/** * Classify a container image as a known forwarder kind (or log10x app). * * Image-string matching, highest-specificity first. We match on substrings * because registry host + tag vary wildly in the wild: * - `public.ecr.aws/fluent/fluent-bit:3.2` * - `cr.fluentbit.io/fluent/fluent-bit:3.2` * - `ghcr.io/log-10x/fluent-bit-10x:latest` * - `docker.elastic.co/beats/filebeat:8.15.0` * - `docker.elastic.co/logstash/logstash:8.15.0` * - `otel/opentelemetry-collector-contrib:0.108.0` * * Returns 'unknown' when nothing matches — callers can still surface the * raw image so a human can override. * * Vector is intentionally NOT classified as a forwarder the advisor can * install today: no log10x-repackaged Vector image ships, and the config * repo has no vector input/report modules. If a customer is running * Vector, it surfaces as `unknown` and the advisor falls back to asking * which supported forwarder to install. */ import type { ForwarderKind, Log10xAppKind } from './types.js'; /** Heuristic forwarder classifier. Order matters — specific before generic. */ export declare function classifyForwarderImage(image: string): ForwarderKind; /** * Classify a log10x app workload by its image + label set + helm chart. * * The most reliable signal in practice is the `helm.sh/chart` label, * which every log10x helm chart stamps (`retriever-10x-X.Y.Z`, * `cron-10x-X.Y.Z`, `fluentd-X.Y.Z`, `fluent-bit-X.Y.Z`, etc.). We * consult that first, then fall back to image/name heuristics for * customers who've stripped the chart label. */ export declare function classifyLog10xApp(image: string, labels: Record, helmChart?: string): Log10xAppKind; /** Is this image from the log10x image registries? */ export declare function isLog10xImage(image: string): boolean;