Skip to content

stream

stream

Long-running event-stream verbs — watch, simple-clearance.

watch is a state-only reader that multiplexes the DNS/audit/NFLOG sources into one JSON-lines feed; it runs confined to its state_dir lane. simple-clearance is a controller that invokes Podman and verdict subprocesses, so it does not use the reader's filesystem policy. Their heavy machinery (watch / simple_clearance) is imported inside the handler bodies, so wiring these verbs — or resolving their group module for --help — pulls in none of it.

WATCH = CommandDef(name='watch', help='Stream shield events — audit log, NFLOG packets, and DNS blocks on the dnsmasq tiers', handler=_handle_watch, extras=NEEDS_CTR, args=(CONTAINER_ARG,)) module-attribute

SIMPLE_CLEARANCE = CommandDef(name='simple-clearance', help='Terminal clearance fallback — prompts operator for each blocked connection (no D-Bus)', handler=_handle_simple_clearance, extras=NEEDS_CTR, args=(CONTAINER_ARG,)) module-attribute