/** * log10x_emit_sample_plan — step 2 of the fenced POC. * * Renders a shell script that reads a log sample out of the user's own SIEM, * with the user's own credentials, on the user's own machine, and writes it * to plain text files. This server does not run it and could not: in the * fenced profile the process it lives in has no network at all. * * The split is the whole design. Code that sees log data (this server, the * engine it spawns) has no network; code that has network (the user's `aws`, * the user's `curl`) is not ours. An egress allowlist would have been the * obvious alternative and does not hold: an allowlist constrains hosts, but * tenancy is chosen by the credential inside TLS, so vendor code carrying an * attacker's own key could write a user's logs to the attacker's tenant * through an allowed host. `--network none` is checkable; an allowlist is a * promise. See `lib/fenced.ts`. * * What makes the script trustworthy is that it is short, stereotyped and * read-only, and that the reviewer only has to read it once: one API per * script, every argument single-quoted, every sub-window listed as a literal * timestamp in the header, and no vendor hostname anywhere in it (enforced at * render time by `assertNoVendorHost`, and by a regression test per SIEM). * * The sampling matches `log10x_poc_from_siem` bucket for bucket — same * `randomTimeBuckets`, same `perBucketCap`, same connector bucket counts — * so a fenced POC and a credentialed POC over the same window differ because * the logs differ, not because two samplers disagreed. */ import { z } from 'zod'; import { type StructuredOutput } from '../lib/output-types.js'; /** Filename the emitted script lands under, and the name the docs use. */ export declare const SAMPLE_SCRIPT_FILE_NAME = "export-sample.sh"; export declare const emitSamplePlanSchema: { siem: z.ZodEnum<["cloudwatch", "splunk", "elasticsearch", "opensearch", "datadog"]>; window: z.ZodDefault; target_event_count: z.ZodDefault; scope: z.ZodOptional; query: z.ZodOptional; output_dir: z.ZodOptional; write_script: z.ZodDefault; }; export interface EmitSamplePlanArgs { siem: string; window?: string; target_event_count?: number; scope?: string; query?: string; output_dir?: string; write_script?: boolean; } export declare function executeEmitSamplePlan(args: EmitSamplePlanArgs): Promise;