/** * Local-source POC tool: pulls log lines from kubectl or from local * files/globs and renders a cost-optimization report without touching * any log-analyzer API. * * Distinct from `log10x_poc_from_siem`: * - No vendor credentials needed (kubeconfig, or plain file reads) * - Cost framing is an industry-pricing matrix (Datadog list, * Splunk list, CloudWatch, OpenSearch), NOT a prediction of any * specific bill — we only see the sampled slice, not * CloudTrail / ALB logs / VM-hosted apps that the SIEM ingests * - Synchronous (the pull is fast); no snapshot lifecycle * * `source: "file"` is the serverless-estate path: a host with no * cluster (100% Lambda shops, VMs, a downloaded log bundle) samples * from `paths` instead of pods. * * Sample-composition table forces the user to declare the sample * representative: "70% of bytes come from your-noisy-service" surfaces * up-front so the prospect can either confirm or widen scope before * trusting the savings projection. */ import { z } from 'zod'; import { type StructuredOutput } from '../lib/output-types.js'; import { type SiemId } from '../lib/siem/pricing.js'; export declare const REPORT_FILE_NAME = "log10x-poc-report.html"; /** * Markdown copy of the plan, written alongside the HTML report in the fenced * profile only. * * The fenced profile's honest residual is that the ANSWER leaves the fence — * any tool that answers leaks its answer, and the plan is read by a human in * a chat window that is not inside the container. Nothing can change that. * What can change is where the detail lives: the full plan lands on the * mounted output directory as a file the user controls, so the chat transcript * does not have to be the only copy, and a user who wants to keep pattern * bodies off a hosted model's context has somewhere to read them instead. */ export declare const PLAN_FILE_NAME = "plan.md"; export declare const pocFromLocalSchema: { source: z.ZodDefault>>; path: z.ZodOptional; siem: z.ZodOptional>; forwarder: z.ZodOptional; workload: z.ZodOptional; report_annotations: z.ZodOptional>; namespace: z.ZodDefault>; paths: z.ZodOptional>; window: z.ZodDefault>; per_pod_limit: z.ZodDefault>; max_pods: z.ZodDefault>; retriever_installed: z.ZodDefault>; allow_lossy: z.ZodDefault>; target_percent_reduction: z.ZodOptional; budget_usd_monthly: z.ZodOptional; budget_gb_monthly: z.ZodOptional; exception_services: z.ZodOptional>; pin_services: z.ZodOptional>>; pin_patterns: z.ZodOptional>>; }; export interface PocFromLocalArgs { source?: 'kubectl' | 'file'; path?: string; siem?: SiemId; forwarder?: string; workload?: string; report_annotations?: Record; namespace?: string; paths?: string[]; window?: string; per_pod_limit?: number; max_pods?: number; ai_prettify?: boolean; retriever_installed?: boolean; allow_lossy?: boolean; target_percent_reduction?: number; budget_usd_monthly?: number; budget_gb_monthly?: number; exception_services?: string[]; pin_services?: Record; pin_patterns?: Record; } export declare function executePocFromLocal(args: PocFromLocalArgs): Promise;