/** * federation/audit.ts — AuditService: NDJSON log of every * federation decision. * * F-038 — ported from ruflo * `v3/@claude-flow/plugin-agent-federation/src/domain/services/audit-service.ts` * stripped to the parts the skeleton needs: * * - record(envelope, decision) appends ONE NDJSON line to * `.harness/federation-audit.log`. * - When the file exceeds 10 MB, it rotates to * `.harness/federation-audit.log.1` (single generation). * - tail() reads the last N lines for the `federation_status` MCP tool. * - size() returns the on-disk file size for the status payload. * * Writes are synchronous (fs.appendFileSync) — the skeleton is * in-process and not throughput-bound; an async path would only * complicate testing. * * The `.harness/` directory is created on first write. The audit * log file is added to `.gitignore` by the Makefile/install step. */ /** Default audit log path — colocated with the rest of `.harness/`. */ export declare const DEFAULT_AUDIT_PATH = ".harness/federation-audit.log"; /** Decisions recorded by the orchestrator — matches the schema the * `federation_status` MCP tool reads back. */ export type AuditDecision = { allowed: true; reason: string; } | { allowed: false; reason: string; }; export interface AuditEntry { readonly ts: string; readonly envelopeId: string; readonly sourceNodeId: string; readonly targetNodeId: string; readonly messageType: string; readonly nonce: string; readonly allowed: boolean; readonly reason: string; readonly layer: "trust" | "policy" | "hmac" | "budget" | "received" | "sent"; readonly nodeId: string; } export interface AuditServiceOpts { /** Override the audit file path (defaults to .harness/federation-audit.log). */ readonly path?: string; /** Local nodeId stamped into every entry. */ readonly nodeId: string; } export declare class AuditService { private readonly path; private readonly nodeId; private rotated; constructor(opts: AuditServiceOpts); getPath(): string; /** Append an NDJSON line. Triggers rotation if the file would * exceed the threshold after the write. */ record(entry: Omit): void; /** Rotate the current log to `.log.1`. Subsequent writes go to a * fresh `.log` file. Idempotent within a single service lifetime. */ rotate(): void; /** On-disk size in bytes. 0 if file missing. */ size(): number; /** Read the last `n` entries from the log. Bounded by TAIL_MAX_BYTES. */ tail(n?: number): AuditEntry[]; /** Wipe the audit log. Test-only helper. */ reset(): void; } //# sourceMappingURL=audit.d.ts.map