watch
watch
¶
shield watch — stream blocked-access events as JSON lines.
Tails the per-container audit log, (optionally) the NFLOG netlink socket, and the dnsmasq query log on the tiers that run dnsmasq. Clean exit on SIGINT or SIGTERM.
run_watch(state_dir, container)
¶
Stream blocked-access events as JSON lines to stdout.
The audit log and the NFLOG socket feed every tier; the dnsmasq query
log feeds only the tiers that run dnsmasq, so elsewhere the events carry
IP addresses and no domain. Uses select so a single thread can
multiplex the sources without blocking on any one of them.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
state_dir
|
Path
|
Per-container state directory. |
required |
container
|
str
|
Container name (for event metadata). |
required |
Raises:
| Type | Description |
|---|---|
SystemExit
|
If the container recorded no DNS tier. |