Steps 3-4 of the onboarding plan, plus the sibling-product reconciliation seams. Ingest (compliance-agent/src/ingest, #120): - ingest_all / ingest_artifact normalize each artifact to a working path + metadata. Every blob is SHA-256 hashed (content-addressed store, dedup) — that digest is also the tramiton reconciliation key. - git via GitOps reuse; zip archives + mobile packages extracted; firmware stored as blob; live URL / plaintext / container = metadata only. - IngestContext decoupled from the full AgentConfig (testable in isolation). Classify (compliance-agent/src/classify, #121): - FirmwareDetector port + TramitonCli (shell out `tramiton detect --json`, parse a mirrored BuildPlan subset — no dependency on the proprietary crate) + a deterministic MockFirmwareDetector so CI never needs the binary. - HeuristicClassifier: artifact-kind priors + source-marker fingerprinting (web/backend/mobile/desktop/PLC). - classify_target merges + ranks verdicts into a Classification. Suite-integration seams (compliance-core, #135/#136/#137): - Model: ExternalRef/ExternalSystem (reconcile with tramiton/werkpilot/breakpilot), ComplianceProfile/ComplianceFramework + default_compliance_profile per type. - Ports: EvidenceProvider (fetch external SBOM/VEX/lock/attestation) and ControlsProvider (built-in OSCAL vs breakpilot RAG). - TargetType now derives Hash; AgentConfig gains artifact_store_base_path. 44 unit tests (23 core + 8 ingest + 13 classify). Passes fmt + clippy -D warnings across agent, dashboard (server + web), and mcp. Additive; legacy paths untouched. Refs #118, #120, #121, #135, #136, #137. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
62 lines
2.4 KiB
Rust
62 lines
2.4 KiB
Rust
use secrecy::SecretString;
|
|
use serde::{Deserialize, Serialize};
|
|
|
|
#[derive(Clone, Debug)]
|
|
pub struct AgentConfig {
|
|
pub mongodb_uri: String,
|
|
pub mongodb_database: String,
|
|
pub litellm_url: String,
|
|
pub litellm_api_key: SecretString,
|
|
pub litellm_model: String,
|
|
pub litellm_embed_model: String,
|
|
pub github_token: Option<SecretString>,
|
|
pub github_webhook_secret: Option<SecretString>,
|
|
pub gitlab_url: Option<String>,
|
|
pub gitlab_token: Option<SecretString>,
|
|
pub gitlab_webhook_secret: Option<SecretString>,
|
|
pub jira_url: Option<String>,
|
|
pub jira_email: Option<String>,
|
|
pub jira_api_token: Option<SecretString>,
|
|
pub jira_project_key: Option<String>,
|
|
pub searxng_url: Option<String>,
|
|
pub nvd_api_key: Option<SecretString>,
|
|
pub agent_port: u16,
|
|
pub scan_schedule: String,
|
|
pub cve_monitor_schedule: String,
|
|
pub git_clone_base_path: String,
|
|
/// Base directory for content-addressed artifact blobs and per-run working
|
|
/// dirs (`<base>/blobs/<sha[0:2]>/<sha>`, `<base>/work/<target>/<artifact>/`).
|
|
pub artifact_store_base_path: String,
|
|
pub ssh_key_path: String,
|
|
pub keycloak_url: Option<String>,
|
|
pub keycloak_realm: Option<String>,
|
|
pub keycloak_admin_username: Option<String>,
|
|
pub keycloak_admin_password: Option<SecretString>,
|
|
// Pentest defaults
|
|
pub pentest_verification_email: Option<String>,
|
|
pub pentest_imap_host: Option<String>,
|
|
pub pentest_imap_port: Option<u16>,
|
|
/// Use implicit TLS (IMAPS, port 993) instead of plain IMAP.
|
|
pub pentest_imap_tls: bool,
|
|
pub pentest_imap_username: Option<String>,
|
|
pub pentest_imap_password: Option<SecretString>,
|
|
/// Static bearer for the cross-tenant admin endpoints under
|
|
/// `/api/v1/admin/*`. When `None`, those endpoints are not
|
|
/// mounted at all (defense-in-depth: ops endpoints never reach
|
|
/// any auth path if no operator has explicitly opted in).
|
|
pub admin_api_token: Option<SecretString>,
|
|
/// Live tenant-registry URL the scheduler consults for the list
|
|
/// of tenants to iterate. When `None` or unreachable, scheduler
|
|
/// falls back to `SCHEDULER_TENANT_IDS` env (M7.2-C).
|
|
pub tenant_registry_url: Option<String>,
|
|
}
|
|
|
|
#[derive(Clone, Debug, Serialize, Deserialize)]
|
|
pub struct DashboardConfig {
|
|
pub mongodb_uri: String,
|
|
pub mongodb_database: String,
|
|
pub agent_api_url: String,
|
|
pub dashboard_port: u16,
|
|
pub mcp_endpoint_url: Option<String>,
|
|
}
|