Traffic Intel (was dead code, now wired): - TrafficHook in listener accept path: cps/pps windows -> AttackDetector - auto-ban IPs below reputation threshold under attack ([detect.autoban]) - AlertDispatcher: webhook on attack state transition only (dedup), metrics AUTO_BANS_TOTAL / INTEL_* ; [detect.alert].webhook_url XDP SYN RST-challenge (Oubliette pattern, off by default): - G_SYN_CHALLENGE_ENABLED=0: kernel replies bad-ACK SYN-ACK via XDP_TX, spoofed sources stay silent, live clients answer RST with secret echo -> challenge_verified (LRU, sliding TTL); brute-force of marker impossible - maps challenge_verified/challenge_pending, STAT_CHALLENGE_*, all logic in xdp/core/syn_challenge.h (221 lines) XDP diagnostics (src/xdp/diagnostics.rs): - EnvironmentReport: kernel version/BTF/driver->AttachMode verdict, fail-fast before load on unsupported kernels; wired into CLI - SystemProbe trait for kernel-less testing fix: .gitignore 'bin/' matched src/bin/ — rampart.rs was never committed cargo build/clippy(-D warnings, --features xdp)/test green: 107 tests
72 lines
2 KiB
Rust
72 lines
2 KiB
Rust
#![allow(clippy::print_stdout, clippy::print_stderr)]
|
|
|
|
use clap::{Parser, Subcommand};
|
|
use rampart::cli::commands;
|
|
|
|
#[derive(Parser)]
|
|
#[command(name = "rampart-cli", about = "Rampart management CLI")]
|
|
struct Cli {
|
|
#[command(subcommand)]
|
|
command: Commands,
|
|
}
|
|
|
|
#[derive(Subcommand)]
|
|
enum Commands {
|
|
/// Show overall system status
|
|
Status,
|
|
/// Run full diagnostics
|
|
Doctor,
|
|
/// Get/set configuration
|
|
Config {
|
|
#[arg(required = false)]
|
|
key: Option<String>,
|
|
#[arg(required = false)]
|
|
value: Option<String>,
|
|
},
|
|
/// Manage blacklist
|
|
Blacklist {
|
|
#[command(subcommand)]
|
|
action: BlacklistAction,
|
|
},
|
|
/// Emergency mode
|
|
Emergency {
|
|
#[arg(value_enum)]
|
|
mode: EmergencyMode,
|
|
},
|
|
/// Gracefully drain a node
|
|
Drain { node: String },
|
|
}
|
|
|
|
#[derive(Subcommand)]
|
|
enum BlacklistAction {
|
|
Add { target: String, reason: Option<String> },
|
|
Remove { target: String },
|
|
List,
|
|
}
|
|
|
|
#[derive(clap::ValueEnum, Clone)]
|
|
enum EmergencyMode {
|
|
Enable,
|
|
Disable,
|
|
}
|
|
|
|
#[tokio::main]
|
|
async fn main() -> anyhow::Result<()> {
|
|
let cli = Cli::parse();
|
|
|
|
match cli.command {
|
|
Commands::Status => commands::status::run().await,
|
|
Commands::Doctor => commands::doctor::run().await,
|
|
Commands::Config { key, value } => commands::config::run(key, value).await,
|
|
Commands::Blacklist { action } => match action {
|
|
BlacklistAction::Add { target, reason } => commands::blacklist::add(target, reason).await,
|
|
BlacklistAction::Remove { target } => commands::blacklist::remove(target).await,
|
|
BlacklistAction::List => commands::blacklist::list().await,
|
|
},
|
|
Commands::Emergency { mode } => match mode {
|
|
EmergencyMode::Enable => commands::emergency::enable().await,
|
|
EmergencyMode::Disable => commands::emergency::disable().await,
|
|
},
|
|
Commands::Drain { node } => commands::drain::run(&node).await,
|
|
}
|
|
}
|