| | | 1 | | namespace ProjectTemplate.Infrastructure.Data.Auditing; |
| | | 2 | | |
| | | 3 | | public static class ApplicationAuditReconciliationReasonCodes |
| | | 4 | | { |
| | | 5 | | public const string MissingCompletion = "MissingCompletion"; |
| | | 6 | | public const string MissingAuditBatch = "MissingAuditBatch"; |
| | | 7 | | public const string AuditRecordCountMismatch = "AuditRecordCountMismatch"; |
| | | 8 | | public const string ManifestVerificationFailed = "ManifestVerificationFailed"; |
| | | 9 | | public const string IncompleteGeneratedValues = "IncompleteGeneratedValues"; |
| | | 10 | | public const string MalformedCorrelation = "MalformedCorrelation"; |
| | | 11 | | public const string DuplicateCompletion = "DuplicateCompletion"; |
| | | 12 | | public const string StalePending = "StalePending"; |
| | | 13 | | public const string StaleRetryReady = "StaleRetryReady"; |
| | | 14 | | public const string DeliveryFailed = "DeliveryFailed"; |
| | | 15 | | public const string DeadLettered = "DeadLettered"; |
| | | 16 | | } |
| | | 17 | | |
| | | 18 | | public static class ApplicationAuditReconciliationSeverities |
| | | 19 | | { |
| | | 20 | | public const string Information = "Information"; |
| | | 21 | | public const string Warning = "Warning"; |
| | | 22 | | public const string Error = "Error"; |
| | | 23 | | public const string Critical = "Critical"; |
| | | 24 | | } |
| | | 25 | | |
| | | 26 | | public static class ApplicationAuditReconciliationRemediationStatuses |
| | | 27 | | { |
| | | 28 | | public const string Open = "Open"; |
| | | 29 | | public const string Acknowledged = "Acknowledged"; |
| | | 30 | | public const string Resolved = "Resolved"; |
| | | 31 | | } |
| | | 32 | | |
| | | 33 | | public sealed class ApplicationAuditReconciliationOptions |
| | | 34 | | { |
| | | 35 | | public bool Enabled { get; set; } = true; |
| | | 36 | | |
| | | 37 | | public bool RunWorker { get; set; } = true; |
| | | 38 | | |
| | | 39 | | public TimeSpan Interval { get; set; } = TimeSpan.FromMinutes(5); |
| | | 40 | | |
| | | 41 | | /// <summary> |
| | | 42 | | /// Gets or sets the maximum delay between reconciliation cycles after consecutive failures. The delay doubles for |
| | | 43 | | /// each additional consecutive failure, up to this value, and returns to <see cref="Interval"/> after a success. |
| | | 44 | | /// </summary> |
| | | 45 | | public TimeSpan MaximumCycleRetryDelay { get; set; } = TimeSpan.FromMinutes(30); |
| | | 46 | | |
| | | 47 | | public TimeSpan CompletionGracePeriod { get; set; } = TimeSpan.FromMinutes(2); |
| | | 48 | | |
| | | 49 | | public TimeSpan StalePendingThreshold { get; set; } = TimeSpan.FromMinutes(15); |
| | | 50 | | |
| | | 51 | | public TimeSpan StaleRetryReadyThreshold { get; set; } = TimeSpan.FromMinutes(15); |
| | | 52 | | |
| | | 53 | | public int MaximumBatchesPerRun { get; set; } = 1_000; |
| | | 54 | | |
| | | 55 | | public int MaximumMalformedRecordsPerRun { get; set; } = 1_000; |
| | | 56 | | |
| | | 57 | | public int HealthWarningFindingCount { get; set; } = 1; |
| | | 58 | | |
| | | 59 | | public int HealthUnhealthyFindingCount { get; set; } = 10; |
| | | 60 | | |
| | | 61 | | /// <summary> |
| | | 62 | | /// Gets or sets how long after the last successful reconciliation run the audit integrity health check reports |
| | | 63 | | /// <c>Degraded</c>. When <see langword="null"/>, three times <see cref="Interval"/> is used. |
| | | 64 | | /// </summary> |
| | | 65 | | /// <remarks> |
| | | 66 | | /// Freshness is only evaluated when <see cref="RunWorker"/> is <see langword="true"/>, because the last run time is |
| | | 67 | | /// tracked by the process that runs the scheduled reconciliation loop. A process that never completed a run, or |
| | | 68 | | /// whose worker stopped or keeps failing, therefore reports <c>Degraded</c> instead of a green check that reads |
| | | 69 | | /// zero findings indefinitely. |
| | | 70 | | /// </remarks> |
| | | 71 | | public TimeSpan? HealthStaleRunThreshold { get; set; } |
| | | 72 | | } |
| | | 73 | | |
| | | 74 | | public interface IApplicationAuditReconciler |
| | | 75 | | { |
| | | 76 | | Task<ApplicationAuditReconciliationSummary> ReconcileAsync( |
| | | 77 | | CancellationToken cancellationToken = default); |
| | | 78 | | |
| | | 79 | | Task<ApplicationAuditReconciliationSummary> GetSummaryAsync( |
| | | 80 | | CancellationToken cancellationToken = default); |
| | | 81 | | |
| | | 82 | | Task<IReadOnlyList<ApplicationAuditReconciliationFindingItem>> QueryFindingsAsync( |
| | | 83 | | ApplicationAuditReconciliationQuery request, |
| | | 84 | | CancellationToken cancellationToken = default); |
| | | 85 | | |
| | | 86 | | Task<ApplicationAuditReconciliationRemediationItem> RecordRemediationAsync( |
| | | 87 | | Guid findingId, |
| | | 88 | | ApplicationAuditReconciliationRemediationRequest request, |
| | | 89 | | CancellationToken cancellationToken = default); |
| | | 90 | | } |
| | | 91 | | |
| | | 92 | | public sealed record ApplicationAuditReconciliationSummary( |
| | | 93 | | bool Enabled, |
| | | 94 | | DateTime? LastRunUtc, |
| | | 95 | | long OpenFindingCount, |
| | | 96 | | long ErrorFindingCount, |
| | | 97 | | long CriticalFindingCount, |
| | | 98 | | long ManifestVerificationFailureCount, |
| | | 99 | | long MissingCompletionCount, |
| | | 100 | | long StaleDeliveryCount, |
| | | 101 | | long DeadLetterCount); |
| | | 102 | | |
| | | 103 | | public sealed record ApplicationAuditReconciliationQuery( |
| | | 104 | | string? ReasonCode = null, |
| | | 105 | | string? Severity = null, |
| | | 106 | | string? MutationBatchId = null, |
| | | 107 | | string? RemediationStatus = null, |
| | | 108 | | int MaximumResults = 100); |
| | | 109 | | |
| | | 110 | | public sealed record ApplicationAuditReconciliationFindingItem( |
| | | 111 | | Guid Id, |
| | | 112 | | string SchemaVersion, |
| | | 113 | | string FindingKey, |
| | | 114 | | string ReasonCode, |
| | | 115 | | string Severity, |
| | | 116 | | string MutationBatchId, |
| | | 117 | | string? Destination, |
| | | 118 | | string Guidance, |
| | | 119 | | string RemediationStatus, |
| | | 120 | | DateTime FirstObservedUtc, |
| | | 121 | | DateTime LastObservedUtc, |
| | | 122 | | DateTime? ResolvedUtc); |
| | | 123 | | |
| | | 124 | | public sealed record ApplicationAuditReconciliationRemediationRequest( |
| | | 125 | | string ActionCode, |
| | | 126 | | string ActorId, |
| | | 127 | | string? EvidenceReference = null, |
| | | 128 | | bool ResolveFinding = false); |
| | | 129 | | |
| | | 130 | | public sealed record ApplicationAuditReconciliationRemediationItem( |
| | | 131 | | Guid Id, |
| | | 132 | | Guid FindingId, |
| | | 133 | | string MutationBatchId, |
| | | 134 | | string ActionCode, |
| | | 135 | | string ActorId, |
| | | 136 | | string? EvidenceReference, |
| | | 137 | | DateTime RecordedUtc); |
| | | 138 | | |
| | 21 | 139 | | internal sealed record ApplicationAuditReconciliationCandidate( |
| | 21 | 140 | | string FindingKey, |
| | 21 | 141 | | string ReasonCode, |
| | 21 | 142 | | string Severity, |
| | 21 | 143 | | string MutationBatchId, |
| | 21 | 144 | | string? Destination, |
| | 21 | 145 | | string Guidance); |