/** * Reporter + Receiver install/verify/teardown plan builder. * * Given a DiscoverySnapshot + user args, produce an `AdvisePlan` that * covers the whole lifecycle for one forwarder kind. The plan is pure * data — rendering to markdown is the render layer's job. * * The same builder serves both apps. The current chart format unifies * around a single Receiver workload with two opt-in feature flags: * - `optimize`: compact events (reduction varies by destination and by the * events themselves). The losslessness is not a property of the encoding * alone: it holds only where the DESTINATION has the 10x expander installed * to expand events again at read time, meaning the Splunk app or the l1es * Elasticsearch/OpenSearch plugin. Destinations with no expander (Datadog, * CloudWatch) cannot use the flag at all, and on ClickHouse the lever is * offload rather than compaction. See `./compaction-support.ts`. * - `readOnly` — emit metrics, do NOT write events back through the * forwarder (passive observation). * The flags are mutually exclusive at the chart level. AdvisorApp keeps * a thin distinction at the user-facing surface: `reporter` is sugar * for "Receiver with readOnly=true" (different release-name default, * different verify wording, blocks optimize since there are no * write-back events to encode); `receiver` exposes the flags directly. */ import type { DiscoverySnapshot, ForwarderKind, MetricsBackendKind, BackendCredentialConfig } from '../discovery/types.js'; import type { AdvisePlan } from './types.js'; import { type OutputDestination } from './reporter-forwarders.js'; export type AdvisorApp = 'reporter' | 'receiver'; /** * Deployment shape — orthogonal to forwarder kind. * inline = replace the user's forwarder deployment with a * log10x-repackaged version of the same chart (tenx baked * in as a processor/filter/init-container). * standalone = install log10x/reporter-10x as a parallel DaemonSet * that bundles its own fluent-bit. Does NOT touch the * user's forwarder. Report-mode only. * The user's detected forwarder kind is still surfaced in the plan when * shape='standalone' — as context, not as the install target. */ export type DeploymentShape = 'inline' | 'standalone'; export interface ReporterAdviseArgs { snapshot: DiscoverySnapshot; /** * Which app this plan installs. Default: 'reporter'. * - 'reporter' → standalone dedicated fluent-bit DaemonSet, read-only * - 'receiver' → sidecar inside the user's existing forwarder * Deployment shape is derived from app; no `shape` arg. */ app?: AdvisorApp; /** Forwarder to target. If omitted, uses the snapshot's recommendation. */ forwarder?: ForwarderKind; /** Helm release name. Default: `my-${app}`. */ releaseName?: string; /** Target namespace. Default: snapshot's suggestedNamespace. */ namespace?: string; /** * Log10x license JWT — mints from `POST /api/v1/license/demo` (anonymous) * or `POST /api/v1/license` (Auth0-authed). Maps to the chart's * `log10xLicenseJwt` value. Required for a complete install plan. */ licenseJwt?: string; /** * True when the JWT came from the demo endpoint. Drives the secret-vs-inline * decision in the chart values renderer: demo licenses inline the JWT * (one-step setup, transient); real licenses point the chart at an * out-of-band Kubernetes Secret the user creates before `helm upgrade`. */ isDemoLicense?: boolean; /** Output destination flavor. Default: 'mock' (safe for dogfooding). */ destination?: OutputDestination; /** Host for non-mock destinations (ES endpoint, Splunk HEC host, etc.). */ outputHost?: string; /** Splunk HEC token if destination=splunk. */ splunkHecToken?: string; /** * Enable encoded event output (compact encoded form; the reduction varies * by destination and by the events). Only meaningful when app='receiver'; * blocks when app='reporter' (Reporter has no write-back path to * encode events on). Maps to `tenx.optimize: true` in every * supported chart's values.yaml. * * Reading those events back needs the destination's 10x expander, so a plan * that compacts states that prerequisite in preflight, and a destination * with no expander to install blocks the flag outright. */ optimize?: boolean; /** * Read-only mode (Receiver app only). When true, the receiver * publishes TenXSummary metrics but does NOT write events back * through the forwarder. Maps to `tenx.readOnly: true` in every * supported chart's values.yaml. Silently ignored when app='reporter' * — that app sets readOnly implicitly (Reporter IS read-only by * definition). */ readOnly?: boolean; /** * Metrics backends the engine emits TenXSummary to. Multi-destination * — a user can report to log10x SaaS AND their own Datadog/Prom/etc. * simultaneously. Each entry maps to a `@run/output/metric/` * CLI arg appended to the engine's launch args, plus any vendor- * specific env vars (DD_API_KEY for datadog, ELASTIC_HOST for elastic, * etc.). Default: `['log10x']`. When `airgapped=true`, `'log10x'` * MUST NOT be in this list (engine sends nothing to log10x.com). */ backends?: MetricsBackendKind[]; /** * Per-backend credential configuration the wizard collected: secret * name + plain-value overrides. The renderer threads this into the * `tenx.extraEnv` block as `valueFrom.secretKeyRef` references. * When unset for a selected backend, the renderer falls back to * `-credentials` for the secret name and per-backend defaults * for plain values. */ backendCredentials?: Partial>; /** * Run the engine fully airgapped — no outbound calls to log10x.com * (no telemetry, no online license check, no update probes). Engine * emits only to the user-configured `backend`. Reporter chart maps * this to top-level `airgapped: true`; Receiver wires it via the * `TENX_AIRGAPPED=true` env var on the engine sidecar. * * Hard product constraint surfaced at plan-render time, NOT blocked: * demo / limited licenses cannot actually run airgapped — the engine * logs a warning and downgrades to online mode. The wizard surfaces * this softly and lets the user proceed without airgapped if they * decline to sign in. */ airgapped?: boolean; /** Skip install — for users who just want verify or teardown guidance. */ skipInstall?: boolean; /** Skip teardown. */ skipTeardown?: boolean; /** Skip verify. */ skipVerify?: boolean; } /** Produce the plan. Never throws — surfaces missing input as `blockers`. */ export declare function buildReporterPlan(args: ReporterAdviseArgs): Promise;