pub struct ReportAgentFactSummary {Show 18 fields
pub api_version: String,
pub kind: String,
pub report_id: String,
pub agent_id: String,
pub instance_id: String,
pub content_digest: String,
pub revision: i64,
pub observed_at: String,
pub os: String,
pub arch: String,
pub process_count: i64,
pub process_executables: Vec<String>,
pub packages: Vec<String>,
pub listen_ports: Vec<String>,
pub host_id: String,
pub host_name: String,
pub network_addresses: Vec<String>,
pub reported_at: String,
}Expand description
agentd → 网关的事实摘要上报(控制面)。
与数据面上的原文快照(ReportDiscoverySnapshot)分工不同,不是同一条路:
摘要只服务用途推断(网关侧按规则表算),去重后 10~30 KB,走已认证的控制面;
原文快照一台几百 KB,走数据面给中心做资产整理。所以网关只接摘要。
幂等键是内容摘要,不是 revision(后者每轮 refresh 无条件 +1)。
agentd 无条件周期全量上报,判重归网关:网关用
wist_contracts::fact_summary::FactContent::content_digest 从收到的内容自己算摘要,
以此判重。content_digest 字段因此只是 agent 的声明:
与网关算出来的不一致时会记 FactDigestMismatch 告警(可能只是版本偏差,不拒收)。
Fields§
§api_version: String§kind: String§report_id: String§agent_id: String§instance_id: String§content_digest: Stringagent 侧声明的内容摘要。不是判重键:网关从下列内容字段自算,此值只作版本偏差的金丝雀。
revision: i64仅留痕:快照 revision 每轮 refresh 无条件 +1,网关不据它判重。
observed_at: String仅留痕:观察到的事实属于哪一刻(快照生成时间)。
os: String§arch: String§process_count: i64仅留痕:去重前的进程条数(去重会毁掉基数,留一个原始计数备查),不进摘要。
process_executables: Vec<String>去重后的进程可执行标识。注意两边不同源:
macOS 是 ps -axo comm= 给的完整路径,Linux 是 /proc/{pid}/comm(只有 basename)。
packages: Vec<String>已装包名(仅 linux;macOS 侧待定)。
listen_ports: Vec<String>§host_id: String主机标识(发现里 host 方向的 host.id)。
host_name: String主机名(host.name)。
network_addresses: Vec<String>网卡地址(每块网卡一条,形如 en0 192.168.1.5/24)。
reported_at: StringImplementations§
Source§impl ReportAgentFactSummary
impl ReportAgentFactSummary
pub fn new_agent_facts( report_id: String, agent_id: String, instance_id: String, content_digest: String, revision: i64, observed_at: String, os: String, arch: String, process_count: i64, process_executables: Vec<String>, packages: Vec<String>, listen_ports: Vec<String>, reported_at: String, ) -> Self
Trait Implementations§
Source§impl Clone for ReportAgentFactSummary
impl Clone for ReportAgentFactSummary
Source§impl Debug for ReportAgentFactSummary
impl Debug for ReportAgentFactSummary
Source§impl<'de> Deserialize<'de> for ReportAgentFactSummary
impl<'de> Deserialize<'de> for ReportAgentFactSummary
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
Deserialize this value from the given Serde deserializer. Read more
Source§impl PartialEq for ReportAgentFactSummary
impl PartialEq for ReportAgentFactSummary
Source§impl Serialize for ReportAgentFactSummary
impl Serialize for ReportAgentFactSummary
impl StructuralPartialEq for ReportAgentFactSummary
Auto Trait Implementations§
impl Freeze for ReportAgentFactSummary
impl RefUnwindSafe for ReportAgentFactSummary
impl Send for ReportAgentFactSummary
impl Sync for ReportAgentFactSummary
impl Unpin for ReportAgentFactSummary
impl UnsafeUnpin for ReportAgentFactSummary
impl UnwindSafe for ReportAgentFactSummary
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more