Documentation
¶
Index ¶
- func NormalizeTeamSlug(raw string) string
- func PlatformMode() string
- func PublicCatalogEnabled() bool
- func ResolveDeployImageReference(image, namespace, teamSlug string) string
- func ValidateDeployImage(image, namespace, teamSlug, role string) error
- type AccessService
- func (s *AccessService) HandleAdapterCertificate(w http.ResponseWriter, r *http.Request)
- func (s *AccessService) HandleAdapterSession(w http.ResponseWriter, r *http.Request)
- func (s *AccessService) HandleGrantItemPath(w http.ResponseWriter, r *http.Request)
- func (s *AccessService) HandleRuntimeGrants(w http.ResponseWriter, r *http.Request)
- func (s *AccessService) HandleRuntimePolicy(w http.ResponseWriter, r *http.Request)
- func (s *AccessService) HandleRuntimeSessions(w http.ResponseWriter, r *http.Request)
- func (s *AccessService) HandleSessionItemPath(w http.ResponseWriter, r *http.Request)
- type DeploymentService
- func (s *DeploymentService) EnsureCatalogNamespace(ctx context.Context, namespace string) error
- func (s *DeploymentService) HandleAdminDeployments(w http.ResponseWriter, r *http.Request)
- func (s *DeploymentService) HandleDeploymentItem(w http.ResponseWriter, r *http.Request)
- func (s *DeploymentService) HandleDeployments(w http.ResponseWriter, r *http.Request)
- func (s *DeploymentService) ListAdminDeploymentSummaries(ctx context.Context, namespace string) ([]map[string]any, error)
- func (s *DeploymentService) ReconcileTeamNamespaceNetworkPolicies(ctx context.Context)
- type InventoryService
- type Principal
- type RegistryPushService
- type RuntimeServer
- func (s *RuntimeServer) Access() *AccessService
- func (s *RuntimeServer) AuthenticateUserAPIKey(ctx context.Context, rawKey string) (principal, bool, error)
- func (s *RuntimeServer) CreateUserAPIKey(ctx context.Context, userID, name string) (userAPIKeySummary, string, error)
- func (s *RuntimeServer) Deployments() *DeploymentService
- func (s *RuntimeServer) HandleActionRestart(w http.ResponseWriter, r *http.Request)
- func (s *RuntimeServer) HandleDashboardSummary(w http.ResponseWriter, r *http.Request)
- func (s *RuntimeServer) HandleRuntimeAgentPath(w http.ResponseWriter, r *http.Request)
- func (s *RuntimeServer) HandleRuntimeComponents(w http.ResponseWriter, r *http.Request)
- func (s *RuntimeServer) HandleRuntimeNamespaceItem(w http.ResponseWriter, r *http.Request)
- func (s *RuntimeServer) HandleRuntimeNamespaces(w http.ResponseWriter, r *http.Request)
- func (s *RuntimeServer) HandleRuntimeObservabilityLinks(w http.ResponseWriter, r *http.Request)
- func (s *RuntimeServer) HandleRuntimeObservabilityPrometheusQuery(w http.ResponseWriter, r *http.Request)
- func (s *RuntimeServer) HandleRuntimeServerEvents(w http.ResponseWriter, r *http.Request)
- func (s *RuntimeServer) HandleRuntimeServerItem(w http.ResponseWriter, r *http.Request)
- func (s *RuntimeServer) HandleRuntimeServers(w http.ResponseWriter, r *http.Request)
- func (s *RuntimeServer) HandleRuntimeTeamAgents(w http.ResponseWriter, r *http.Request, p principal, teamSlug string)
- func (s *RuntimeServer) HandleRuntimeTeamItemPath(w http.ResponseWriter, r *http.Request)
- func (s *RuntimeServer) HandleRuntimeTeams(w http.ResponseWriter, r *http.Request)
- func (s *RuntimeServer) Inventory() *InventoryService
- func (s *RuntimeServer) KubernetesAvailable() bool
- func (s *RuntimeServer) ListUserAPIKeys(ctx context.Context, userID string) ([]userAPIKeySummary, error)
- func (s *RuntimeServer) RegistryPush() *RegistryPushService
- func (s *RuntimeServer) RevokeUserAPIKey(ctx context.Context, userID, id string) (userAPIKeySummary, error)
- func (s *RuntimeServer) SetAuditWriter(writer auditWriter)
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func NormalizeTeamSlug ¶
NormalizeTeamSlug canonicalizes a team slug using the platform store rules shared with identity APIs.
func PlatformMode ¶
func PlatformMode() string
PlatformMode returns the configured platform tenancy mode, defaulting invalid or empty values to tenant mode.
func PublicCatalogEnabled ¶
func PublicCatalogEnabled() bool
PublicCatalogEnabled reports whether the runtime should expose public catalog behavior.
func ResolveDeployImageReference ¶
ResolveDeployImageReference expands short image names into the platform registry and namespace repository scope.
func ValidateDeployImage ¶
ValidateDeployImage enforces registry allow-list and namespace-scoped repository rules for deployment images.
Types ¶
type AccessService ¶
type AccessService struct {
// contains filtered or unexported fields
}
func (*AccessService) HandleAdapterCertificate ¶
func (s *AccessService) HandleAdapterCertificate(w http.ResponseWriter, r *http.Request)
HandleAdapterCertificate signs a client-generated CSR after verifying that its SPIFFE URI names a session owned by the authenticated principal.
func (*AccessService) HandleAdapterSession ¶
func (s *AccessService) HandleAdapterSession(w http.ResponseWriter, r *http.Request)
HandleAdapterSession issues (or reuses) an MCPAgentSession for an adapter call. The platform — not the adapter — picks the matching grant, caps the trust at the grant's ceiling, and writes the session resource. The adapter then uses the returned session to enroll a certificate for every request to the runtime gateway.
Errors:
- 400 when body decoding or input validation fails
- 401 when no Principal is on the request (auth middleware should reject first)
- 403 when no matching enabled grant is found, or the principal lacks the team
- 503 when Kubernetes is unavailable
func (*AccessService) HandleGrantItemPath ¶
func (s *AccessService) HandleGrantItemPath(w http.ResponseWriter, r *http.Request)
HandleGrantItemPath handles GET, DELETE, PATCH, and legacy enable or disable actions for one MCPAccessGrant.
func (*AccessService) HandleRuntimeGrants ¶
func (s *AccessService) HandleRuntimeGrants(w http.ResponseWriter, r *http.Request)
HandleRuntimeGrants lists and applies MCPAccessGrant resources within the caller's allowed namespace scope.
func (*AccessService) HandleRuntimePolicy ¶
func (s *AccessService) HandleRuntimePolicy(w http.ResponseWriter, r *http.Request)
HandleRuntimePolicy returns the rendered gateway policy for a server the caller can administer.
func (*AccessService) HandleRuntimeSessions ¶
func (s *AccessService) HandleRuntimeSessions(w http.ResponseWriter, r *http.Request)
HandleRuntimeSessions lists and applies MCPAgentSession resources within the caller's allowed namespace scope.
func (*AccessService) HandleSessionItemPath ¶
func (s *AccessService) HandleSessionItemPath(w http.ResponseWriter, r *http.Request)
HandleSessionItemPath handles GET, DELETE, PATCH, and legacy revoke or unrevoke actions for one MCPAgentSession.
type DeploymentService ¶
type DeploymentService struct {
// contains filtered or unexported fields
}
func (*DeploymentService) EnsureCatalogNamespace ¶
func (s *DeploymentService) EnsureCatalogNamespace(ctx context.Context, namespace string) error
EnsureCatalogNamespace creates or updates a catalog namespace with platform labels, security defaults, and ingress watch access.
func (*DeploymentService) HandleAdminDeployments ¶
func (s *DeploymentService) HandleAdminDeployments(w http.ResponseWriter, r *http.Request)
HandleAdminDeployments lists platform-visible deployments across namespaces for admins.
func (*DeploymentService) HandleDeploymentItem ¶
func (s *DeploymentService) HandleDeploymentItem(w http.ResponseWriter, r *http.Request)
HandleDeploymentItem deletes a user-managed Kubernetes deployment and service after namespace authorization.
func (*DeploymentService) HandleDeployments ¶
func (s *DeploymentService) HandleDeployments(w http.ResponseWriter, r *http.Request)
HandleDeployments lists and applies user-managed Kubernetes deployments for the caller's namespace scope.
func (*DeploymentService) ListAdminDeploymentSummaries ¶
func (s *DeploymentService) ListAdminDeploymentSummaries(ctx context.Context, namespace string) ([]map[string]any, error)
ListAdminDeploymentSummaries returns deployment summaries from all namespaces or one requested namespace.
func (*DeploymentService) ReconcileTeamNamespaceNetworkPolicies ¶
func (s *DeploymentService) ReconcileTeamNamespaceNetworkPolicies(ctx context.Context)
ReconcileTeamNamespaceNetworkPolicies refreshes default-deny NetworkPolicies for existing team namespaces so ingress controller namespace changes take effect without recreating teams.
type InventoryService ¶
type InventoryService struct {
// contains filtered or unexported fields
}
func (*InventoryService) HandleRuntimeTools ¶
func (s *InventoryService) HandleRuntimeTools(w http.ResponseWriter, r *http.Request)
HandleRuntimeTools returns a scoped, filterable catalog of tools across visible MCP servers.
type Principal ¶
type Principal = platformauth.Principal
Principal is the authenticated platform identity contract shared by runtime handlers.
func PublicCatalogFallback ¶
PublicCatalogFallback authenticates anonymous public-mode reads of the catalog collections.
func PublicCatalogPrincipal ¶
func PublicCatalogPrincipal() Principal
PublicCatalogPrincipal returns the synthetic principal used for unauthenticated public catalog reads.
type RegistryPushService ¶
type RegistryPushService struct {
// contains filtered or unexported fields
}
func (*RegistryPushService) HandleRegistryPushTransfer ¶
func (s *RegistryPushService) HandleRegistryPushTransfer(w http.ResponseWriter, r *http.Request)
HandleRegistryPushTransfer serves a one-time docker save tar to in-cluster helper pods.
func (*RegistryPushService) HandleRuntimeRegistryPush ¶
func (s *RegistryPushService) HandleRuntimeRegistryPush(w http.ResponseWriter, r *http.Request)
HandleRuntimeRegistryPush accepts a docker save tar and pushes it to the platform registry from inside the cluster.
type RuntimeServer ¶
type RuntimeServer struct {
// contains filtered or unexported fields
}
RuntimeServer composes runtime API dependencies for analytics, Kubernetes control-plane access, and platform identity.
func NewRuntimeServer ¶
func NewRuntimeServer(db clickhouse.Conn, dbName string, apiKeys map[string]struct{}, identity identityStore) (*RuntimeServer, error)
NewRuntimeServer creates a runtime server with Kubernetes access.
func (*RuntimeServer) Access ¶
func (s *RuntimeServer) Access() *AccessService
Access returns the grant/session capability owned by the runtime server.
func (*RuntimeServer) AuthenticateUserAPIKey ¶
func (s *RuntimeServer) AuthenticateUserAPIKey(ctx context.Context, rawKey string) (principal, bool, error)
AuthenticateUserAPIKey validates a raw user API key against the Kubernetes-backed key store.
func (*RuntimeServer) CreateUserAPIKey ¶
func (s *RuntimeServer) CreateUserAPIKey(ctx context.Context, userID, name string) (userAPIKeySummary, string, error)
CreateUserAPIKey stores a new hashed user API key and returns the one-time raw key value.
func (*RuntimeServer) Deployments ¶
func (s *RuntimeServer) Deployments() *DeploymentService
Deployments returns the deployment capability owned by the runtime server.
func (*RuntimeServer) HandleActionRestart ¶
func (s *RuntimeServer) HandleActionRestart(w http.ResponseWriter, r *http.Request)
HandleActionRestart restarts one or all Sentinel runtime components.
func (*RuntimeServer) HandleDashboardSummary ¶
func (s *RuntimeServer) HandleDashboardSummary(w http.ResponseWriter, r *http.Request)
HandleDashboardSummary returns analytics and live control-plane counters for the Sentinel dashboard.
func (*RuntimeServer) HandleRuntimeAgentPath ¶
func (s *RuntimeServer) HandleRuntimeAgentPath(w http.ResponseWriter, r *http.Request)
HandleRuntimeAgentPath reads, renames, deactivates, or reactivates one agent.
func (*RuntimeServer) HandleRuntimeComponents ¶
func (s *RuntimeServer) HandleRuntimeComponents(w http.ResponseWriter, r *http.Request)
HandleRuntimeComponents returns admin-only health details for Sentinel platform components.
func (*RuntimeServer) HandleRuntimeNamespaceItem ¶
func (s *RuntimeServer) HandleRuntimeNamespaceItem(w http.ResponseWriter, r *http.Request)
HandleRuntimeNamespaceItem returns one visible namespace record or synthetic catalog namespace entry.
func (*RuntimeServer) HandleRuntimeNamespaces ¶
func (s *RuntimeServer) HandleRuntimeNamespaces(w http.ResponseWriter, r *http.Request)
HandleRuntimeNamespaces lists namespaces visible to the caller, including catalog namespace entries for the current platform mode.
func (*RuntimeServer) HandleRuntimeObservabilityLinks ¶
func (s *RuntimeServer) HandleRuntimeObservabilityLinks(w http.ResponseWriter, r *http.Request)
func (*RuntimeServer) HandleRuntimeObservabilityPrometheusQuery ¶
func (s *RuntimeServer) HandleRuntimeObservabilityPrometheusQuery(w http.ResponseWriter, r *http.Request)
func (*RuntimeServer) HandleRuntimeServerEvents ¶
func (s *RuntimeServer) HandleRuntimeServerEvents(w http.ResponseWriter, r *http.Request)
HandleRuntimeServerEvents returns recent analytics events for a server the caller can administer.
func (*RuntimeServer) HandleRuntimeServerItem ¶
func (s *RuntimeServer) HandleRuntimeServerItem(w http.ResponseWriter, r *http.Request)
HandleRuntimeServerItem returns or retires one MCPServer after namespace authorization.
func (*RuntimeServer) HandleRuntimeServers ¶
func (s *RuntimeServer) HandleRuntimeServers(w http.ResponseWriter, r *http.Request)
HandleRuntimeServers lists and applies MCPServer resources within the caller's readable or publishable namespaces.
func (*RuntimeServer) HandleRuntimeTeamAgents ¶
func (s *RuntimeServer) HandleRuntimeTeamAgents(w http.ResponseWriter, r *http.Request, p principal, teamSlug string)
HandleRuntimeTeamAgents lists and creates governance agents under a team.
func (*RuntimeServer) HandleRuntimeTeamItemPath ¶
func (s *RuntimeServer) HandleRuntimeTeamItemPath(w http.ResponseWriter, r *http.Request)
HandleRuntimeTeamItemPath routes team detail and membership operations after role checks.
func (*RuntimeServer) HandleRuntimeTeams ¶
func (s *RuntimeServer) HandleRuntimeTeams(w http.ResponseWriter, r *http.Request)
HandleRuntimeTeams lists visible teams and lets admins create team identity records.
func (*RuntimeServer) Inventory ¶
func (s *RuntimeServer) Inventory() *InventoryService
Inventory returns the tool inventory capability owned by the runtime server.
func (*RuntimeServer) KubernetesAvailable ¶
func (s *RuntimeServer) KubernetesAvailable() bool
KubernetesAvailable reports whether Kubernetes-backed runtime endpoints can serve requests.
func (*RuntimeServer) ListUserAPIKeys ¶
func (s *RuntimeServer) ListUserAPIKeys(ctx context.Context, userID string) ([]userAPIKeySummary, error)
ListUserAPIKeys returns metadata for API keys owned by one platform user.
func (*RuntimeServer) RegistryPush ¶
func (s *RuntimeServer) RegistryPush() *RegistryPushService
RegistryPush returns the registry push transfer capability owned by the runtime server.
func (*RuntimeServer) RevokeUserAPIKey ¶
func (s *RuntimeServer) RevokeUserAPIKey(ctx context.Context, userID, id string) (userAPIKeySummary, error)
RevokeUserAPIKey marks a user's API key revoked and returns its final metadata.
func (*RuntimeServer) SetAuditWriter ¶
func (s *RuntimeServer) SetAuditWriter(writer auditWriter)
SetAuditWriter overrides the audit sink used by runtime mutation handlers.
Source Files
¶
- access_cache.go
- actions.go
- adapter.go
- adapter_certificate.go
- agent_enforcement.go
- agents.go
- audit.go
- capabilities.go
- components.go
- cross_team_grants.go
- deployments.go
- deps.go
- grant_handlers.go
- grants.go
- live_inventory.go
- namespaces.go
- observability.go
- platform_mode.go
- policy.go
- publish_policy.go
- registry_push.go
- registry_push_transfer.go
- server.go
- server_events.go
- servers.go
- session_handlers.go
- sessions.go
- subject_binding.go
- team_members.go
- teams.go
- tools.go
- user_keys.go
- visibility.go