AW_BROWSER_SMOKE_HOST=HOST-EXAMPLE
AW_BROWSER_SMOKE_HOST=SHARKON2025
AW_BROWSER_SMOKE_OUTPUT_DIR=/var/lib/activitywatch/browser-smoke
AW_BROWSER_SMOKE_KEEP_RUNS=24
AW_BROWSER_SMOKE_ENGINE=chromium-cli
@@ -91,15 +79,6 @@ AW_HAYABUSA_TELEGRAM_ENABLED=true
AW_HAYABUSA_TELEGRAM_MIN_SEVERITY=high
AW_HAYABUSA_TELEGRAM_BOT_TOKEN=
AW_HAYABUSA_TELEGRAM_CHAT_IDS=
AW_SECURITY_FINDING_INBOX_ENABLED=false
AW_SECURITY_FINDING_INBOX_REQUIRED=false
AW_SECURITY_FINDING_INBOX_BIN=/usr/local/bin/security-finding-inbox
AW_SECURITY_FINDING_INBOX_MIN_SEVERITY=medium
AW_SECURITY_FINDING_EXECUTOR_WORK_DIR=/var/lib/activitywatch/security-finding-executor
AW_SECURITY_FINDING_EXECUTOR_LOCK=/var/lock/aw-security-finding-executor.lock
AW_CONTAINMENT_ENGINE_BIN=/usr/local/bin/containment-engine
AW_CONTAINMENT_MANAGEMENT_ALLOWLIST=
AW_CONTAINMENT_BLOCKED_REMOTE_ADDRESSES=
# Integration Test Configuration
AW_INTEGRATION_TEST_ENABLED=false
+50 -50
View File
@@ -135,61 +135,61 @@ wheels = [
[[package]]
name = "cryptography"
version = "48.0.0"
version = "48.0.1"
source = { registry = "https://pypi.org/simple" }
dependencies = [
{ name = "cffi", marker = "platform_python_implementation != 'PyPy'" },
]
sdist = { url = "https://files.pythonhosted.org/packages/9f/a9/db8f313fdcd85d767d4973515e1db101f9c71f95fced83233de224673757/cryptography-48.0.0.tar.gz", hash = "sha256:5c3932f4436d1cccb036cb0eaef46e6e2db91035166f1ad6505c3c9d5a635920", size = 832984, upload-time = "2026-05-04T22:59:38.133Z" }
sdist = { url = "https://files.pythonhosted.org/packages/12/45/870e7f4bef50e5f53b9f51d4428aee5290eedf58ba443f16b1ebb7ab8e66/cryptography-48.0.1.tar.gz", hash = "sha256:266f4ee051abb2f725b74ef8072b521ce1feacf685a3364fa6a6b45548db791a", size = 832989, upload-time = "2026-06-09T22:32:31.8Z" }
wheels = [
{ url = "https://files.pythonhosted.org/packages/df/3d/01f6dd9190170a5a241e0e98c2d04be3664a9e6f5b9b872cde63aff1c3dd/cryptography-48.0.0-cp311-abi3-macosx_10_9_universal2.whl", hash = "sha256:0c558d2cdffd8f4bbb30fc7134c74d2ca9a476f830bb053074498fbc86f41ed6", size = 8001587, upload-time = "2026-05-04T22:57:36.803Z" },
{ url = "https://files.pythonhosted.org/packages/b2/6e/e90527eef33f309beb811cf7c982c3aeffcce8e3edb178baa4ca3ae4a6fa/cryptography-48.0.0-cp311-abi3-manylinux2014_aarch64.manylinux_2_17_aarch64.whl", hash = "sha256:f5333311663ea94f75dd408665686aaf426563556bb5283554a3539177e03b8c", size = 4690433, upload-time = "2026-05-04T22:57:40.373Z" },
{ url = "https://files.pythonhosted.org/packages/90/04/673510ed51ddff56575f306cf1617d80411ee76831ccd3097599140efdfe/cryptography-48.0.0-cp311-abi3-manylinux2014_x86_64.manylinux_2_17_x86_64.whl", hash = "sha256:7995ef305d7165c3f11ae07f2517e5a4f1d5c18da1376a0a9ed496336b69e5f3", size = 4710620, upload-time = "2026-05-04T22:57:42.935Z" },
{ url = "https://files.pythonhosted.org/packages/14/d5/e9c4ef932c8d800490c34d8bd589d64a31d5890e27ec9e9ad532be893294/cryptography-48.0.0-cp311-abi3-manylinux_2_28_aarch64.whl", hash = "sha256:40ba1f85eaa6959837b1d51c9767e230e14612eea4ef110ee8854ada22da1bf5", size = 4696283, upload-time = "2026-05-04T22:57:45.294Z" },
{ url = "https://files.pythonhosted.org/packages/0c/29/174b9dfb60b12d59ecfc6cfa04bc88c21b42a54f01b8aae09bb6e51e4c7f/cryptography-48.0.0-cp311-abi3-manylinux_2_28_ppc64le.whl", hash = "sha256:369a6348999f94bbd53435c894377b20ab95f25a9065c283570e70150d8abc3c", size = 5296573, upload-time = "2026-05-04T22:57:47.933Z" },
{ url = "https://files.pythonhosted.org/packages/95/38/0d29a6fd7d0d1373f0c0c88a04ba20e359b257753ac497564cd660fc1d55/cryptography-48.0.0-cp311-abi3-manylinux_2_28_x86_64.whl", hash = "sha256:a0e692c683f4df67815a2d258b324e66f4738bd7a96a218c826dce4f4bd05d8f", size = 4743677, upload-time = "2026-05-04T22:57:50.067Z" },
{ url = "https://files.pythonhosted.org/packages/30/be/eef653013d5c63b6a490529e0316f9ac14a37602965d4903efed1399f32b/cryptography-48.0.0-cp311-abi3-manylinux_2_31_armv7l.whl", hash = "sha256:18349bbc56f4743c8b12dc32e2bccb2cf83ee8b69a3bba74ef8ae857e26b3d25", size = 4330808, upload-time = "2026-05-04T22:57:52.301Z" },
{ url = "https://files.pythonhosted.org/packages/84/9e/500463e87abb7a0a0f9f256ec21123ecde0a7b5541a15e840ea54551fd81/cryptography-48.0.0-cp311-abi3-manylinux_2_34_aarch64.whl", hash = "sha256:7e8eac43dfca5c4cccc6dad9a80504436fca53bb9bc3100a2386d730fbe6b602", size = 4695941, upload-time = "2026-05-04T22:57:54.603Z" },
{ url = "https://files.pythonhosted.org/packages/e3/dc/7303087450c2ec9e7fbb750e17c2abfbc658f23cbd0e54009509b7cc4091/cryptography-48.0.0-cp311-abi3-manylinux_2_34_ppc64le.whl", hash = "sha256:9ccdac7d40688ecb5a3b4a604b8a88c8002e3442d6c60aead1db2a89a041560c", size = 5252579, upload-time = "2026-05-04T22:57:57.207Z" },
{ url = "https://files.pythonhosted.org/packages/d0/c0/7101d3b7215edcdc90c45da544961fd8ed2d6448f77577460fa75a8443f7/cryptography-48.0.0-cp311-abi3-manylinux_2_34_x86_64.whl", hash = "sha256:bd72e68b06bb1e96913f97dd4901119bc17f39d4586a5adf2d3e47bc2b9d58b5", size = 4743326, upload-time = "2026-05-04T22:57:59.535Z" },
{ url = "https://files.pythonhosted.org/packages/ac/d8/5b833bad13016f562ab9d063d68199a4bd121d18458e439515601d3357ec/cryptography-48.0.0-cp311-abi3-musllinux_1_2_aarch64.whl", hash = "sha256:59baa2cb386c4f0b9905bd6eb4c2a79a69a128408fd31d32ca4d7102d4156321", size = 4826672, upload-time = "2026-05-04T22:58:01.996Z" },
{ url = "https://files.pythonhosted.org/packages/98/e1/7074eb8bf3c135558c73fc2bcf0f5633f912e6fb87e868a55c454080ef09/cryptography-48.0.0-cp311-abi3-musllinux_1_2_x86_64.whl", hash = "sha256:9249e3cd978541d665967ac2cb2787fd6a62bddf1e75b3e347a594d7dacf4f74", size = 4972574, upload-time = "2026-05-04T22:58:03.968Z" },
{ url = "https://files.pythonhosted.org/packages/04/70/e5a1b41d325f797f39427aa44ef8baf0be500065ab6d8e10369d850d4a4f/cryptography-48.0.0-cp311-abi3-win32.whl", hash = "sha256:9c459db21422be75e2809370b829a87eb37f74cd785fc4aa9ea1e5f43b47cda4", size = 3294868, upload-time = "2026-05-04T22:58:06.467Z" },
{ url = "https://files.pythonhosted.org/packages/f4/ac/8ac51b4a5fc5932eb7ee5c517ba7dc8cd834f0048962b6b352f00f41ebf9/cryptography-48.0.0-cp311-abi3-win_amd64.whl", hash = "sha256:5b012212e08b8dd5edc78ef54da83dd9892fd9105323b3993eff6bea65dc21d7", size = 3817107, upload-time = "2026-05-04T22:58:08.845Z" },
{ url = "https://files.pythonhosted.org/packages/6b/84/70e3feea9feea87fd7cbe77efb2712ae1e3e6edf10749dc6e95f4e60e455/cryptography-48.0.0-cp314-cp314t-macosx_10_9_universal2.whl", hash = "sha256:3cb07a3ed6431663cd321ea8a000a1314c74211f823e4177fefa2255e057d1ec", size = 7986556, upload-time = "2026-05-04T22:58:11.172Z" },
{ url = "https://files.pythonhosted.org/packages/89/6e/18e07a618bb5442ba10cf4df16e99c071365528aa570dfcb8c02e25a303b/cryptography-48.0.0-cp314-cp314t-manylinux2014_aarch64.manylinux_2_17_aarch64.whl", hash = "sha256:8c7378637d7d88016fa6791c159f698b3d3eed28ebf844ac36b9dc04a14dae18", size = 4684776, upload-time = "2026-05-04T22:58:13.712Z" },
{ url = "https://files.pythonhosted.org/packages/be/6a/4ea3b4c6c6759794d5ee2103c304a5076dc4b19ae1f9fe47dba439e159e9/cryptography-48.0.0-cp314-cp314t-manylinux2014_x86_64.manylinux_2_17_x86_64.whl", hash = "sha256:cc90c0b39b2e3c65ef52c804b72e3c58f8a04ab2a1871272798e5f9572c17d20", size = 4698121, upload-time = "2026-05-04T22:58:16.448Z" },
{ url = "https://files.pythonhosted.org/packages/2f/59/6ff6ad6cae03bb887da2a5860b2c9805f8dac969ef01ce563336c49bd1d1/cryptography-48.0.0-cp314-cp314t-manylinux_2_28_aarch64.whl", hash = "sha256:76341972e1eff8b4bea859f09c0d3e64b96ce931b084f9b9b7db8ef364c30eff", size = 4690042, upload-time = "2026-05-04T22:58:18.544Z" },
{ url = "https://files.pythonhosted.org/packages/ca/b4/fc334ed8cfd705aca282fe4d8f5ae64a8e0f74932e9feecb344610cf6e4d/cryptography-48.0.0-cp314-cp314t-manylinux_2_28_ppc64le.whl", hash = "sha256:55b7718303bf06a5753dcdccf2f3945cf18ad7bffde41b61226e4db31ab89a9c", size = 5282526, upload-time = "2026-05-04T22:58:20.75Z" },
{ url = "https://files.pythonhosted.org/packages/11/08/9f8c5386cc4cd90d8255c7cdd0f5baf459a08502a09de30dc51f553d38dc/cryptography-48.0.0-cp314-cp314t-manylinux_2_28_x86_64.whl", hash = "sha256:a64697c641c7b1b2178e573cbc31c7c6684cd56883a478d75143dbb7118036db", size = 4733116, upload-time = "2026-05-04T22:58:23.627Z" },
{ url = "https://files.pythonhosted.org/packages/b8/77/99307d7574045699f8805aa500fa0fb83422d115b5400a064ddd306d7750/cryptography-48.0.0-cp314-cp314t-manylinux_2_31_armv7l.whl", hash = "sha256:561215ea3879cb1cbbf272867e2efda62476f240fb58c64de6b393ae19246741", size = 4316030, upload-time = "2026-05-04T22:58:25.581Z" },
{ url = "https://files.pythonhosted.org/packages/fd/36/a608b98337af3cb2aff4818e406649d30572b7031918b04c87d979495348/cryptography-48.0.0-cp314-cp314t-manylinux_2_34_aarch64.whl", hash = "sha256:ad64688338ed4bc1a6618076ba75fd7194a5f1797ac60b47afe926285adb3166", size = 4689640, upload-time = "2026-05-04T22:58:27.747Z" },
{ url = "https://files.pythonhosted.org/packages/dd/a6/825010a291b4438aecc1f568bc428189fc1175515223632477c07dc0a6df/cryptography-48.0.0-cp314-cp314t-manylinux_2_34_ppc64le.whl", hash = "sha256:906cbf0670286c6e0044156bc7d4af9cbb0ef6db9f73e52c3ec56ba6bdde5336", size = 5237657, upload-time = "2026-05-04T22:58:29.848Z" },
{ url = "https://files.pythonhosted.org/packages/b9/09/4e76a09b4caa29aad535ddc806f5d4c5d01885bd978bd984fbc6ca032cae/cryptography-48.0.0-cp314-cp314t-manylinux_2_34_x86_64.whl", hash = "sha256:ea8990436d914540a40ab24b6a77c0969695ed52f4a4874c5137ccf7045a7057", size = 4732362, upload-time = "2026-05-04T22:58:32.009Z" },
{ url = "https://files.pythonhosted.org/packages/18/78/444fa04a77d0cb95f417dda20d450e13c56ba8e5220fc892a1658f44f882/cryptography-48.0.0-cp314-cp314t-musllinux_1_2_aarch64.whl", hash = "sha256:c18684a7f0cc9a3cb60328f496b8e3372def7c5d2df39ac267878b05565aaaae", size = 4819580, upload-time = "2026-05-04T22:58:34.254Z" },
{ url = "https://files.pythonhosted.org/packages/38/85/ea67067c70a1fd4be2c63d35eeed82658023021affccc7b17705f8527dd2/cryptography-48.0.0-cp314-cp314t-musllinux_1_2_x86_64.whl", hash = "sha256:9be5aafa5736574f8f15f262adc81b2a9869e2cfe9014d52a44633905b40d52c", size = 4963283, upload-time = "2026-05-04T22:58:36.376Z" },
{ url = "https://files.pythonhosted.org/packages/75/54/cc6d0f3deac3e81c7f847e8a189a12b6cdd65059b43dad25d4316abd849a/cryptography-48.0.0-cp314-cp314t-win32.whl", hash = "sha256:c17dfe85494deaeddc5ce251aebd1d60bbe6afc8b62071bb0b469431a000124f", size = 3270954, upload-time = "2026-05-04T22:58:38.791Z" },
{ url = "https://files.pythonhosted.org/packages/49/67/cc947e288c0758a4e5473d1dcb743037ab7785541265a969240b8885441a/cryptography-48.0.0-cp314-cp314t-win_amd64.whl", hash = "sha256:27241b1dc9962e056062a8eef1991d02c3a24569c95975bd2322a8a52c6e5e12", size = 3797313, upload-time = "2026-05-04T22:58:40.746Z" },
{ url = "https://files.pythonhosted.org/packages/f2/63/61d4a4e1c6b6bab6ce1e213cd36a24c415d90e76d78c5eb8577c5541d2e8/cryptography-48.0.0-cp39-abi3-macosx_10_9_universal2.whl", hash = "sha256:58d00498e8933e4a194f3076aee1b4a97dfec1a6da444535755822fe5d8b0b86", size = 7983482, upload-time = "2026-05-04T22:58:43.769Z" },
{ url = "https://files.pythonhosted.org/packages/d5/ac/f5b5995b87770c693e2596559ffafe195b4033a57f14a82268a2842953f3/cryptography-48.0.0-cp39-abi3-manylinux2014_aarch64.manylinux_2_17_aarch64.whl", hash = "sha256:614d0949f4790582d2cc25553abd09dd723025f0c0e7c67376a1d77196743d6e", size = 4683266, upload-time = "2026-05-04T22:58:46.064Z" },
{ url = "https://files.pythonhosted.org/packages/ec/c6/8b14f67e18338fbc4adb76f66c001f5c3610b3e2d1837f268f47a347dbbb/cryptography-48.0.0-cp39-abi3-manylinux2014_x86_64.manylinux_2_17_x86_64.whl", hash = "sha256:7ce4bfae76319a532a2dc68f82cc32f5676ee792a983187dac07183690e5c66f", size = 4696228, upload-time = "2026-05-04T22:58:48.22Z" },
{ url = "https://files.pythonhosted.org/packages/ea/73/f808fbae9514bd91b47875b003f13e284c8c6bdfd904b7944e803937eec1/cryptography-48.0.0-cp39-abi3-manylinux_2_28_aarch64.whl", hash = "sha256:2eb992bbd4661238c5a397594c83f5b4dc2bc5b848c365c8f991b6780efcc5c7", size = 4689097, upload-time = "2026-05-04T22:58:50.9Z" },
{ url = "https://files.pythonhosted.org/packages/93/01/d86632d7d28db8ae83221995752eeb6639ffb374c2d22955648cf8d52797/cryptography-48.0.0-cp39-abi3-manylinux_2_28_ppc64le.whl", hash = "sha256:22a5cb272895dce158b2cacdfdc3debd299019659f42947dbdac6f32d68fe832", size = 5283582, upload-time = "2026-05-04T22:58:53.017Z" },
{ url = "https://files.pythonhosted.org/packages/02/e1/50edc7a50334807cc4791fc4a0ce7468b4a1416d9138eab358bfc9a3d70b/cryptography-48.0.0-cp39-abi3-manylinux_2_28_x86_64.whl", hash = "sha256:2b4d59804e8408e2fea7d1fbaf218e5ec984325221db76e6a241a9abd6cdd95c", size = 4730479, upload-time = "2026-05-04T22:58:55.611Z" },
{ url = "https://files.pythonhosted.org/packages/6f/af/99a582b1b1641ff5911ac559beb45097cf79efd4ead4657f578ef1af2d47/cryptography-48.0.0-cp39-abi3-manylinux_2_31_armv7l.whl", hash = "sha256:984a20b0f62a26f48a3396c72e4bc34c66e356d356bf370053066b3b6d54634a", size = 4326481, upload-time = "2026-05-04T22:58:57.607Z" },
{ url = "https://files.pythonhosted.org/packages/90/ee/89aa26a06ef0a7d7611788ffd571a7c50e368cc6a4d5eef8b4884e866edb/cryptography-48.0.0-cp39-abi3-manylinux_2_34_aarch64.whl", hash = "sha256:5a5ed8fde7a1d09376ca0b40e68cd59c69fe23b1f9768bd5824f54681626032a", size = 4688713, upload-time = "2026-05-04T22:59:00.077Z" },
{ url = "https://files.pythonhosted.org/packages/70/ba/bcb1b0bb7a33d4c7c0c4d4c7874b4a62ae4f56113a5f4baefa362dfb1f0f/cryptography-48.0.0-cp39-abi3-manylinux_2_34_ppc64le.whl", hash = "sha256:8cd666227ef7af430aa5914a9910e0ddd703e75f039cef0825cd0da71b6b711a", size = 5238165, upload-time = "2026-05-04T22:59:02.317Z" },
{ url = "https://files.pythonhosted.org/packages/c9/70/ca4003b1ce5ca3dc3186ada51908c8a9b9ff7d5cab83cc0d43ee14ec144f/cryptography-48.0.0-cp39-abi3-manylinux_2_34_x86_64.whl", hash = "sha256:9071196d81abc88b3516ac8cdfad32e2b66dd4a5393a8e68a961e9161ddc6239", size = 4729947, upload-time = "2026-05-04T22:59:05.255Z" },
{ url = "https://files.pythonhosted.org/packages/44/a0/4ec7cf774207905aef1a8d11c3750d5a1db805eb380ee4e16df317870128/cryptography-48.0.0-cp39-abi3-musllinux_1_2_aarch64.whl", hash = "sha256:1e2d54c8be6152856a36f0882ab231e70f8ec7f14e93cf87db8a2ed056bf160c", size = 4822059, upload-time = "2026-05-04T22:59:07.802Z" },
{ url = "https://files.pythonhosted.org/packages/1e/75/a2e55f99c16fcac7b5d6c1eb19ad8e00799854d6be5ca845f9259eae1681/cryptography-48.0.0-cp39-abi3-musllinux_1_2_x86_64.whl", hash = "sha256:a5da777e32ffed6f85a7b2b3f7c5cbc88c146bfcd0a1d7baf5fcc6c52ee35dd4", size = 4960575, upload-time = "2026-05-04T22:59:09.851Z" },
{ url = "https://files.pythonhosted.org/packages/b8/23/6e6f32143ab5d8b36ca848a502c4bcd477ae75b9e1677e3530d669062578/cryptography-48.0.0-cp39-abi3-win32.whl", hash = "sha256:77a2ccbbe917f6710e05ba9adaa25fb5075620bf3ea6fb751997875aff4ae4bd", size = 3279117, upload-time = "2026-05-04T22:59:12.019Z" },
{ url = "https://files.pythonhosted.org/packages/9d/9a/0fea98a70cf1749d41d738836f6349d97945f7c89433a259a6c2642eefeb/cryptography-48.0.0-cp39-abi3-win_amd64.whl", hash = "sha256:16cd65b9330583e4619939b3a3843eec1e6e789744bb01e7c7e2e62e33c239c8", size = 3792100, upload-time = "2026-05-04T22:59:14.884Z" },
{ url = "https://files.pythonhosted.org/packages/be/d2/024b5e06be9d44cb021fb0e1a03d34d63989cf56a0fe62f3dfbab695b9b4/cryptography-48.0.0-pp311-pypy311_pp73-macosx_11_0_arm64.whl", hash = "sha256:84cf79f0dc8b36ac5da873481716e87aef31fcfa0444f9e1d8b4b2cece142855", size = 3950391, upload-time = "2026-05-04T22:59:17.415Z" },
{ url = "https://files.pythonhosted.org/packages/bc/17/3861e17c56fa0fd37491a14a8673fdb77c57fc5693cafe745ea8b06dba75/cryptography-48.0.0-pp311-pypy311_pp73-manylinux_2_28_aarch64.whl", hash = "sha256:fdfef35d751d510fcef5252703621574364fec16418c4a1e5e1055248401054b", size = 4637126, upload-time = "2026-05-04T22:59:20.197Z" },
{ url = "https://files.pythonhosted.org/packages/f0/0a/7e226dbff530f21480727eb764973a7bff2b912f8e15cd4f129e71b56d1d/cryptography-48.0.0-pp311-pypy311_pp73-manylinux_2_28_x86_64.whl", hash = "sha256:0890f502ddf7d9c6426129c3f49f5c0a39278ed7cd6322c8755ffca6ee675a13", size = 4667270, upload-time = "2026-05-04T22:59:22.647Z" },
{ url = "https://files.pythonhosted.org/packages/3b/f2/5a72274ca9f1b2a8b44a662ee0bf1b435909deb473d6f97bcd035bcdbc71/cryptography-48.0.0-pp311-pypy311_pp73-manylinux_2_34_aarch64.whl", hash = "sha256:ecde28a596bead48b0cfd2a1b4416c3d43074c2d785e3a398d7ec1fc4d0f7fbb", size = 4636797, upload-time = "2026-05-04T22:59:24.912Z" },
{ url = "https://files.pythonhosted.org/packages/b4/e1/48cedb2fe63626e91ded1edad159e2a4fb8b6906c4425eb7749673077ce7/cryptography-48.0.0-pp311-pypy311_pp73-manylinux_2_34_x86_64.whl", hash = "sha256:4defde8685ae324a9eb9d818717e93b4638ef67070ac9bc15b8ca85f63048355", size = 4666800, upload-time = "2026-05-04T22:59:27.474Z" },
{ url = "https://files.pythonhosted.org/packages/a2/ca/7e8365deec19afb2b2c7be7c1c0aa8f99633b54e90c570999acda93260fc/cryptography-48.0.0-pp311-pypy311_pp73-win_amd64.whl", hash = "sha256:db63bf618e5dea46c07de12e900fe1cdd2541e6dc9dbae772a70b7d4d4765f6a", size = 3739536, upload-time = "2026-05-04T22:59:29.61Z" },
{ url = "https://files.pythonhosted.org/packages/1b/bc/ee4137cbbe105652c0ee4252792b78fc8e7afa4b8e61d9d5dc05a7f45731/cryptography-48.0.1-cp311-abi3-macosx_10_9_universal2.whl", hash = "sha256:3e4a1a3232eef2e6c732827d5722db29a0cc8b27af2a4d865b094cf954be9ca1", size = 8008324, upload-time = "2026-06-09T22:31:00.702Z" },
{ url = "https://files.pythonhosted.org/packages/d5/85/6379d42181bfc713094f081360fc5784d6c816b599d45e7f082502d173ce/cryptography-48.0.1-cp311-abi3-manylinux2014_aarch64.manylinux_2_17_aarch64.whl", hash = "sha256:32143b24adb918f078134e1e230f1eb8cc04886b92c28b5f0041aaf3e5699225", size = 4696243, upload-time = "2026-06-09T22:32:33.446Z" },
{ url = "https://files.pythonhosted.org/packages/9c/87/c85d147b53323c7eb4d850920c8901377323c2a0ff8d79c262d4fee89aa2/cryptography-48.0.1-cp311-abi3-manylinux2014_x86_64.manylinux_2_17_x86_64.whl", hash = "sha256:f0d27a5696721ef7a672b8c810f6aded391058e0b9486e63e6d93baf765da691", size = 4713235, upload-time = "2026-06-09T22:31:40.141Z" },
{ url = "https://files.pythonhosted.org/packages/79/58/67cbf8cf1ee7c54b439ca07bbecf8362c07afc11a3724fea70f745784add/cryptography-48.0.1-cp311-abi3-manylinux_2_28_aarch64.whl", hash = "sha256:eb86ce1af36fe65041b6db9a8bb064ee621a7e5fded0f80d475ec243477cd242", size = 4702323, upload-time = "2026-06-09T22:31:42.191Z" },
{ url = "https://files.pythonhosted.org/packages/89/c6/24266ac10c47f6cd2a865f4446062b466da1d1f10b27189eac00e61bf0c9/cryptography-48.0.1-cp311-abi3-manylinux_2_28_ppc64le.whl", hash = "sha256:b024e784ad6c077ee0147b35ea9cbfc1e34e1fd4c1dcca214c2794d73a12df08", size = 5300085, upload-time = "2026-06-09T22:31:58.703Z" },
{ url = "https://files.pythonhosted.org/packages/d2/bb/cc4b78784f97efc8c5874c2a9743708d172be6663024b34a0467885ae0c8/cryptography-48.0.1-cp311-abi3-manylinux_2_28_x86_64.whl", hash = "sha256:3752f2dbc8f07a30aad2932c986cea495b03bb554887828225da104f732852b6", size = 4746137, upload-time = "2026-06-09T22:31:31.01Z" },
{ url = "https://files.pythonhosted.org/packages/1f/52/0c44de3f5267f8fbe8e835138017522a333436166e406f0db9b9e6e3033f/cryptography-48.0.1-cp311-abi3-manylinux_2_31_armv7l.whl", hash = "sha256:bd81490cd5801d755cf97bb68ac191f14b708470b1c7cf4580f669b9c9264cd8", size = 4333867, upload-time = "2026-06-09T22:32:28.096Z" },
{ url = "https://files.pythonhosted.org/packages/9a/2e/772d7adbfa931537bc401640b7cac9976bff689bda187833e5d63b428e49/cryptography-48.0.1-cp311-abi3-manylinux_2_34_aarch64.whl", hash = "sha256:66fd0771e7b9c6dcd44cf1120690d2338d16d72795cf40cae2786a39eba65429", size = 4701805, upload-time = "2026-06-09T22:31:38.284Z" },
{ url = "https://files.pythonhosted.org/packages/f8/a3/b06844f303873493c963caf581c04df31c7035e0c1b0f02c4814d319ec80/cryptography-48.0.1-cp311-abi3-manylinux_2_34_ppc64le.whl", hash = "sha256:3fd2ca57062b241c856670b073487d2e86c4637937ca5601e48f97bf8e11fc8f", size = 5258461, upload-time = "2026-06-09T22:31:04.187Z" },
{ url = "https://files.pythonhosted.org/packages/9f/13/8b765e2e12b07c74941caadb9d1c8fdc006c4dfbf2b8f2d610519758954d/cryptography-48.0.1-cp311-abi3-manylinux_2_34_x86_64.whl", hash = "sha256:0ee6ea481db1ab889cba043ec1eda17bb9c1ea79db6722f779c3667f9f70322f", size = 4745488, upload-time = "2026-06-09T22:32:30.07Z" },
{ url = "https://files.pythonhosted.org/packages/2e/aa/48972bce55049b32a94f4907eda4d75fa385aad8a39506cc2fc72196ecf0/cryptography-48.0.1-cp311-abi3-musllinux_1_2_aarch64.whl", hash = "sha256:f2ceef93cb096aa3c4cc4b5c94ca6131f9196d28c64d6111533402a9b2054d41", size = 4830256, upload-time = "2026-06-09T22:31:43.868Z" },
{ url = "https://files.pythonhosted.org/packages/47/a2/e5079a032fb85cf6005046ca92bbd78b0c82dad2b5751ab8c311659da06f/cryptography-48.0.1-cp311-abi3-musllinux_1_2_x86_64.whl", hash = "sha256:9bd3f92d76217892b15df84ca256c2c113d386fdda7a7d8691aeeced976507c6", size = 4979117, upload-time = "2026-06-09T22:31:05.845Z" },
{ url = "https://files.pythonhosted.org/packages/b7/a0/8f50cae9c74e718ed769d63ed5c74bd0ea830c9550a74629cebd1b9c7bc7/cryptography-48.0.1-cp311-abi3-win32.whl", hash = "sha256:b9a32b876490d66c8bcc9963ef220199569748434ab01a9d6aaeabf88e7f5158", size = 3304154, upload-time = "2026-06-09T22:32:16.845Z" },
{ url = "https://files.pythonhosted.org/packages/c5/69/0572c77dbace6fef72f33755bd52ea399c71367250d366237f8691826b9e/cryptography-48.0.1-cp311-abi3-win_amd64.whl", hash = "sha256:39489bfca54c7a1f6b297efcd8bc608ab92d16c4ca631b0cad4da46724588b24", size = 3817138, upload-time = "2026-06-09T22:32:00.388Z" },
{ url = "https://files.pythonhosted.org/packages/42/06/3e768b4c3bc78201583fa35a0e18f640dd782ff41afba88f8545481a8874/cryptography-48.0.1-cp314-cp314t-macosx_10_9_universal2.whl", hash = "sha256:f817adc181390bd54f2f700107a7419040fb7c1bdf2fc26f36551a06a68c3345", size = 7989830, upload-time = "2026-06-09T22:31:07.8Z" },
{ url = "https://files.pythonhosted.org/packages/8a/13/6476736484b94041110c8340a3eb63962fea4975baea8cb4a512adb44d4d/cryptography-48.0.1-cp314-cp314t-manylinux2014_aarch64.manylinux_2_17_aarch64.whl", hash = "sha256:d5d30989c6917b478b5817902e85fddaea2261efa8648383d965381ccb9e1ac4", size = 4689201, upload-time = "2026-06-09T22:31:09.745Z" },
{ url = "https://files.pythonhosted.org/packages/79/62/65a87f34d2a431546e2509b85d55e8c90df86d668f6731da64d538512ac2/cryptography-48.0.1-cp314-cp314t-manylinux2014_x86_64.manylinux_2_17_x86_64.whl", hash = "sha256:df637c05205ea7c1d7fbcbe54bbfea648a52951155f997af13d895d0ecc96991", size = 4702822, upload-time = "2026-06-09T22:32:24.409Z" },
{ url = "https://files.pythonhosted.org/packages/7f/59/810b5204b0a9b10f4b6bc06bd551a8b609803cd931806bc3b71884b225e5/cryptography-48.0.1-cp314-cp314t-manylinux_2_28_aarch64.whl", hash = "sha256:869c3b8a53bfe27147832df48b32adadf558249d50e76cb3769d40e986b13265", size = 4694875, upload-time = "2026-06-09T22:32:08.737Z" },
{ url = "https://files.pythonhosted.org/packages/24/dc/d8ca05ffea724eec6d232ea6f18e74c269eb6bdfdcc9bfba689790d1325f/cryptography-48.0.1-cp314-cp314t-manylinux_2_28_ppc64le.whl", hash = "sha256:e361afba8918070d376df76f408a4f67fec0ee9cff81a99e48fe9a233ef59e17", size = 5290385, upload-time = "2026-06-09T22:31:15.212Z" },
{ url = "https://files.pythonhosted.org/packages/03/8c/3be6cb4da181f5bb6c19cf560c2359d60644a6b5fc5b57854e528f47b296/cryptography-48.0.1-cp314-cp314t-manylinux_2_28_x86_64.whl", hash = "sha256:d069066deead00ac7f090be101be875a06855908f7ec004c27b8fefb4acfb411", size = 4737082, upload-time = "2026-06-09T22:32:22.66Z" },
{ url = "https://files.pythonhosted.org/packages/aa/f6/d5f60a5a1434dbfd949e227fd0065d194c7e6b6ac526b17f5c06152b8231/cryptography-48.0.1-cp314-cp314t-manylinux_2_31_armv7l.whl", hash = "sha256:09f73a725d582cef64b91281a322cd798d14a33b2b6f2b7ad9531dc336d84c02", size = 4325328, upload-time = "2026-06-09T22:32:10.777Z" },
{ url = "https://files.pythonhosted.org/packages/17/b7/ba75dd947a14b6ad907b01ae8f6b5b348cdd1b48142f0063dee9e20c1d9d/cryptography-48.0.1-cp314-cp314t-manylinux_2_34_aarch64.whl", hash = "sha256:15254441469dd6bf027039453288e2072124f8b6603563f5d759e1c9b69273fa", size = 4694530, upload-time = "2026-06-09T22:31:53.105Z" },
{ url = "https://files.pythonhosted.org/packages/62/29/50d6b9e8aff12d8b67afaeb3569335e32dc83a5723e3bbded24fdac9f809/cryptography-48.0.1-cp314-cp314t-manylinux_2_34_ppc64le.whl", hash = "sha256:8ace4507d1e6533c125f4fac754f8bb8b6a74c08e92179dabd7e16571a3efbf3", size = 5245046, upload-time = "2026-06-09T22:31:25.774Z" },
{ url = "https://files.pythonhosted.org/packages/9f/04/618f4115cfc0add0838c82507aa18a346089428da8653ad38b3ff36f5cb3/cryptography-48.0.1-cp314-cp314t-manylinux_2_34_x86_64.whl", hash = "sha256:b4e391975f038e66432328639620a4aff2d307513b004f1ca06d6225bced815c", size = 4736660, upload-time = "2026-06-09T22:32:12.676Z" },
{ url = "https://files.pythonhosted.org/packages/24/9c/06e062462a0de28a3b3911322eded4c16deb9f441b1b7575d3dc59488ab5/cryptography-48.0.1-cp314-cp314t-musllinux_1_2_aarch64.whl", hash = "sha256:42fcd8e26fe555d9b3577a135f5091fefa0aa4e99129c23fb56787a1bd4ada72", size = 4822229, upload-time = "2026-06-09T22:31:17.062Z" },
{ url = "https://files.pythonhosted.org/packages/f4/be/0561971eaaee4b8a0e7d5113c536921063ab91aaf23278ac374eaf881e11/cryptography-48.0.1-cp314-cp314t-musllinux_1_2_x86_64.whl", hash = "sha256:c1400da5e32a43253392277eac7490a60e497d810a63dd5608d71bbd7af507c9", size = 4966364, upload-time = "2026-06-09T22:31:32.842Z" },
{ url = "https://files.pythonhosted.org/packages/a4/27/728c77876f12b000820b69ae490f3c4083775e79e07827e9e60be07ad209/cryptography-48.0.1-cp314-cp314t-win32.whl", hash = "sha256:0df56b056bc17c1b7d6821dfa65216e62bd232d8ab05eb3db44e71d235651471", size = 3278498, upload-time = "2026-06-09T22:31:29.154Z" },
{ url = "https://files.pythonhosted.org/packages/06/e3/79a612c6d7b1e6ee0edd43633d53035bec2cfb78c82b76f7864f39e36f34/cryptography-48.0.1-cp314-cp314t-win_amd64.whl", hash = "sha256:9de21387aa95e2a895823d0745b430bed4f33503ba9ab5e0b5311f33e37d66d2", size = 3798790, upload-time = "2026-06-09T22:31:56.697Z" },
{ url = "https://files.pythonhosted.org/packages/ca/6c/00fa2a95997164c8b2072ce327c23d4ab20809ccc323ea5fab91e53a4bba/cryptography-48.0.1-cp39-abi3-macosx_10_9_universal2.whl", hash = "sha256:4fdc69f8e4316bcf0c8c8ec1f26f285d12e8142d88d96c876a59a03be3f6ae67", size = 7987408, upload-time = "2026-06-09T22:32:20.777Z" },
{ url = "https://files.pythonhosted.org/packages/b0/d9/45f309a7e4e5f3f8f121d6d3be9e94024a7726ec598d6e08ae04edb2f04d/cryptography-48.0.1-cp39-abi3-manylinux2014_aarch64.manylinux_2_17_aarch64.whl", hash = "sha256:48fe40804d4caa2288f24e70ca8c64c42dd826da0ad7e4f1b41b2128d679e6c8", size = 4690196, upload-time = "2026-06-09T22:31:54.74Z" },
{ url = "https://files.pythonhosted.org/packages/5f/9f/a1bc8bcc798811b8527eb374bbccf30a3f3e806829d967118222bf1125eb/cryptography-48.0.1-cp39-abi3-manylinux2014_x86_64.manylinux_2_17_x86_64.whl", hash = "sha256:86be3b1b0b6bf09482fb50a979c508d2950ed95f5621ec77f4e385962006b83a", size = 4696782, upload-time = "2026-06-09T22:31:45.615Z" },
{ url = "https://files.pythonhosted.org/packages/66/c2/81a4fb4e4373c500bb526bc337ac5719dd31dd15b970b84a238168c6aa08/cryptography-48.0.1-cp39-abi3-manylinux_2_28_aarch64.whl", hash = "sha256:4ab0a343c807bbcd90c971cd1ecf072937cd01847a9e002bef88fb47ac6be577", size = 4696618, upload-time = "2026-06-09T22:31:11.564Z" },
{ url = "https://files.pythonhosted.org/packages/e5/0b/aa68b221dde92d09cb29a024ede17550ee21e77a404e59fc093c82bb51e1/cryptography-48.0.1-cp39-abi3-manylinux_2_28_ppc64le.whl", hash = "sha256:9621de99d2da096006b629979efd8ae7eb2d8b822488d0c89ee4000c306c59b1", size = 5289970, upload-time = "2026-06-09T22:31:20.368Z" },
{ url = "https://files.pythonhosted.org/packages/78/13/fba657f958d2af66ea959a4ba01212632089249d34af1ae48054136344d7/cryptography-48.0.1-cp39-abi3-manylinux_2_28_x86_64.whl", hash = "sha256:88c852a0ae366e262e5a1744b685e6a433dc8788dd2a277e418bf4904203609d", size = 4731873, upload-time = "2026-06-09T22:31:22.253Z" },
{ url = "https://files.pythonhosted.org/packages/4c/4c/9a964756d24a26b3e34dfcb16f961b89838786e6700b635b0d1e3adff4b6/cryptography-48.0.1-cp39-abi3-manylinux_2_31_armv7l.whl", hash = "sha256:43c5835e2cb98c8733d86f57d6fc879b613f5c3478607281c3e36daffc6dd8a6", size = 4330804, upload-time = "2026-06-09T22:31:36.56Z" },
{ url = "https://files.pythonhosted.org/packages/4b/0f/a10f3a6eb12950a10e3a874070283aa2dd5875b2bfd15fad8a3e17b3f13e/cryptography-48.0.1-cp39-abi3-manylinux_2_34_aarch64.whl", hash = "sha256:fe0180af5bf9236518a087e35bf2d9a347d5f5f51e63c579d683ddff424e3d46", size = 4696217, upload-time = "2026-06-09T22:31:13.351Z" },
{ url = "https://files.pythonhosted.org/packages/f3/6f/5cd12f951165ea73ef85266775d97e4c763b2474ccfd816dd69d3a18d6f8/cryptography-48.0.1-cp39-abi3-manylinux_2_34_ppc64le.whl", hash = "sha256:b7a2d1a937a738a881737cec135a38bb61470589b17515b9f73f571d0ae10401", size = 5245252, upload-time = "2026-06-09T22:32:02.193Z" },
{ url = "https://files.pythonhosted.org/packages/68/ab/8aaa12e4516ec4464033ab79b6f3b592bd5a92102467c4ace8a0d970203f/cryptography-48.0.1-cp39-abi3-manylinux_2_34_x86_64.whl", hash = "sha256:b74ca3b8e5ecdd833bf6a002ca41b4793bb27fb8f1c06ffaf2643c9e9140e31b", size = 4731388, upload-time = "2026-06-09T22:32:04.019Z" },
{ url = "https://files.pythonhosted.org/packages/1b/24/50027ea4dca85ec1f40688f3c24fb32ccacd520583c9592c3cc95628e6fb/cryptography-48.0.1-cp39-abi3-musllinux_1_2_aarch64.whl", hash = "sha256:2c37f2461406063b417837f5f3daab668652acd82423efcd7f0a9f04be972de1", size = 4824186, upload-time = "2026-06-09T22:32:18.707Z" },
{ url = "https://files.pythonhosted.org/packages/52/41/04cb5eb17085ade6f50cc611fb657df6a0f5885350de8764ece89c050197/cryptography-48.0.1-cp39-abi3-musllinux_1_2_x86_64.whl", hash = "sha256:86fe77abb1bd87afb251d4d02ada7ecf53a32cee9b67d976abb2e45a13297475", size = 4964539, upload-time = "2026-06-09T22:31:18.793Z" },
{ url = "https://files.pythonhosted.org/packages/36/bf/ed70785c496e89d7e73b7cda2d21f2447fd6d4e821714b8d04ff217fed92/cryptography-48.0.1-cp39-abi3-win32.whl", hash = "sha256:6b2c0c3e6ccf3ade7750f836ef3ee36eea250cc467d45c256895573ac08cc6f1", size = 3282307, upload-time = "2026-06-09T22:30:53.162Z" },
{ url = "https://files.pythonhosted.org/packages/b3/ff/371ea7d252656ee1eb6d83eeeef3d1d0c6baf1d6497687d081ea03814670/cryptography-48.0.1-cp39-abi3-win_amd64.whl", hash = "sha256:9a49ca6c81417f6a5edb50375a60cccdd70fa0a91a5211829dbea74eba94d2ac", size = 3793408, upload-time = "2026-06-09T22:32:15.191Z" },
{ url = "https://files.pythonhosted.org/packages/a9/d3/eb4e394e587341fdad09a09101fa76478ead3a78b0ad63e55c22f0d75c02/cryptography-48.0.1-pp311-pypy311_pp73-macosx_11_0_arm64.whl", hash = "sha256:08a597acce1ff37f347400087776599e2348a3a8bc53b44120e463cd274efe4a", size = 3951747, upload-time = "2026-06-09T22:31:23.871Z" },
{ url = "https://files.pythonhosted.org/packages/e0/4a/3f43451b4f858bfceaaaffc649e6e787e8d4fb332a1d443af39ab02cc8f1/cryptography-48.0.1-pp311-pypy311_pp73-manylinux_2_28_aarch64.whl", hash = "sha256:735824ec41b7f74a7c45fb1591349333e4c696cb6c044e5f46356e560143e4cd", size = 4641226, upload-time = "2026-06-09T22:31:02.532Z" },
{ url = "https://files.pythonhosted.org/packages/73/4e/855584c2c23b09e4ce2d3b9c30e983e679cd60b068c513c6bbdb91e11782/cryptography-48.0.1-pp311-pypy311_pp73-manylinux_2_28_x86_64.whl", hash = "sha256:92a46e1d638daa264ba2971c0b0489c9409787943efae4d60ffda3d091ef832c", size = 4668958, upload-time = "2026-06-09T22:32:06.213Z" },
{ url = "https://files.pythonhosted.org/packages/42/3b/d35750e41d803d1e516fd6d6011f065424924da7af1748cef4cc9cb3ede1/cryptography-48.0.1-pp311-pypy311_pp73-manylinux_2_34_aarch64.whl", hash = "sha256:7e234ac052af99f2700826a5c29ea99d9c1b1f80341cde62d11c8154dc8e0bd9", size = 4640793, upload-time = "2026-06-09T22:32:26.331Z" },
{ url = "https://files.pythonhosted.org/packages/ca/aa/cdb7181fe865285e87e96825aaab239400f1de0c3bfba9bd9769b79f1a92/cryptography-48.0.1-pp311-pypy311_pp73-manylinux_2_34_x86_64.whl", hash = "sha256:33842cf0888951cef5bc7ac724ab844a42044c1727b967b7f8997289a0464f92", size = 4668505, upload-time = "2026-06-09T22:31:27.534Z" },
{ url = "https://files.pythonhosted.org/packages/5d/8c/ce3823c06c2804f194f9e64f0d67fa3f4094a39f2bb1a990cd03603af8fc/cryptography-48.0.1-pp311-pypy311_pp73-win_amd64.whl", hash = "sha256:6184ca7b174f28d7c703f1290d4b297217c45355f77a98f67e9b7f14549ac54a", size = 3742204, upload-time = "2026-06-09T22:31:34.773Z" },
]
[[package]]
+18 -80
View File
@@ -26,38 +26,19 @@ logical host id остаётся `SHARKON2025`. Подробный post-restore
`653b22b0fbf29a22f7de42ade7b689490b1de16fa07e785e4e0efd3078e7a3bc`.
- Бэкап предыдущего binary на сервере:
`/usr/local/bin/detmir-portal.bak.20260625T045640Z`.
- Runtime mode после 2026-06-30 prod hardening:
server-side DLP runtime зафиксирован в `core_only/disabled`.
Portal DLP UI/API module может оставаться включённым для чтения исторического
SQLite/evidence-среза, но это не означает запуск DLP collectors/exporters.
- Runtime mode после phase 1 deploy:
`DETMIR_PORTAL_DLP_MODULE_ENABLED=false`.
- Server-side optional DLP runtime control:
`AW_DLP_ENABLED=false|true` и `DETMIR_DLP_ENABLED=false|true`.
- Current resource profile: `AW_DLP_ENABLED=false`,
`AW_DLP_PROFILE=core_only`; возврат в `light` выполняется только вручную
после проверки нагрузки.
- Runtime control/statistics script:
`scripts/detmir_dlp_runtime_control.sh` / live
`/usr/local/bin/detmir-dlp-runtime-control`.
- DLP runtime state after 2026-06-30 prod hardening:
`AW_DLP_ENABLED=false`, `AW_DLP_PROFILE=core_only`,
`AW_DLP_INFLUX_ENABLED=false`; optional DLP units should be
`inactive/disabled`. `detmir-dlp-load-guard.timer` remains enabled and active
as protection for any later operator re-enable.
- Live DLP runtime state after 2026-06-25 controlled disable:
`AW_DLP_ENABLED=false`, `AW_DLP_INFLUX_ENABLED=false`;
active/enabled DLP units: `0/0`.
- Reason: DLP runtime materially increases Proxmox VM/LXC, InfluxDB, Grafana,
ClickHouse and AW server load. In production DetMir the safe default is
`core_only`; `light` is a reconnectable profile, not the automatic default.
- Auto-disable guard:
`scripts/detmir_dlp_load_guard.sh` / live
`/usr/local/bin/detmir-dlp-load-guard`. При перегрузе переводит DLP в
`core_only` через runtime-control и пишет evidence в
`/var/lib/activitywatch/health/dlp-light-guard-state.json`.
- DLP warehouse sync для портала:
`scripts/detmir_dlp_warehouse_sync.sh` / live
`/usr/local/bin/detmir-dlp-warehouse-sync`. Доставляет локальный SQLite
snapshot на portal host для UEBA/DLP views без heavy DLP hot path.
- Loki CT is intentionally excluded from the current DetMir production resource
profile. It must not be returned by routine deploy/recovery while the goal is
to keep Proxmox VM/LXC load low.
ClickHouse and AW server load. In production DetMir it is currently kept
disabled, but remains a documented optional module that can be enabled later.
- Health после деплоя: `/healthz` возвращал `status=ok`.
- Readiness после деплоя: `/readyz` возвращал `status=ready`.
@@ -103,11 +84,9 @@ logical host id остаётся `SHARKON2025`. Подробный post-restore
- DLP evidence, screenshots, endpoint signals, case review и forensics
enrichment требуют больше CPU/IO/сетевых операций, чем Workforce core.
Вывод: DLP/evidence/forensics enrichment вынесен из обязательного hot path.
Phase 1 делал это через `DETMIR_PORTAL_DLP_MODULE_ENABLED=false`; текущий
lightweight-профиль оставляет DLP-status/UEBA-сигналы включенными без тяжелого
evidence/case/exporter path. Полная оптимизация тяжелого snapshot/prewarm
остается отдельной инженерной задачей.
Вывод: DLP/evidence/forensics enrichment уже вынесен из обязательного hot path
phase 1 через `DETMIR_PORTAL_DLP_MODULE_ENABLED=false`, но полная оптимизация
тяжелого snapshot/prewarm остается отдельной инженерной задачей.
## Целевая граница после переработки
@@ -175,45 +154,23 @@ AW_DLP_ENABLED=true|false
DETMIR_DLP_ENABLED=true|false
```
DetMir production default после 2026-06-30 hardening:
`AW_DLP_ENABLED=false` / `AW_DLP_PROFILE=core_only`. Portal DLP module may stay
enabled for historical/security views, but server-side DLP collectors/exporters
remain off. В этом режиме портал:
Default остается `true`, чтобы существующее поведение не менялось без явного
решения администратора. Для ускоренного Workforce/operator режима допускается
`DETMIR_PORTAL_DLP_MODULE_ENABLED=false`; в этом режиме портал:
- не читает DLP incident/case/review/audit файлы в основном report/operator
path;
- использует только уже имеющийся лёгкий DLP-срез для UEBA и статуса;
- не включает evidence/case/exporters/Loki/Influx-heavy path;
- не считает отсутствие heavy DLP ошибкой Workforce core.
- отключает security-events backend внутри snapshot, не меняя сохраненные
ClickHouse credentials;
- возвращает disabled-state для DLP evidence API;
- не считает отсутствие DLP ошибкой Workforce core.
Ansible-параметр поставки для старого disabled-профиля:
Ansible-параметр поставки:
```yaml
detmir_portal_dlp_module_enabled_override: false
```
Для текущего safe production профиля:
```yaml
detmir_portal_dlp_module_enabled_override: true
aw_dlp_profile: "core_only"
aw_dlp_enabled: false
aw_dlp_influx_enabled: false
aw_dlp_light_collector_enabled: false
aw_dlp_light_guard_enabled: true
```
Возврат в `light` выполняется только после resource check:
```bash
sudo AW_DLP_DISABLED_REASON=operator_reenable_after_resource_check \
/usr/local/bin/detmir-dlp-runtime-control set-profile light
sudo sed -i \
-e 's/^AW_DLP_ENABLED=.*/AW_DLP_ENABLED=true/' \
-e 's/^AW_DLP_PROFILE=.*/AW_DLP_PROFILE=light/' \
/etc/activitywatch/aw-server.env
```
Отдельный `detmir-portal-evidence` сервис не отключается этим флагом и остается
самостоятельным контуром evidence/API при наличии отдельной конфигурации.
@@ -232,7 +189,6 @@ Hayabusa/Velociraptor boundary:
Server-side optional DLP runtime описан отдельно:
- [DLP_OPTIONAL_RUNTIME_RU.md](DLP_OPTIONAL_RUNTIME_RU.md).
- [DLP_RESOURCE_PROFILES_RU.md](DLP_RESOURCE_PROFILES_RU.md).
При `AW_DLP_ENABLED=false`:
@@ -241,27 +197,10 @@ Server-side optional DLP runtime описан отдельно:
- `detmir-check`, `check-aw-full` и `check-aw-data` не считают DLP buckets
обязательными;
- `detmir-readiness` не требует DLP Influx write и DLP systemd units;
- DLP profile changes use
`/usr/local/bin/detmir-dlp-runtime-control set-profile <profile>` and keep a
rollback snapshot for `/usr/local/bin/detmir-dlp-runtime-control rollback`;
- перед отключением и после отключения собираются JSON-срезы в
`/var/lib/activitywatch/health/dlp-runtime-history/`, latest-срез остается в
`/var/lib/activitywatch/health/dlp-runtime-state.json`.
При `AW_DLP_PROFILE=light`:
- `activitywatch-dlp-aggregator.timer` собирает только ограниченный набор DLP
events в локальный SQLite warehouse;
- `detmir-dlp-warehouse-sync.timer` доставляет этот warehouse на portal host
атомарным snapshot;
- UEBA может учитывать `dlp_warn`/`dlp_fail` без запуска Loki/Influx-heavy path;
- `detmir-dlp-load-guard.timer` автоматически переводит профиль в `core_only`
при превышении порогов load/RAM/iowait;
- тяжёлые DLP units (`aw-dlp-influx-exporter`, report/syslog/webhook/CEF,
policy engine, case management, evidence API) должны оставаться выключенными.
- если `detmir-dlp-load-guard.timer` видит повторный перегруз, он автоматически
возвращает DLP runtime в `core_only`.
Live disable evidence 2026-06-25:
- `dlp-health-check` returned `ok=true`, `dlp:mode=disabled`;
@@ -368,7 +307,6 @@ curl -sS --max-time 5 http://10.10.10.2:8720/healthz
- Не удалять DLP collectors и warehouse ради ускорения портала.
- Не включать heavy DLP или Velociraptor server runtime автоматически при
обычном deploy без ресурсного решения.
- Не включать Loki CT автоматически при обычном deploy/recovery DetMir.
- Не менять UI/API несовместимо: новые поля должны быть additive.
- Не заявлять completed DLP decoupling до live deploy и browser/API smoke.
- Не позиционировать AWatch-rus как сертифицированную DLP/SIEM/EDR/СЗИ.
+9 -67
View File
@@ -1,37 +1,14 @@
# Optional DLP runtime for DetMir
Цель: DLP-контур должен оставаться подключаемым, но production default для
DetMir сейчас `core_only/disabled`. Возврат в лёгкий режим выполняется вручную
после resource check; при перегрузе guard снова переводит DLP в `core_only`.
Ресурсные профили и rollback-процедура описаны отдельно:
[DLP_RESOURCE_PROFILES_RU.md](DLP_RESOURCE_PROFILES_RU.md).
Цель: DLP-контур должен отключаться управляемо, без ложных аварий в health/readiness и без автоматического подъема heavy-пайплайна, когда задача контура - снизить нагрузку на InfluxDB, Grafana и ClickHouse.
## Что отключается
Текущий production-профиль DetMir после 2026-06-30 prod hardening -
`core_only/disabled`:
- `AW_DLP_ENABLED=false`;
- `AW_DLP_PROFILE=core_only`;
- `AW_DLP_INFLUX_ENABLED=false`;
- optional DLP timers/services inactive/disabled;
- `detmir-dlp-load-guard.timer` остаётся enabled/active как защита на случай
последующего operator re-enable;
- heavy DLP units, Influx exporter, evidence/case/report/integration units и
Loki остаются выключенными.
Автоотключение выполняет `detmir-dlp-load-guard`: при превышении порогов
load/RAM/iowait он переводит DLP в `core_only` через
`detmir-dlp-runtime-control set-profile core_only`. После стабилизации контур
возвращается вручную командой `set-profile light`.
Штатный runtime off включает:
- `AW_DLP_ENABLED=false` на AW server;
- `DETMIR_DLP_ENABLED=false` в управляющем DetMir contour check;
- portal UI/API DLP-модуль может оставаться включённым для исторического
SQLite/evidence-среза; это не запускает server-side DLP runtime;
- `DETMIR_PORTAL_DLP_MODULE_ENABLED=false` для portal UI/API DLP-модуля;
- остановку DLP timers/services:
- `aw-dlp-influx-exporter.timer`;
- `activitywatch-dlp-aggregator.timer`;
@@ -160,31 +137,10 @@ AW_DLP_ENABLED=false check-aw-full
## Возврат DLP
Для DetMir предпочтительно возвращать не весь DLP сразу, а лёгкий профиль.
Перед этим проверить load/RAM/iowait на Proxmox/AW/Influx/Grafana/ClickHouse.
```bash
sudo AW_DLP_DISABLED_REASON=operator_reenable_after_resource_check \
/usr/local/bin/detmir-dlp-runtime-control set-profile light
sudo sed -i \
-e 's/^AW_DLP_ENABLED=.*/AW_DLP_ENABLED=true/' \
-e 's/^AW_DLP_PROFILE=.*/AW_DLP_PROFILE=light/' \
-e 's/^AW_DLP_INFLUX_ENABLED=.*/AW_DLP_INFLUX_ENABLED=false/' \
/etc/activitywatch/aw-server.env
```
Если профиль ухудшил состояние контура:
```bash
sudo /usr/local/bin/detmir-dlp-runtime-control rollback
```
`on_demand` и `full` включаются только вручную после отдельного resource
preflight:
```bash
sudo /usr/local/bin/detmir-dlp-runtime-control set-profile on_demand
sudo /usr/local/bin/detmir-dlp-runtime-control set-profile full
sudo sed -i 's/^AW_DLP_ENABLED=.*/AW_DLP_ENABLED=true/' /etc/activitywatch/aw-server.env
sudo /usr/local/bin/detmir-dlp-runtime-control enable
sudo systemctl restart aw-worktime-api.service || true
```
Для portal:
@@ -231,27 +187,13 @@ production DetMir без отдельного ресурсного решени
В inventory/group vars:
```yaml
aw_dlp_profile: "core_only"
aw_dlp_enabled: false
aw_dlp_influx_enabled: false
aw_dlp_light_collector_enabled: false
aw_dlp_light_guard_enabled: true
detmir_portal_dlp_module_enabled_override: true
aw_dlp_disabled_reason: "operator_disabled_to_reduce_influx_grafana_clickhouse_load"
aw_dlp_disabled_since: "2026-06-25"
detmir_portal_dlp_module_enabled_override: false
```
Для временного operator re-enable в `light`:
```yaml
aw_dlp_profile: "light"
aw_dlp_enabled: true
aw_dlp_influx_enabled: false
aw_dlp_light_collector_enabled: true
aw_dlp_light_guard_enabled: true
```
При `aw_dlp_profile: light` playbook включает только лёгкий агрегатор, IOC
refresh и load guard. DLP Influx exporter, report/syslog/webhook/CEF,
policy/case/evidence и Loki не должны возвращаться в active state.
При `aw_dlp_enabled: false` playbook пишет `AW_DLP_ENABLED=false`, не включает DLP service/timer runtime и не должен возвращать DLP Influx exporter/aggregator в active state.
## Ограничения
-196
View File
@@ -1,196 +0,0 @@
# DLP resource profiles for DetMir
Дата фиксации: 2026-06-30.
Цель: сохранить стабильный Workforce/AW hot path на малом DetMir Proxmox
контуре и оставить DLP подключаемым модулем. Loki CT в текущем production
resource profile отключен намеренно и не является обязательной зависимостью
AWatch-rus.
## Профили
### `core_only`
Production default и аварийный/экономный профиль для DetMir.
- DLP runtime: выключен.
- DLP Influx exporter: выключен.
- DLP aggregators/report/syslog/webhook/CEF/case/evidence units: выключены.
- Loki/Promtail: выключены.
- Workforce, Worktime, ActivityWatch, ClickHouse 1C, Grafana core,
Hayabusa/Security Finding Inbox: работают независимо от DLP.
Назначение: безопасное состояние при перегрузе CPU/RAM/IOPS или при ручном
отключении DLP.
### `light`
Операторский re-enable профиль для DetMir после проверки ресурсов: лёгкий DLP
режим без Loki и без Influx-heavy path.
- Разрешены `activitywatch-dlp-aggregator.timer` и
`aw-dlp-ioc-refresh.timer`.
- `dlp-aggregator-rust` собирает ограниченный срез из bucket-ов
`aw-file-operations_` и `aw-dlp-incidents_` в локальный
`dlp_warehouse.sqlite` для последующей UEBA-корреляции.
- `detmir-dlp-warehouse-sync.timer` доставляет SQLite warehouse на portal host
через атомарный snapshot, чтобы DetMir Portal/UEBA читали локальный файл, а
не блокировали AW server hot path.
- Для агрегатора заданы короткий lookback, малый event limit, timeout,
`CPUQuota` и `MemoryMax`.
- Evidence, screenshots, case management и exporters остаются выключенными.
- InfluxDB/Grafana/Loki не участвуют в hot path лёгкого DLP.
- Используется для ежедневной эксплуатации, когда нужны DLP-сигналы для UEBA,
но нельзя нагружать Proxmox/Influx/Grafana/ClickHouse.
### `on_demand`
Временный режим для конкретного инцидента или окна проверки.
- Разрешены IOC refresh, policy engine, case management и evidence API.
- Influx exporter, CEF/syslog/webhook/report scheduler и aggregator остаются
выключенными, если администратор отдельно не выбрал `full`.
- После окна проверки профиль должен быть возвращён в `core_only`.
### `full`
Только вручную, только после resource preflight.
- Может включать DLP Influx exporter, aggregator, reports, integrations,
policy/case и evidence.
- На DetMir не является штатным production режимом.
- Запрещено включать автоматически при обычном deploy/recovery.
## Управление
На AW server:
```bash
sudo /usr/local/bin/detmir-dlp-runtime-control status
sudo /usr/local/bin/detmir-dlp-runtime-control set-profile core_only
sudo /usr/local/bin/detmir-dlp-runtime-control set-profile light
sudo /usr/local/bin/detmir-dlp-runtime-control set-profile on_demand
sudo /usr/local/bin/detmir-dlp-runtime-control set-profile full
sudo /usr/local/bin/detmir-dlp-load-guard
```
Перед каждым `set-profile` скрипт сохраняет rollback-снимок active/enabled
состояния DLP units:
```text
/var/lib/activitywatch/health/dlp-runtime-rollback.state
```
Откат к предыдущему состоянию:
```bash
sudo /usr/local/bin/detmir-dlp-runtime-control rollback
```
Важно: rollback восстанавливает только systemd active/enabled состояния DLP
units. Он не меняет retention, не удаляет данные и не включает Loki CT.
## Автоотключение при перегрузе
`detmir-dlp-load-guard.timer` запускает
`/usr/local/bin/detmir-dlp-load-guard`. Guard читает `/proc/loadavg`,
`/proc/meminfo` и `/proc/stat`; если load, свободная память или iowait выходят
за пороги несколько запусков подряд (`AW_DLP_GUARD_STRIKES_REQUIRED`, default
`3`), а DLP units активны, он переводит DLP в `core_only` через:
```bash
AW_DLP_DISABLED_REASON=auto_disabled_by_dlp_load_guard:<reason> \
/usr/local/bin/detmir-dlp-runtime-control set-profile core_only
```
State и история пишутся в:
```text
/var/lib/activitywatch/health/dlp-light-guard-state.json
/var/lib/activitywatch/health/dlp-light-guard-history/
```
Единичный IO/load spike фиксируется как `observe_overload`, но DLP не
отключается до достижения порога подряд. Guard не перезапускает
ActivityWatch/портал, не меняет маршруты, не трогает ClickHouse/Grafana и не
включает Loki. Возврат из `core_only` в `light` делает администратор после
стабилизации контура и проверки Proxmox/AW/Influx/Grafana/ClickHouse load. Если
перегруз повторится, guard снова переведёт профиль в `core_only`.
## Доставка DLP warehouse на портал
Portal читает DLP-срез из локального
`/var/lib/activitywatch/dlp_warehouse.sqlite`. На разнесённом контуре DetMir
этот файл создаётся на AW server, поэтому используется лёгкий sync:
```bash
sudo systemctl start detmir-dlp-warehouse-sync.service
sudo systemctl status detmir-dlp-warehouse-sync.timer
sudo jq . /var/lib/activitywatch/health/dlp-warehouse-sync-state.json
```
Sync делает SQLite backup на AW server и атомарно заменяет локальный файл на
portal host. Он не запускает DLP evidence/case/exporters и не включает Loki.
## Ansible defaults
Для DetMir production defaults должны оставаться экономными и
самозащищающимися:
```yaml
aw_dlp_profile: "core_only"
aw_dlp_enabled: false
aw_dlp_influx_enabled: false
aw_dlp_light_collector_enabled: false
aw_dlp_light_guard_enabled: true
detmir_portal_dlp_profile: "core_only"
detmir_portal_dlp_module_enabled_override: true
```
Для временного возврата в лёгкий профиль:
```yaml
aw_dlp_profile: "light"
aw_dlp_enabled: true
aw_dlp_influx_enabled: false
aw_dlp_light_collector_enabled: true
aw_dlp_light_guard_enabled: true
detmir_portal_dlp_profile: "light"
detmir_portal_dlp_module_enabled_override: true
```
Все тяжёлые DLP component flags должны быть `false`, пока администратор явно не
выбрал `on_demand` или `full`.
## Resource preflight перед `full`
Перед временным включением `full` проверить:
- Proxmox host load и steal/wait;
- свободную RAM и swap pressure;
- IOPS/latency storage;
- ClickHouse health и backlog ingest;
- InfluxDB/Grafana health, если они участвуют в выбранном профиле;
- ActivityWatch `/healthz`, Worktime API и portal latency;
- отсутствие старого Loki CT в autostart.
Если любой core-сервис деградирует, DLP возвращается в `core_only`.
## Проверка
```bash
DETMIR_RESILIENCE_EXPECT_DLP_PROFILE=light \
DETMIR_RESILIENCE_EXPECT_LOKI_OFF=1 \
scripts/detmir_resilience_check.sh --repo
```
Live check на сервере в `light` должен показывать inactive для heavy DLP units
и Loki units. В `core_only` inactive должны быть все optional DLP units.
## Запрещённые утверждения
- Не заявлять, что AWatch-rus заменяет DLP/SIEM/EDR.
- Не заявлять, что Loki обязателен для DetMir production.
- Не заявлять DLP health OK, если DLP выключен.
- Не запускать автоматическое блокирование рабочих станций без approve/apply
workflow.
-17
View File
@@ -47,8 +47,6 @@ bounded payload/query limits и role-gate smoke.
| `--slow-request-log-ms` | `AWATCH_PORTAL_SLOW_REQUEST_LOG_MS` | Порог медленного запроса для логов |
| `--environment` | `AWATCH_PORTAL_ENVIRONMENT` | Безопасное имя окружения |
| `--enabled-modules` | `AWATCH_PORTAL_ENABLED_MODULES` | Разрешенные модули портала |
| `--dlp-module-enabled` | `DETMIR_PORTAL_DLP_MODULE_ENABLED` | Включает DLP/security status для портала; может оставаться `true` для исторического SQLite/evidence-среза без запуска server-side DLP runtime |
| DLP resource profile | `AW_DLP_PROFILE`, `DETMIR_PORTAL_DLP_PROFILE` | Для DetMir production default `core_only`; `light` включается оператором после resource check |
Ограничения применяются к тяжелым API:
@@ -68,21 +66,6 @@ bounded payload/query limits и role-gate smoke.
возвращает `400`;
- слишком большое тело запроса возвращает `413`;
- role gate возвращает `403`.
- при `DETMIR_PORTAL_DLP_MODULE_ENABLED=true` и `AW_DLP_PROFILE=core_only`
портал может показывать исторический DLP/security status без запуска
collectors/exporters.
- при `DETMIR_PORTAL_DLP_MODULE_ENABLED=true` и `AW_DLP_PROFILE=light`
Workforce core, `/healthz`, `/readyz`, `/api/reports` и `/api/operator`
должны оставаться доступными без тяжелого DLP/case/evidence чтения.
- при `AW_DLP_ENABLED=false` и `DETMIR_DLP_ENABLED=false` server-side
DLP health/readiness/checks должны возвращать контролируемый disabled-state,
а не пытаться поднять DLP Influx/exporter/aggregator/case runtime.
Runbook: [DLP_OPTIONAL_RUNTIME_RU.md](DLP_OPTIONAL_RUNTIME_RU.md).
- при `AW_DLP_PROFILE=light` активны только lightweight collector/IOC/guard;
Loki/DLP heavy runtime должен оставаться inactive. При перегрузе
`detmir-dlp-load-guard` переводит DLP в `core_only`; возврат выполняется
только через profile switch и rollback, см.
[DLP_RESOURCE_PROFILES_RU.md](DLP_RESOURCE_PROFILES_RU.md).
### Request ID, logs и metrics
+17 -22
View File
@@ -66,25 +66,23 @@ backup, registry-readiness документации, плана российск
`653b22b0fbf29a22f7de42ade7b689490b1de16fa07e785e4e0efd3078e7a3bc`.
- DetMir portal cold-start UI hang: mitigated. During cold/prewarm state the UI
now shows `STALE / Первичный срез прогревается`, not endless loading.
- DetMir DLP hot-path boundary: phase 1 deployed; current production runtime
uses `AW_DLP_ENABLED=false`, `AW_DLP_PROFILE=core_only`. The portal DLP module
may stay enabled for historical/security views, but server-side DLP
collectors/exporters are off.
- DetMir DLP hot-path boundary: phase 1 deployed on the portal service with
`DETMIR_PORTAL_DLP_MODULE_ENABLED=false`.
- DetMir optional DLP runtime controls: implemented in code/docs through
`AW_DLP_ENABLED`, `DETMIR_DLP_ENABLED`,
`scripts/detmir_dlp_runtime_control.sh` and
`docs/DLP_OPTIONAL_RUNTIME_RU.md`. Resource profiles
`core_only|light|on_demand|full` and rollback are documented in
`docs/DLP_RESOURCE_PROFILES_RU.md`.
- DetMir optional DLP runtime state: 2026-06-25 controlled disable evidence is
retained; 2026-06-30 prod hardening keeps production in `core_only` by
default. `light` can be re-enabled by operator command after
Proxmox/InfluxDB/Grafana/ClickHouse capacity check.
- DetMir DLP contour status: server-side DLP collection is currently disabled;
heavy DLP remains optional and must only be enabled after explicit operator
decision and resource check.
- DetMir DLP auto-disable guard: `detmir-dlp-load-guard` records load/RAM/iowait
state and switches DLP to `core_only` if thresholds are exceeded.
`docs/DLP_OPTIONAL_RUNTIME_RU.md`.
- DetMir optional DLP runtime live state: disabled on 2026-06-25 to reduce
InfluxDB/Grafana/ClickHouse/AW server load. Evidence:
`dlp-health-check=dlp:mode disabled`, `detmir-dlp=dlp:mode disabled`,
active/enabled DLP units `0/0`, history snapshots under
`/var/lib/activitywatch/health/dlp-runtime-history/`.
- DetMir DLP contour status: disabled for the current production resource
profile, not removed. It remains a documented optional module and must only be
re-enabled after explicit operator decision and Proxmox/InfluxDB/Grafana/
ClickHouse capacity check.
- DetMir DLP buckets in manual full check: `SKIPPED` under
`AW_DLP_ENABLED=false`, not reported as dead.
- DetMir RDP collector freshness after 2026-06-29 restore: physical RDP target
is `192.168.100.19`, stable AW logical host id remains `SHARKON2025`.
Buckets are fresh/inactive as expected, collector guard quarantine was reset,
@@ -114,9 +112,6 @@ backup, registry-readiness документации, плана российск
resource usage. Proxmox LXC `202 loki-logs` is stopped, active config has
`onboot: 0`, and smoke checks skip Loki by default unless
`AW_SMOKE_LOKI_ENABLED=1` is set.
- DetMir DLP rollback guard: `detmir-dlp-runtime-control set-profile` stores
the previous DLP systemd active/enabled state and `rollback` restores it.
Rollback does not start Loki CT.
- DetMir restore baseline 2026-06-29:
`docs/DETMIR_RESTORE_BASELINE_2026-06-29_RU.md`.
- DetMir API smoke after phase 1: `/healthz` and `/readyz` OK;
@@ -202,9 +197,9 @@ backup, registry-readiness документации, плана российск
- External peer review remains pending.
- Community adoption remains low until external contributors, public reviews
and sustained third-party activity appear.
- DetMir lightweight DLP profile is implemented in repo defaults/scripts/docs;
heavy DLP modularization and retention/cleanup policy remain separate future
work.
- DetMir DLP runtime disable is complete for the current live contour; deeper
long-term DLP product modularization and retention/cleanup policy remain
separate future work.
- DetMir RDP collector/session recovery after 2026-06-29 restore is verified by
live smoke: `check-aw-full` reports `FRESH=8 STALE=0 DEAD=0`.
+1 -1
View File
@@ -342,7 +342,7 @@
"id": 7,
"targets": [
{
"query": "import \"date\"\nimport \"strings\"\nimport \"timezone\"\noption location = timezone.location(name: \"Europe/Moscow\")\ntoday = strings.substring(v: string(v: date.add(d: 3h, to: date.truncate(t: now(), unit: 1d))), start: 0, end: 10)\nfrom(bucket: \"aw_metrics\")\n |> range(start: -3d)\n |> filter(fn: (r) => r._measurement == \"aw_true_active_app_daily\" and r.host == \"${host}\" and r.report_date == today)\n |> filter(fn: (r) => r._field == \"proved_work_seconds\" or r._field == \"evidence_events\" or r._field == \"last_action\" or r._field == \"last_action_local\")\n |> group(columns:[\"application\",\"report_date\",\"_field\"])\n |> last()\n |> keep(columns:[\"application\",\"report_date\",\"_field\",\"_value\"])\n |> map(fn:(r)=>({ r with _value: string(v:r._value) }))\n |> group()\n |> pivot(rowKey:[\"application\",\"report_date\"], columnKey:[\"_field\"], valueColumn:\"_value\")\n |> map(fn:(r)=>({ r with hours: float(v:r.proved_work_seconds) / 3600.0 }))\n |> sort(columns:[\"hours\"], desc:true)\n |> group()\n |> keep(columns:[\"report_date\",\"application\",\"hours\",\"last_action_local\",\"last_action\",\"evidence_events\"])\n |> rename(columns:{report_date:\"Дата\", application:\"Приложение\", hours:\"Доказано, ч\", last_action_local:\"Последнее действие\", last_action:\"Окно / действие\", evidence_events:\"Подтверждений\"})\n",
"query": "import \"date\"\nimport \"strings\"\nimport \"timezone\"\noption location = timezone.location(name: \"Europe/Moscow\")\ntoday = strings.substring(v: string(v: date.add(d: 3h, to: date.truncate(t: now(), unit: 1d))), start: 0, end: 10)\nbase = from(bucket: \"aw_metrics\")\n |> range(start: -3d)\n |> filter(fn: (r) => r._measurement == \"aw_true_active_app_daily\" and r.host == \"${host}\" and r.report_date == today)\n\nnums = base\n |> filter(fn: (r) => r._field == \"proved_work_seconds\" or r._field == \"evidence_events\")\n |> group(columns:[\"application\",\"_field\"])\n |> last()\n |> group()\n |> pivot(rowKey:[\"application\",\"report_date\"], columnKey:[\"_field\"], valueColumn:\"_value\")\n\ntexts = base\n |> filter(fn: (r) => r._field == \"last_action\" or r._field == \"last_action_local\")\n |> group(columns:[\"application\",\"_field\"])\n |> last()\n |> group()\n |> pivot(rowKey:[\"application\",\"report_date\"], columnKey:[\"_field\"], valueColumn:\"_value\")\n\njoin(tables: {n: nums, t: texts}, on: [\"application\", \"report_date\"])\n |> map(fn:(r)=>({ r with hours: float(v:r.proved_work_seconds) / 3600.0 }))\n |> sort(columns:[\"proved_work_seconds\"], desc:true)\n |> group()\n |> keep(columns:[\"report_date\",\"application\",\"hours\",\"last_action_local\",\"last_action\",\"evidence_events\"])\n |> rename(columns:{report_date:\"Дата\", application:\"Приложение\", hours:\"Доказано, ч\", last_action_local:\"Последнее действие\", last_action:\"Окно / действие\", evidence_events:\"Подтверждений\"})\n",
"refId": "A"
}
],
@@ -630,7 +630,7 @@
},
"targets": [
{
"query": "import \"date\"\nimport \"strings\"\nimport \"timezone\"\noption location = timezone.location(name: \"Europe/Moscow\")\ntoday = strings.substring(v: string(v: date.add(d: 3h, to: date.truncate(t: now(), unit: 1d))), start: 0, end: 10)\nfrom(bucket: \"aw_metrics\")\n |> range(start: -3d)\n |> filter(fn: (r) => r._measurement == \"aw_true_active_app_daily\" and r.host == \"${host}\" and r.report_date == today)\n |> filter(fn: (r) => r._field == \"proved_work_seconds\" or r._field == \"evidence_events\" or r._field == \"last_action\" or r._field == \"last_action_local\")\n |> group(columns:[\"application\",\"report_date\",\"_field\"])\n |> last()\n |> keep(columns:[\"application\",\"report_date\",\"_field\",\"_value\"])\n |> map(fn:(r)=>({ r with _value: string(v:r._value) }))\n |> group()\n |> pivot(rowKey:[\"application\",\"report_date\"], columnKey:[\"_field\"], valueColumn:\"_value\")\n |> map(fn:(r)=>({ r with hours: float(v:r.proved_work_seconds) / 3600.0 }))\n |> sort(columns:[\"hours\"], desc:true)\n |> group()\n |> keep(columns:[\"report_date\",\"application\",\"hours\",\"last_action_local\",\"last_action\",\"evidence_events\"])\n |> rename(columns:{report_date:\"Дата\", application:\"Приложение\", hours:\"Доказано, ч\", last_action_local:\"Последнее действие\", last_action:\"Окно / действие\", evidence_events:\"Подтверждений\"})",
"query": "import \"date\"\nimport \"strings\"\nimport \"timezone\"\noption location = timezone.location(name: \"Europe/Moscow\")\ntoday = strings.substring(v: string(v: date.add(d: 3h, to: date.truncate(t: now(), unit: 1d))), start: 0, end: 10)\nbase = from(bucket: \"aw_metrics\")\n |> range(start: -3d)\n |> filter(fn: (r) => r._measurement == \"aw_true_active_app_daily\" and r.host == \"${host}\" and r.report_date == today)\n\nnums = base\n |> filter(fn: (r) => r._field == \"proved_work_seconds\" or r._field == \"evidence_events\")\n |> group(columns:[\"application\",\"_field\"])\n |> last()\n |> group()\n |> pivot(rowKey:[\"application\",\"report_date\"], columnKey:[\"_field\"], valueColumn:\"_value\")\n\ntexts = base\n |> filter(fn: (r) => r._field == \"last_action\" or r._field == \"last_action_local\")\n |> group(columns:[\"application\",\"_field\"])\n |> last()\n |> group()\n |> pivot(rowKey:[\"application\",\"report_date\"], columnKey:[\"_field\"], valueColumn:\"_value\")\n\njoin(tables: {n: nums, t: texts}, on: [\"application\", \"report_date\"])\n |> map(fn:(r)=>({ r with hours: float(v:r.proved_work_seconds) / 3600.0 }))\n |> sort(columns:[\"proved_work_seconds\"], desc:true)\n |> group()\n |> keep(columns:[\"report_date\",\"application\",\"hours\",\"last_action_local\",\"last_action\",\"evidence_events\"])\n |> rename(columns:{report_date:\"Дата\", application:\"Приложение\", hours:\"Доказано, ч\", last_action_local:\"Последнее действие\", last_action:\"Окно / действие\", evidence_events:\"Подтверждений\"})",
"refId": "A"
}
],
+3 -43
View File
@@ -4,33 +4,8 @@ set -euo pipefail
ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
TARGET_ROOT="${CARGO_TARGET_DIR:-$ROOT_DIR/adk-rust/target}"
RELEASE_DIR="$TARGET_ROOT/release"
SCOPE="${CHECK_DETMIR_RUST_RELEASE_SCOPE:-prod-runtime}"
prod_runtime_bins=(
aw-1c-ingest
aw-hayabusa-autoprocess-rust
aw-rus-healthd
aw-slo-monitor
aw-workforce-ingest
detmir-auto
detmir-portal
detmir-readiness
dlp-aggregator
dlp-case-management
dlp-cef-exporter
dlp-compliance
dlp-influx-exporter
dlp-policy-engine
dlp-syslog-forwarder
dlp-webhook-sender
worktime-api
worktime-autoheal
worktime-influx-exporter
worktime-prewarm
worktime-ui-bridge
)
workspace_bins=(
required_bins=(
detmir-status
detmir-adk-status
detmir-check
@@ -86,23 +61,8 @@ workspace_bins=(
aw-hayabusa-from-windows-rust
aw-hayabusa-autoprocess-rust
aw-1c-ingest
containment-engine
security-finding-inbox
)
case "$SCOPE" in
prod-runtime)
required_bins=("${prod_runtime_bins[@]}")
;;
workspace)
required_bins=("${workspace_bins[@]}")
;;
*)
echo "Unsupported CHECK_DETMIR_RUST_RELEASE_SCOPE=$SCOPE; expected prod-runtime or workspace" >&2
exit 2
;;
esac
missing=0
for bin in "${required_bins[@]}"; do
if [[ -x "$RELEASE_DIR/$bin" ]]; then
@@ -116,7 +76,7 @@ done
if (( missing != 0 )); then
cat >&2 <<EOF
Missing DetMir Rust release artifacts for scope: $SCOPE.
Missing DetMir Rust release artifacts.
Build them with:
cd "$ROOT_DIR/adk-rust"
CARGO_TARGET_DIR="$TARGET_ROOT" cargo build --release --workspace
@@ -124,4 +84,4 @@ EOF
exit 1
fi
echo "detmir rust release artifacts: OK scope=$SCOPE ($RELEASE_DIR)"
echo "detmir rust release artifacts: OK ($RELEASE_DIR)"
-260
View File
@@ -1,260 +0,0 @@
#!/usr/bin/env bash
set -euo pipefail
ENABLED="${AW_DLP_GUARD_ENABLED:-true}"
PROFILE="${AW_DLP_PROFILE:-light}"
STATE_DIR="${AW_DLP_GUARD_STATE_DIR:-/var/lib/activitywatch/health}"
STATE_FILE="${AW_DLP_GUARD_STATE_FILE:-${STATE_DIR}/dlp-light-guard-state.json}"
STATE_HISTORY_DIR="${AW_DLP_GUARD_HISTORY_DIR:-${STATE_DIR}/dlp-light-guard-history}"
CONTROL_BIN="${AW_DLP_CONTROL_BIN:-/usr/local/bin/detmir-dlp-runtime-control}"
LOAD_RATIO="${AW_DLP_GUARD_LOAD_RATIO:-1.50}"
MEM_AVAILABLE_PCT_MIN="${AW_DLP_GUARD_MEM_AVAILABLE_PCT_MIN:-15}"
IOWAIT_PCT_MAX="${AW_DLP_GUARD_IOWAIT_PCT_MAX:-20}"
STRIKES_REQUIRED="${AW_DLP_GUARD_STRIKES_REQUIRED:-3}"
DLP_GUARDED_UNITS=(
aw-dlp-influx-exporter.timer
aw-dlp-influx-exporter.service
activitywatch-dlp-aggregator.timer
activitywatch-dlp-aggregator.service
aw-dlp-report-scheduler.timer
aw-dlp-report-scheduler.service
aw-dlp-syslog-forwarder.timer
aw-dlp-syslog-forwarder.service
aw-dlp-webhook-sender.timer
aw-dlp-webhook-sender.service
aw-dlp-cef-exporter.timer
aw-dlp-cef-exporter.service
aw-dlp-ioc-refresh.timer
aw-dlp-ioc-refresh.service
aw-dlp-policy-engine.service
aw-dlp-case-management.service
detmir-portal-evidence.service
)
json_string() {
python3 -c 'import json,sys; print(json.dumps(sys.argv[1], ensure_ascii=False))' "$1"
}
number_or_null() {
local value="${1:-}"
if [[ "$value" =~ ^-?[0-9]+([.][0-9]+)?$ ]]; then
printf '%s' "$value"
else
printf 'null'
fi
}
active_dlp_units_json() {
local first=1 unit
printf '['
if command -v systemctl >/dev/null 2>&1; then
for unit in "${DLP_GUARDED_UNITS[@]}"; do
if systemctl is-active --quiet "$unit" 2>/dev/null; then
[[ "$first" -eq 1 ]] || printf ','
first=0
json_string "$unit"
fi
done
fi
printf ']'
}
active_dlp_unit_count() {
local count=0 unit
if command -v systemctl >/dev/null 2>&1; then
for unit in "${DLP_GUARDED_UNITS[@]}"; do
if systemctl is-active --quiet "$unit" 2>/dev/null; then
count=$((count + 1))
fi
done
fi
printf '%s\n' "$count"
}
read_load1() {
awk '{print $1}' /proc/loadavg 2>/dev/null || printf '0'
}
read_cpu_count() {
local cores
cores="$(getconf _NPROCESSORS_ONLN 2>/dev/null || printf '1')"
if [[ ! "$cores" =~ ^[0-9]+$ || "$cores" -lt 1 ]]; then
cores=1
fi
printf '%s\n' "$cores"
}
read_mem_available_pct() {
awk '
/^MemTotal:/ { total=$2 }
/^MemAvailable:/ { available=$2 }
END {
if (total > 0) {
printf "%.2f", (available * 100.0 / total)
} else {
printf "0"
}
}
' /proc/meminfo 2>/dev/null || printf '0'
}
read_cpu_sample() {
awk '/^cpu / {
idle=$5
iowait=$6
total=0
for (i=2; i<=NF; i++) total += $i
printf "%s %s\n", total, iowait
exit
}' /proc/stat 2>/dev/null || printf '0 0'
}
read_iowait_pct() {
local total1 wait1 total2 wait2 dtotal dwait
read -r total1 wait1 < <(read_cpu_sample)
sleep 1
read -r total2 wait2 < <(read_cpu_sample)
dtotal=$((total2 - total1))
dwait=$((wait2 - wait1))
if [[ "$dtotal" -le 0 || "$dwait" -lt 0 ]]; then
printf '0'
return
fi
awk -v wait="$dwait" -v total="$dtotal" 'BEGIN { printf "%.2f", wait * 100.0 / total }'
}
is_over_threshold() {
local value="$1"
local threshold="$2"
awk -v value="$value" -v threshold="$threshold" 'BEGIN { exit !(value > threshold) }'
}
is_under_threshold() {
local value="$1"
local threshold="$2"
awk -v value="$value" -v threshold="$threshold" 'BEGIN { exit !(value < threshold) }'
}
write_state() {
local action="$1"
local reason="$2"
local load1="$3"
local cores="$4"
local load_threshold="$5"
local mem_pct="$6"
local iowait_pct="$7"
local active_count="$8"
local active_units_json="$9"
local control_exit="${10}"
local strikes="${11:-0}"
local now stamp tmp history
now="$(date -u +%Y-%m-%dT%H:%M:%SZ)"
stamp="$(date -u +%Y%m%dT%H%M%SZ)"
mkdir -p "$STATE_DIR" "$STATE_HISTORY_DIR"
tmp="$(mktemp "${STATE_FILE}.tmp.XXXXXX")"
{
printf '{'
printf '"generated_at_utc":%s,' "$(json_string "$now")"
printf '"profile":%s,' "$(json_string "$PROFILE")"
printf '"guard_enabled":%s,' "$(json_string "$ENABLED")"
printf '"action":%s,' "$(json_string "$action")"
printf '"reason":%s,' "$(json_string "$reason")"
printf '"consecutive_overload_count":%s,' "$(number_or_null "$strikes")"
printf '"consecutive_overload_required":%s,' "$(number_or_null "$STRIKES_REQUIRED")"
printf '"control_bin":%s,' "$(json_string "$CONTROL_BIN")"
printf '"control_exit":%s,' "$(number_or_null "$control_exit")"
printf '"metrics":{'
printf '"load1":%s,' "$(number_or_null "$load1")"
printf '"cpu_count":%s,' "$(number_or_null "$cores")"
printf '"load_threshold":%s,' "$(number_or_null "$load_threshold")"
printf '"mem_available_pct":%s,' "$(number_or_null "$mem_pct")"
printf '"mem_available_pct_min":%s,' "$(number_or_null "$MEM_AVAILABLE_PCT_MIN")"
printf '"iowait_pct":%s,' "$(number_or_null "$iowait_pct")"
printf '"iowait_pct_max":%s' "$(number_or_null "$IOWAIT_PCT_MAX")"
printf '},'
printf '"active_dlp_unit_count":%s,' "$(number_or_null "$active_count")"
printf '"active_dlp_units":%s' "$active_units_json"
printf '}\n'
} >"$tmp"
mv "$tmp" "$STATE_FILE"
history="${STATE_HISTORY_DIR}/dlp-light-guard-${stamp}.json"
cp -a "$STATE_FILE" "$history"
printf 'dlp guard action=%s reason=%s state=%s history=%s\n' "$action" "$reason" "$STATE_FILE" "$history"
}
main() {
local load1 cores load_threshold mem_pct iowait_pct active_count active_units_json overloaded reason control_exit strikes prev_strikes
load1="$(read_load1)"
cores="$(read_cpu_count)"
load_threshold="$(awk -v cores="$cores" -v ratio="$LOAD_RATIO" 'BEGIN { printf "%.2f", cores * ratio }')"
mem_pct="$(read_mem_available_pct)"
iowait_pct="$(read_iowait_pct)"
active_units_json="$(active_dlp_units_json)"
active_count="$(active_dlp_unit_count)"
overloaded=0
reason="within_thresholds"
prev_strikes="$(
python3 - "$STATE_FILE" <<'PY' 2>/dev/null || true
import json, sys
try:
print(int(json.load(open(sys.argv[1])).get("consecutive_overload_count", 0)))
except Exception:
print(0)
PY
)"
[[ "$prev_strikes" =~ ^[0-9]+$ ]] || prev_strikes=0
strikes=0
if is_over_threshold "$load1" "$load_threshold"; then
overloaded=1
reason="load1_above_threshold"
elif is_under_threshold "$mem_pct" "$MEM_AVAILABLE_PCT_MIN"; then
overloaded=1
reason="mem_available_below_threshold"
elif is_over_threshold "$iowait_pct" "$IOWAIT_PCT_MAX"; then
overloaded=1
reason="iowait_above_threshold"
fi
if [[ "$ENABLED" != "true" && "$ENABLED" != "1" && "$ENABLED" != "yes" ]]; then
write_state "skipped" "guard_disabled" "$load1" "$cores" "$load_threshold" "$mem_pct" "$iowait_pct" "$active_count" "$active_units_json" "0" "0"
return 0
fi
if [[ "$overloaded" -eq 0 ]]; then
write_state "none" "$reason" "$load1" "$cores" "$load_threshold" "$mem_pct" "$iowait_pct" "$active_count" "$active_units_json" "0" "0"
return 0
fi
strikes=$((prev_strikes + 1))
if [[ "$strikes" -lt "$STRIKES_REQUIRED" ]]; then
write_state "observe_overload" "$reason" "$load1" "$cores" "$load_threshold" "$mem_pct" "$iowait_pct" "$active_count" "$active_units_json" "0" "$strikes"
return 0
fi
if [[ "$active_count" -eq 0 ]]; then
write_state "none" "${reason}_but_no_active_dlp_units" "$load1" "$cores" "$load_threshold" "$mem_pct" "$iowait_pct" "$active_count" "$active_units_json" "0" "$strikes"
return 0
fi
if [[ ! -x "$CONTROL_BIN" ]]; then
write_state "failed" "${reason}_control_bin_missing" "$load1" "$cores" "$load_threshold" "$mem_pct" "$iowait_pct" "$active_count" "$active_units_json" "127" "$strikes"
printf 'DLP guard cannot disable overloaded DLP: executable not found: %s\n' "$CONTROL_BIN" >&2
return 127
fi
control_exit=0
AW_DLP_DISABLED_REASON="auto_disabled_by_dlp_load_guard:${reason}" "$CONTROL_BIN" set-profile core_only || control_exit=$?
if [[ "$control_exit" -eq 0 ]]; then
write_state "auto_disabled" "$reason" "$load1" "$cores" "$load_threshold" "$mem_pct" "$iowait_pct" "$active_count" "$active_units_json" "$control_exit" "$strikes"
else
write_state "failed" "${reason}_control_exit_${control_exit}" "$load1" "$cores" "$load_threshold" "$mem_pct" "$iowait_pct" "$active_count" "$active_units_json" "$control_exit" "$strikes"
fi
return "$control_exit"
}
main "$@"
-269
View File
@@ -1,269 +0,0 @@
#!/usr/bin/env bash
set -euo pipefail
ACTION="${1:-status}"
PROFILE="${2:-${AW_DLP_PROFILE:-core_only}}"
AW_BASE="${AW_DLP_CONTROL_AW_BASE:-http://127.0.0.1:5600}"
HOSTNAME_FILTER="${AW_DLP_CONTROL_HOSTNAME:-${AW_LOGICAL_HOST_ID:-${AW_MONITORED_WINDOWS_HOSTNAME:-HOST-EXAMPLE}}}"
STATE_DIR="${AW_DLP_CONTROL_STATE_DIR:-/var/lib/activitywatch/health}"
STATE_FILE="${AW_DLP_CONTROL_STATE_FILE:-${STATE_DIR}/dlp-runtime-state.json}"
STATE_HISTORY_DIR="${AW_DLP_CONTROL_HISTORY_DIR:-${STATE_DIR}/dlp-runtime-history}"
ROLLBACK_FILE="${AW_DLP_CONTROL_ROLLBACK_FILE:-${STATE_DIR}/dlp-runtime-rollback.state}"
REASON="${AW_DLP_DISABLED_REASON:-dlp_runtime_profile_control}"
DLP_UNITS=(
aw-dlp-influx-exporter.timer
aw-dlp-influx-exporter.service
activitywatch-dlp-aggregator.timer
activitywatch-dlp-aggregator.service
aw-dlp-report-scheduler.timer
aw-dlp-report-scheduler.service
aw-dlp-syslog-forwarder.timer
aw-dlp-syslog-forwarder.service
aw-dlp-webhook-sender.timer
aw-dlp-webhook-sender.service
aw-dlp-cef-exporter.timer
aw-dlp-cef-exporter.service
aw-dlp-ioc-refresh.timer
aw-dlp-ioc-refresh.service
aw-dlp-policy-engine.service
aw-dlp-case-management.service
detmir-portal-evidence.service
)
DLP_BUCKET_PREFIXES=(
aw-dlp-endpoint-signals
aw-dlp-incidents
aw-dlp-review
aw-dlp-rules
)
DLP_LIGHT_UNITS=(
activitywatch-dlp-aggregator.timer
aw-dlp-ioc-refresh.timer
)
DLP_ON_DEMAND_UNITS=(
aw-dlp-ioc-refresh.timer
aw-dlp-policy-engine.service
aw-dlp-case-management.service
detmir-portal-evidence.service
)
json_escape() {
local value="$1"
python3 -c 'import json,sys; print(json.dumps(sys.argv[1], ensure_ascii=False))' "$value"
}
unit_json() {
local first=1 unit active enabled load
printf '['
for unit in "${DLP_UNITS[@]}"; do
load="$(systemctl show -p LoadState --value "$unit" 2>/dev/null || true)"
if [[ "$load" == "not-found" || -z "$load" ]]; then
active="not-found"
enabled="not-found"
else
active="$(systemctl is-active "$unit" 2>/dev/null || true)"
enabled="$(systemctl is-enabled "$unit" 2>/dev/null || true)"
fi
[[ "$first" -eq 1 ]] || printf ','
first=0
printf '{"unit":%s,"load":%s,"active":%s,"enabled":%s}' \
"$(json_escape "$unit")" \
"$(json_escape "${load:-not-found}")" \
"$(json_escape "${active:-unknown}")" \
"$(json_escape "${enabled:-unknown}")"
done
printf ']'
}
bucket_json() {
local first=1 prefix bucket url payload ts count
printf '['
for prefix in "${DLP_BUCKET_PREFIXES[@]}"; do
bucket="${prefix}_${HOSTNAME_FILTER}"
url="${AW_BASE%/}/api/0/buckets/${bucket}/events?limit=1"
payload="$(curl -sS --connect-timeout 3 --max-time 8 "$url" 2>/dev/null || true)"
ts="$(printf '%s' "$payload" | jq -r '.[0].timestamp // ""' 2>/dev/null || true)"
count="$(printf '%s' "$payload" | jq -r 'if type == "array" then length else 0 end' 2>/dev/null || printf '0')"
[[ "$first" -eq 1 ]] || printf ','
first=0
printf '{"bucket":%s,"sample_count":%s,"latest_timestamp":%s}' \
"$(json_escape "$bucket")" \
"${count:-0}" \
"$(json_escape "$ts")"
done
printf ']'
}
unit_exists() {
local unit="$1"
systemctl list-unit-files "$unit" --no-legend 2>/dev/null | grep -q . || systemctl status "$unit" >/dev/null 2>&1
}
stop_disable_all_dlp() {
local unit
for unit in "${DLP_UNITS[@]}"; do
if unit_exists "$unit"; then
systemctl stop "$unit" >/dev/null 2>&1 || true
systemctl disable "$unit" >/dev/null 2>&1 || true
systemctl reset-failed "$unit" >/dev/null 2>&1 || true
fi
done
}
enable_start_units() {
local unit
for unit in "$@"; do
if unit_exists "$unit"; then
systemctl enable --now "$unit" >/dev/null 2>&1 || true
fi
done
}
capture_rollback_state() {
local tmp unit load active enabled
mkdir -p "$STATE_DIR"
tmp="$(mktemp "${ROLLBACK_FILE}.tmp.XXXXXX")"
{
printf '# generated_at_utc=%s\n' "$(date -u +%Y-%m-%dT%H:%M:%SZ)"
printf '# reason=pre_profile_change\n'
for unit in "${DLP_UNITS[@]}"; do
load="$(systemctl show -p LoadState --value "$unit" 2>/dev/null || true)"
if [[ "$load" == "not-found" || -z "$load" ]]; then
active="not-found"
enabled="not-found"
else
active="$(systemctl is-active "$unit" 2>/dev/null || true)"
enabled="$(systemctl is-enabled "$unit" 2>/dev/null || true)"
fi
printf '%s|%s|%s|%s\n' "$unit" "${load:-not-found}" "$active" "$enabled"
done
} >"$tmp"
mv "$tmp" "$ROLLBACK_FILE"
}
write_stats() {
local mode="${1:-current}" now stamp tmp history_file
now="$(date -u +%Y-%m-%dT%H:%M:%SZ)"
stamp="$(date -u +%Y%m%dT%H%M%SZ)"
mkdir -p "$STATE_DIR" "$STATE_HISTORY_DIR"
tmp="$(mktemp "${STATE_FILE}.tmp.XXXXXX")"
{
printf '{'
printf '"generated_at_utc":%s,' "$(json_escape "$now")"
printf '"mode":%s,' "$(json_escape "$mode")"
printf '"profile":%s,' "$(json_escape "${AW_DLP_PROFILE:-$PROFILE}")"
printf '"reason":%s,' "$(json_escape "$REASON")"
printf '"aw_base":%s,' "$(json_escape "$AW_BASE")"
printf '"hostname":%s,' "$(json_escape "$HOSTNAME_FILTER")"
printf '"units":'
unit_json
printf ',"buckets":'
bucket_json
printf '}\n'
} >"$tmp"
mv "$tmp" "$STATE_FILE"
history_file="${STATE_HISTORY_DIR}/dlp-runtime-${mode}-${stamp}.json"
cp -a "$STATE_FILE" "$history_file"
printf 'latest=%s\nhistory=%s\n' "$STATE_FILE" "$history_file"
}
apply_profile() {
local target_profile="$1"
capture_rollback_state
case "$target_profile" in
core_only|disabled|off)
PROFILE="core_only"
stop_disable_all_dlp
AW_DLP_PROFILE="core_only" write_stats "disabled"
;;
light)
PROFILE="light"
stop_disable_all_dlp
enable_start_units "${DLP_LIGHT_UNITS[@]}"
AW_DLP_PROFILE="light" write_stats "enabled_light"
;;
on_demand)
PROFILE="on_demand"
stop_disable_all_dlp
enable_start_units "${DLP_ON_DEMAND_UNITS[@]}"
AW_DLP_PROFILE="on_demand" write_stats "enabled_on_demand"
;;
full|enabled|on)
PROFILE="full"
stop_disable_all_dlp
enable_start_units "${DLP_LIGHT_UNITS[@]}"
enable_start_units \
aw-dlp-influx-exporter.timer \
activitywatch-dlp-aggregator.timer \
aw-dlp-report-scheduler.timer \
aw-dlp-syslog-forwarder.timer \
aw-dlp-webhook-sender.timer \
aw-dlp-cef-exporter.timer \
aw-dlp-policy-engine.service \
aw-dlp-case-management.service \
detmir-portal-evidence.service
AW_DLP_PROFILE="full" write_stats "enabled_full"
;;
*)
printf 'unsupported DLP profile: %s\n' "$target_profile" >&2
printf 'supported profiles: core_only, light, on_demand, full\n' >&2
exit 2
;;
esac
}
disable_dlp() {
apply_profile "core_only"
}
enable_dlp() {
apply_profile "full"
}
rollback_dlp() {
local unit load active enabled
if [[ ! -s "$ROLLBACK_FILE" ]]; then
printf 'rollback state not found: %s\n' "$ROLLBACK_FILE" >&2
exit 1
fi
stop_disable_all_dlp
while IFS='|' read -r unit load active enabled; do
[[ -n "${unit:-}" && "${unit:0:1}" != "#" ]] || continue
[[ "$load" != "not-found" ]] || continue
if [[ "$enabled" == "enabled" ]]; then
systemctl enable "$unit" >/dev/null 2>&1 || true
fi
if [[ "$active" == "active" ]]; then
systemctl start "$unit" >/dev/null 2>&1 || true
fi
done <"$ROLLBACK_FILE"
write_stats "rollback"
}
case "$ACTION" in
status|stats)
write_stats "current"
;;
profile)
printf '%s\n' "${AW_DLP_PROFILE:-$PROFILE}"
;;
set-profile)
apply_profile "$PROFILE"
;;
disable)
disable_dlp
;;
enable)
enable_dlp
;;
rollback)
rollback_dlp
;;
*)
printf 'Usage: %s [status|stats|profile|set-profile <core_only|light|on_demand|full>|disable|enable|rollback]\n' "$0" >&2
exit 2
;;
esac
-73
View File
@@ -1,73 +0,0 @@
#!/usr/bin/env bash
set -euo pipefail
SOURCE_HOST="${AW_DLP_WAREHOUSE_SOURCE_HOST:-igor@10.10.10.13}"
SOURCE_PATH="${AW_DLP_WAREHOUSE_SOURCE_PATH:-/var/lib/activitywatch/dlp_warehouse.sqlite}"
DEST_PATH="${AW_DLP_WAREHOUSE_DEST_PATH:-/var/lib/activitywatch/dlp_warehouse.sqlite}"
STATE_DIR="${AW_DLP_WAREHOUSE_SYNC_STATE_DIR:-/var/lib/activitywatch/health}"
STATE_FILE="${AW_DLP_WAREHOUSE_SYNC_STATE_FILE:-${STATE_DIR}/dlp-warehouse-sync-state.json}"
SSH_OPTS="${AW_DLP_WAREHOUSE_SSH_OPTS:--o BatchMode=yes -o ConnectTimeout=5}"
REMOTE_TMP="/tmp/dlp_warehouse_sync_$$.sqlite"
LOCAL_TMP=""
json_string() {
python3 -c 'import json,sys; print(json.dumps(sys.argv[1], ensure_ascii=False))' "$1"
}
write_state() {
local status="$1"
local message="$2"
local rows="${3:-}"
local bytes="${4:-}"
local now tmp
now="$(date -u +%Y-%m-%dT%H:%M:%SZ)"
mkdir -p "$STATE_DIR"
tmp="$(mktemp "${STATE_FILE}.tmp.XXXXXX")"
{
printf '{'
printf '"generated_at_utc":%s,' "$(json_string "$now")"
printf '"status":%s,' "$(json_string "$status")"
printf '"message":%s,' "$(json_string "$message")"
printf '"source_host":%s,' "$(json_string "$SOURCE_HOST")"
printf '"source_path":%s,' "$(json_string "$SOURCE_PATH")"
printf '"dest_path":%s,' "$(json_string "$DEST_PATH")"
if [[ "$rows" =~ ^[0-9]+$ ]]; then
printf '"dlp_events":%s,' "$rows"
else
printf '"dlp_events":null,'
fi
if [[ "$bytes" =~ ^[0-9]+$ ]]; then
printf '"bytes":%s' "$bytes"
else
printf '"bytes":null'
fi
printf '}\n'
} >"$tmp"
mv "$tmp" "$STATE_FILE"
}
cleanup_remote() {
ssh $SSH_OPTS "$SOURCE_HOST" "rm -f '$REMOTE_TMP'" >/dev/null 2>&1 || true
}
main() {
local dest_dir rows bytes
dest_dir="$(dirname "$DEST_PATH")"
mkdir -p "$dest_dir" "$STATE_DIR"
LOCAL_TMP="$(mktemp "${DEST_PATH}.tmp.XXXXXX")"
trap 'rm -f "${LOCAL_TMP:-}"; cleanup_remote' EXIT
ssh $SSH_OPTS "$SOURCE_HOST" \
"set -euo pipefail; if command -v sqlite3 >/dev/null 2>&1; then sqlite3 '$SOURCE_PATH' \".backup '$REMOTE_TMP'\" || cp -f '$SOURCE_PATH' '$REMOTE_TMP'; else cp -f '$SOURCE_PATH' '$REMOTE_TMP'; fi; test -s '$REMOTE_TMP'"
scp $SSH_OPTS "$SOURCE_HOST:$REMOTE_TMP" "$LOCAL_TMP"
chmod 0644 "$LOCAL_TMP"
mv "$LOCAL_TMP" "$DEST_PATH"
bytes="$(stat -c %s "$DEST_PATH" 2>/dev/null || printf '')"
rows="$(sqlite3 "$DEST_PATH" 'select count(*) from dlp_events;' 2>/dev/null || printf '')"
write_state "ok" "synced" "$rows" "$bytes"
printf 'dlp warehouse synced: source=%s:%s dest=%s rows=%s bytes=%s\n' \
"$SOURCE_HOST" "$SOURCE_PATH" "$DEST_PATH" "${rows:-unknown}" "${bytes:-unknown}"
}
main "$@"
+14 -52
View File
@@ -53,26 +53,6 @@ done
log() { printf "%s %s\n" "$(date +"%F %T")" "$*" >&2; }
die() { log "ERROR: $*"; exit 1; }
is_truthy() {
case "${1:-}" in
1|true|TRUE|yes|YES|on|ON) return 0 ;;
*) return 1 ;;
esac
}
require_real_value() {
local name="$1"
local value="${!name:-}"
if [[ -z "$value" ]]; then
die "missing required variable: $name"
fi
case "$value" in
*192.0.2.*|*198.51.100.*|*203.0.113.*|*HOST-EXAMPLE*|*.example*)
die "refusing placeholder value for $name: $value"
;;
esac
}
command -v ansible >/dev/null 2>&1 || die "ansible not found"
command -v ansible-playbook >/dev/null 2>&1 || die "ansible-playbook not found"
[[ -f "$INVENTORY" ]] || die "inventory not found: $INVENTORY"
@@ -88,14 +68,10 @@ restart_server_components() {
"activitywatch-server"
"aw-worktime-api"
"aw-worktime-ui-bridge.timer"
"aw-dlp-policy-engine.service"
"aw-dlp-aggregator.timer"
"activitywatch-dlp-aggregator.timer"
)
if is_truthy "${DETMIR_DLP_ENABLED:-${AW_DLP_ENABLED:-false}}"; then
units+=(
"aw-dlp-policy-engine.service"
"aw-dlp-aggregator.timer"
"activitywatch-dlp-aggregator.timer"
)
fi
for unit in "${units[@]}"; do
if ansible -i "$INVENTORY" aw_server -b -m ansible.builtin.command -a "systemctl status ${unit}" >/dev/null 2>&1; then
ansible -i "$INVENTORY" aw_server -b -m ansible.builtin.systemd -a "name=${unit} state=restarted enabled=true" || true
@@ -104,32 +80,24 @@ restart_server_components() {
}
seed_server_dlp_events() {
if ! is_truthy "${ALLOW_DLP_SEED_EVENTS:-0}"; then
log "Skipping DLP freshness seeding; set ALLOW_DLP_SEED_EVENTS=1 with real DETMIR_HOSTNAME/DETMIR_AW_SERVER_HOST to allow it."
return 0
fi
require_real_value DETMIR_HOSTNAME
require_real_value DETMIR_AW_SERVER_HOST
log "Seeding DLP freshness events on aw_server..."
local ts host server_host
local ts
ts="$(date -u +%Y-%m-%dT%H:%M:%SZ)"
host="${DETMIR_HOSTNAME}"
server_host="${DETMIR_AW_SERVER_HOST}"
ansible -i "$INVENTORY" aw_server -b -m ansible.builtin.shell -a "cat >/tmp/aw-endpoint-seed.json <<'JSON'
{\"timestamp\":\"${ts}\",\"duration\":0.0,\"data\":{\"hostname\":\"${host}\",\"signalType\":\"self_test\",\"source\":\"diag_and_manual_restart\",\"username\":\"system\",\"queueDepth\":0,\"eventsEnqueued\":0,\"eventsFlushed\":0,\"sendFailures\":0}}
{\"timestamp\":\"${ts}\",\"duration\":0.0,\"data\":{\"hostname\":\"HOST-EXAMPLE\",\"signalType\":\"self_test\",\"source\":\"diag_and_manual_restart\",\"username\":\"system\",\"queueDepth\":0,\"eventsEnqueued\":0,\"eventsFlushed\":0,\"sendFailures\":0}}
JSON
cat >/tmp/aw-fileops-seed-host.json <<'JSON'
{\"timestamp\":\"${ts}\",\"duration\":0.0,\"data\":{\"hostname\":\"${host}\",\"operation\":\"self_test\",\"source\":\"diag_and_manual_restart\"}}
{\"timestamp\":\"${ts}\",\"duration\":0.0,\"data\":{\"hostname\":\"HOST-EXAMPLE\",\"operation\":\"self_test\",\"source\":\"diag_and_manual_restart\"}}
JSON
cat >/tmp/aw-fileops-seed-server.json <<'JSON'
{\"timestamp\":\"${ts}\",\"duration\":0.0,\"data\":{\"hostname\":\"${server_host}\",\"operation\":\"self_test\",\"source\":\"diag_and_manual_restart\"}}
{\"timestamp\":\"${ts}\",\"duration\":0.0,\"data\":{\"hostname\":\"192.0.2.13\",\"operation\":\"self_test\",\"source\":\"diag_and_manual_restart\"}}
JSON
curl -sS -X POST 'http://127.0.0.1:5600/api/0/buckets/aw-dlp-endpoint-signals_${host}' -H 'Content-Type: application/json' -d '{\"client\":\"aw-dlp-endpoint-signals\",\"type\":\"aw.dlp.endpoint.signal\",\"hostname\":\"${host}\"}' >/dev/null 2>&1 || true
curl -sS -X POST 'http://127.0.0.1:5600/api/0/buckets/aw-file-operations_${host}' -H 'Content-Type: application/json' -d '{\"client\":\"aw-file-operations\",\"type\":\"aw.file.operation\",\"hostname\":\"${host}\"}' >/dev/null 2>&1 || true
curl -sS -X POST 'http://127.0.0.1:5600/api/0/buckets/aw-file-operations_${server_host}' -H 'Content-Type: application/json' -d '{\"client\":\"aw-file-operations\",\"type\":\"aw.file.operation\",\"hostname\":\"${server_host}\"}' >/dev/null 2>&1 || true
curl -sS -X POST 'http://127.0.0.1:5600/api/0/buckets/aw-dlp-endpoint-signals_${host}/heartbeat?pulsetime=30' -H 'Content-Type: application/json' --data-binary @/tmp/aw-endpoint-seed.json >/dev/null
curl -sS -X POST 'http://127.0.0.1:5600/api/0/buckets/aw-file-operations_${host}/heartbeat?pulsetime=30' -H 'Content-Type: application/json' --data-binary @/tmp/aw-fileops-seed-host.json >/dev/null
curl -sS -X POST 'http://127.0.0.1:5600/api/0/buckets/aw-file-operations_${server_host}/heartbeat?pulsetime=30' -H 'Content-Type: application/json' --data-binary @/tmp/aw-fileops-seed-server.json >/dev/null
curl -sS -X POST 'http://127.0.0.1:5600/api/0/buckets/aw-dlp-endpoint-signals_HOST-EXAMPLE' -H 'Content-Type: application/json' -d '{\"client\":\"aw-dlp-endpoint-signals\",\"type\":\"aw.dlp.endpoint.signal\",\"hostname\":\"HOST-EXAMPLE\"}' >/dev/null 2>&1 || true
curl -sS -X POST 'http://127.0.0.1:5600/api/0/buckets/aw-file-operations_HOST-EXAMPLE' -H 'Content-Type: application/json' -d '{\"client\":\"aw-file-operations\",\"type\":\"aw.file.operation\",\"hostname\":\"HOST-EXAMPLE\"}' >/dev/null 2>&1 || true
curl -sS -X POST 'http://127.0.0.1:5600/api/0/buckets/aw-file-operations_192.0.2.13' -H 'Content-Type: application/json' -d '{\"client\":\"aw-file-operations\",\"type\":\"aw.file.operation\",\"hostname\":\"192.0.2.13\"}' >/dev/null 2>&1 || true
curl -sS -X POST 'http://127.0.0.1:5600/api/0/buckets/aw-dlp-endpoint-signals_HOST-EXAMPLE/heartbeat?pulsetime=30' -H 'Content-Type: application/json' --data-binary @/tmp/aw-endpoint-seed.json >/dev/null
curl -sS -X POST 'http://127.0.0.1:5600/api/0/buckets/aw-file-operations_HOST-EXAMPLE/heartbeat?pulsetime=30' -H 'Content-Type: application/json' --data-binary @/tmp/aw-fileops-seed-host.json >/dev/null
curl -sS -X POST 'http://127.0.0.1:5600/api/0/buckets/aw-file-operations_192.0.2.13/heartbeat?pulsetime=30' -H 'Content-Type: application/json' --data-binary @/tmp/aw-fileops-seed-server.json >/dev/null
" >/dev/null
}
@@ -139,14 +107,8 @@ restart_windows_collectors() {
}
seed_windows_dlp_events() {
if ! is_truthy "${ALLOW_DLP_SEED_EVENTS:-0}"; then
log "Skipping Windows DLP freshness seeding; set ALLOW_DLP_SEED_EVENTS=1 with real DETMIR_HOSTNAME/DETMIR_AW_API to allow it."
return 0
fi
require_real_value DETMIR_HOSTNAME
require_real_value DETMIR_AW_API
log "Seeding endpoint/file-ops events from aw_windows..."
ansible -i "$INVENTORY" aw_windows -m ansible.windows.win_shell -a "powershell -NoProfile -ExecutionPolicy Bypass -Command \"\$ErrorActionPreference = 'Stop'; \$ts = (Get-Date).ToUniversalTime().ToString('o'); \$api='${DETMIR_AW_API}'; \$hostName='${DETMIR_HOSTNAME}'; \$endpointBucket=\$api + '/buckets/aw-dlp-endpoint-signals_' + \$hostName; \$fileopsBucket=\$api + '/buckets/aw-file-operations_' + \$hostName; \$endpoint=@{timestamp=\$ts;duration=0.0;data=@{hostname=\$hostName;signalType='self_test';source='diag_and_manual_restart';username=\$env:USERNAME;queueDepth=0;eventsEnqueued=0;eventsFlushed=0;sendFailures=0}} | ConvertTo-Json -Depth 8 -Compress; \$fileops=@{timestamp=\$ts;duration=0.0;data=@{hostname=\$hostName;operation='self_test';source='diag_and_manual_restart';username=\$env:USERNAME}} | ConvertTo-Json -Depth 8 -Compress; Invoke-RestMethod -Method Post -Uri \$endpointBucket -ContentType 'application/json' -Body (@{client='aw-dlp-endpoint-signals';type='aw.dlp.endpoint.signal';hostname=\$hostName} | ConvertTo-Json -Compress) -TimeoutSec 15 -DisableKeepAlive -ErrorAction SilentlyContinue | Out-Null; Invoke-RestMethod -Method Post -Uri \$fileopsBucket -ContentType 'application/json' -Body (@{client='aw-file-operations';type='aw.file.operation';hostname=\$hostName} | ConvertTo-Json -Compress) -TimeoutSec 15 -DisableKeepAlive -ErrorAction SilentlyContinue | Out-Null; Invoke-RestMethod -Method Post -Uri (\$endpointBucket + '/heartbeat?pulsetime=30') -ContentType 'application/json' -Body \$endpoint -TimeoutSec 15 -DisableKeepAlive | Out-Null; Invoke-RestMethod -Method Post -Uri (\$fileopsBucket + '/heartbeat?pulsetime=30') -ContentType 'application/json' -Body \$fileops -TimeoutSec 15 -DisableKeepAlive | Out-Null; Write-Output 'windows-dlp-seeded'\""
ansible -i "$INVENTORY" aw_windows -m ansible.windows.win_shell -a "powershell -NoProfile -ExecutionPolicy Bypass -Command \"\$ErrorActionPreference = 'Stop'; \$ts = (Get-Date).ToUniversalTime().ToString('o'); \$api='http://192.0.2.13:5600/api/0'; \$endpoint=@{timestamp=\$ts;duration=0.0;data=@{hostname='HOST-EXAMPLE';signalType='self_test';source='diag_and_manual_restart';username=\$env:USERNAME;queueDepth=0;eventsEnqueued=0;eventsFlushed=0;sendFailures=0}} | ConvertTo-Json -Depth 8 -Compress; \$fileops=@{timestamp=\$ts;duration=0.0;data=@{hostname='HOST-EXAMPLE';operation='self_test';source='diag_and_manual_restart';username=\$env:USERNAME}} | ConvertTo-Json -Depth 8 -Compress; Invoke-RestMethod -Method Post -Uri \$api'/buckets/aw-dlp-endpoint-signals_HOST-EXAMPLE' -ContentType 'application/json' -Body '{\\\"client\\\":\\\"aw-dlp-endpoint-signals\\\",\\\"type\\\":\\\"aw.dlp.endpoint.signal\\\",\\\"hostname\\\":\\\"HOST-EXAMPLE\\\"}' -TimeoutSec 15 -DisableKeepAlive -ErrorAction SilentlyContinue | Out-Null; Invoke-RestMethod -Method Post -Uri \$api'/buckets/aw-file-operations_HOST-EXAMPLE' -ContentType 'application/json' -Body '{\\\"client\\\":\\\"aw-file-operations\\\",\\\"type\\\":\\\"aw.file.operation\\\",\\\"hostname\\\":\\\"HOST-EXAMPLE\\\"}' -TimeoutSec 15 -DisableKeepAlive -ErrorAction SilentlyContinue | Out-Null; Invoke-RestMethod -Method Post -Uri \$api'/buckets/aw-dlp-endpoint-signals_HOST-EXAMPLE/heartbeat?pulsetime=30' -ContentType 'application/json' -Body \$endpoint -TimeoutSec 15 -DisableKeepAlive | Out-Null; Invoke-RestMethod -Method Post -Uri \$api'/buckets/aw-file-operations_HOST-EXAMPLE/heartbeat?pulsetime=30' -ContentType 'application/json' -Body \$fileops -TimeoutSec 15 -DisableKeepAlive | Out-Null; Write-Output 'windows-dlp-seeded'\""
}
confirm_restart() {
+3 -23
View File
@@ -4,29 +4,14 @@ set -euo pipefail
DAY=""
FROM=""
TO=""
AW_BASE_URL="${AW_BASE_URL:-}"
AW_WORKTIME_HOST="${AW_WORKTIME_HOST:-}"
AW_BASE_URL="${AW_BASE_URL:-http://192.0.2.13:5600/api/0}"
AW_WORKTIME_HOST="${AW_WORKTIME_HOST:-HOST-EXAMPLE}"
AW_WORKTIME_DEFAULT_SAMPLE_SECONDS="${AW_WORKTIME_DEFAULT_SAMPLE_SECONDS:-30}"
AW_WORKTIME_MAX_SAMPLE_SECONDS="${AW_WORKTIME_MAX_SAMPLE_SECONDS:-300}"
OUT_DIR="${OUT_DIR:-reports}"
TARGET_ROOT="${CARGO_TARGET_DIR:-$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)/adk-rust/target}"
RUST_BIN="${RDP_WORKTIME_REPORT_RUST:-}"
require_live_value() {
local name="$1"
local value="${!name:-}"
if [[ -z "$value" ]]; then
echo "Missing required variable: $name" >&2
exit 2
fi
case "$value" in
*192.0.2.*|*198.51.100.*|*203.0.113.*|*HOST-EXAMPLE*|*.example*)
echo "Refusing placeholder value for $name: $value" >&2
exit 2
;;
esac
}
usage() {
cat <<EOF
Usage:
@@ -67,9 +52,6 @@ if [[ -z "$FROM" || -z "$TO" ]]; then
exit 2
fi
require_live_value AW_BASE_URL
require_live_value AW_WORKTIME_HOST
mkdir -p "$OUT_DIR"
CSV_OUT="${OUT_DIR}/rdp-worktime-${FROM}_${TO}.csv"
JSON_OUT="${OUT_DIR}/rdp-worktime-${FROM}_${TO}.json"
@@ -98,9 +80,7 @@ import urllib.request
from datetime import datetime, timedelta, timezone
base, host, default_sample, max_sample, from_d, to_d, csv_out, json_out = sys.argv[1:9]
if not base:
raise SystemExit("AW_BASE_URL is required")
base = base.rstrip("/")
base = (base or "http://192.0.2.13:5600").rstrip("/")
if not base.endswith("/api/0"):
base = base + "/api/0"
default_sample = max(1.0, float(default_sample))
+5 -29
View File
@@ -43,27 +43,11 @@ configure_detmir_env() {
fi
fi
export DETMIR_DLP_ENABLED="${DETMIR_DLP_ENABLED:-${AW_DLP_ENABLED:-false}}"
require_live_value DETMIR_AW_API
require_live_value DETMIR_WORKTIME_URL
require_live_value DETMIR_ONE_C_URL
require_live_value DETMIR_RDP_HOST
require_live_value DETMIR_HOSTNAME
}
require_live_value() {
local name="$1"
local value="${!name:-}"
if [[ -z "${value}" ]]; then
printf 'Missing required live contour variable: %s. Set it in %s or the environment.\n' "${name}" "${ENV_FILE}" >&2
exit 2
fi
case "${value}" in
*192.0.2.*|*198.51.100.*|*203.0.113.*|*HOST-EXAMPLE*|*.example*)
printf 'Refusing placeholder value for %s: %s\n' "${name}" "${value}" >&2
exit 2
;;
esac
export DETMIR_AW_API="${DETMIR_AW_API:-http://192.0.2.13:5600/api/0}"
export DETMIR_WORKTIME_URL="${DETMIR_WORKTIME_URL:-http://192.0.2.13:5610}"
export DETMIR_ONE_C_URL="${DETMIR_ONE_C_URL:-http://192.0.2.2:8710}"
export DETMIR_RDP_HOST="${DETMIR_RDP_HOST:-198.51.100.18}"
export DETMIR_HOSTNAME="${DETMIR_HOSTNAME:-HOST-EXAMPLE}"
}
write_summary() {
@@ -80,7 +64,6 @@ write_summary() {
printf 'DETMIR_HOSTNAME=%s\n' "${DETMIR_HOSTNAME}"
printf 'DETMIR_GATEWAY_HOST=%s\n' "${DETMIR_GATEWAY_HOST}"
printf 'DETMIR_PORTAL_URL=%s\n' "${DETMIR_PORTAL_URL}"
printf 'DETMIR_DLP_ENABLED=%s\n' "${DETMIR_DLP_ENABLED}"
printf 'DETMIR_DLP_COMMAND=%s\n' "${DETMIR_DLP_COMMAND}"
printf 'DETMIR_DISABLE_PORTAL_CHECK=%s\n' "${DETMIR_DISABLE_PORTAL_CHECK:-0}"
printf 'DETMIR_DISABLE_DLP_HEALTH_CHECK=%s\n' "${DETMIR_DISABLE_DLP_HEALTH_CHECK:-0}"
@@ -198,12 +181,5 @@ if [[ "${RUN_REGISTRY_CHECK:-0}" == "1" ]] && [[ -x "${REPO_ROOT}/scripts/regist
fi
fi
if [[ "${RUN_RESILIENCE_CHECK:-0}" == "1" ]] && [[ -f "${REPO_ROOT}/scripts/detmir_resilience_check.sh" ]]; then
resilience_mode="${RESILIENCE_CHECK_MODE:-repo}"
if ! run_and_log "detmir-resilience-check" bash "${REPO_ROOT}/scripts/detmir_resilience_check.sh" "--${resilience_mode}"; then
status=1
fi
fi
printf 'final_status: %s\n' "$([[ "${status}" -eq 0 ]] && printf ok || printf fail)" | tee -a "${OUTPUT_DIR}/SUMMARY.md"
exit "${status}"