Files
ja4sentinel/internal/logging/service_logger.go
Jacquin Antoine efd4481729 feat: implémentation complète du pipeline JA4 + Docker + tests
Nouveaux modules:
- cmd/ja4sentinel/main.go : point d'entrée avec pipeline capture→parse→fingerprint→output
- internal/config/loader.go : chargement YAML + env (JA4SENTINEL_*) + validation
- internal/tlsparse/parser.go : extraction ClientHello avec suivi d'état de flux (NEW/WAIT_CLIENT_HELLO/JA4_DONE)
- internal/fingerprint/engine.go : génération JA4/JA3 via psanford/tlsfingerprint
- internal/output/writers.go : StdoutWriter, FileWriter, UnixSocketWriter, MultiWriter

Infrastructure:
- Dockerfile (multi-stage), Dockerfile.dev, Dockerfile.test-server
- Makefile (build, test, lint, docker-build-*)
- docker-compose.test.yml pour tests d'intégration
- README.md (276 lignes) avec architecture, config, exemples

API (api/types.go):
- Ajout Close() aux interfaces Capture et Parser
- Ajout FlowTimeoutSec dans Config (défaut: 30s, env: JA4SENTINEL_FLOW_TIMEOUT)
- ServiceLog: +Timestamp, +TraceID, +ConnID
- LogRecord: champs flatten (ip_meta_*, tcp_meta_*, ja4*)
- Helper NewLogRecord() pour conversion TLSClientHello+Fingerprints→LogRecord

Architecture (architecture.yml):
- Documentation module logging + interfaces LoggerFactory/Logger
- Section service.systemd complète (unit, security, capabilities)
- Section logging.strategy (JSON lines, champs, règles)
- api.Config: +FlowTimeoutSec documenté

Fixes/cleanup:
- Suppression internal/api/types.go (consolidé dans api/types.go)
- Correction imports logging (ja4sentinel/api)
- .dockerignore / .gitignore
- config.yml.example

Tests:
- Tous les modules ont leurs tests (*_test.go)
- Tests unitaires : capture, config, fingerprint, output, tlsparse
- Tests d'intégration via docker-compose.test.yml

Build:
- Binaires dans dist/ (make build → dist/ja4sentinel)
- Docker runtime avec COPY --from=builder /app/dist/

Co-authored-by: Qwen-Coder <qwen-coder@alibabacloud.com>
2026-02-25 20:02:52 +01:00

121 lines
2.9 KiB
Go

// Package logging provides structured logging for ja4sentinel service components
package logging
import (
"encoding/json"
"fmt"
"log"
"os"
"strings"
"sync"
"time"
"ja4sentinel/api"
)
// ServiceLogger handles structured logging for the ja4sentinel service
type ServiceLogger struct {
level string
mutex sync.Mutex
out *log.Logger
formatter func(api.ServiceLog) ([]byte, error)
}
// NewServiceLogger creates a new service logger
func NewServiceLogger(level string) *ServiceLogger {
logger := &ServiceLogger{
level: strings.ToLower(level),
out: log.New(os.Stdout, "", 0),
formatter: func(s api.ServiceLog) ([]byte, error) {
logData := map[string]interface{}{
"timestamp": time.Now().UnixNano(),
"level": strings.ToUpper(s.Level),
"component": s.Component,
"message": s.Message,
}
if s.Details != nil && len(s.Details) > 0 {
for k, v := range s.Details {
logData[k] = v
}
}
return json.Marshal(logData)
},
}
return logger
}
// Log emits a structured log entry to stdout in JSON format
func (l *ServiceLogger) Log(component, level, message string, details map[string]string) {
if !l.isLogLevelEnabled(level) {
return
}
// Lock to prevent concurrent writes to stdout
l.mutex.Lock()
defer l.mutex.Unlock()
serviceLog := api.ServiceLog{
Level: level,
Component: component,
Message: message,
Details: details,
}
jsonData, err := l.formatter(serviceLog)
if err != nil {
// Fallback to simple logging if JSON formatting fails
fmt.Printf(`{"timestamp":%d,"level":"ERROR","component":"logging","message":"%s","original_message":"%s"}`,
time.Now().UnixNano(), err.Error(), message)
return
}
fmt.Println(string(jsonData))
}
// Debug logs a debug level entry
func (l *ServiceLogger) Debug(component, message string, details map[string]string) {
if l.isLogLevelEnabled("debug") {
l.Log(component, "DEBUG", message, details)
}
}
// Info logs an info level entry
func (l *ServiceLogger) Info(component, message string, details map[string]string) {
if l.isLogLevelEnabled("info") {
l.Log(component, "INFO", message, details)
}
}
// Warn logs a warning level entry
func (l *ServiceLogger) Warn(component, message string, details map[string]string) {
if l.isLogLevelEnabled("warn") {
l.Log(component, "WARN", message, details)
}
}
// Error logs an error level entry
func (l *ServiceLogger) Error(component, message string, details map[string]string) {
if l.isLogLevelEnabled("error") {
l.Log(component, "ERROR", message, details)
}
}
// isLogLevelEnabled checks if a log level should be emitted based on configured level
func (l *ServiceLogger) isLogLevelEnabled(messageLevel string) bool {
switch l.level {
case "debug":
return true
case "info":
return messageLevel != "debug"
case "warn":
return messageLevel != "debug" && messageLevel != "info"
case "error":
return messageLevel == "error"
default:
return false // If level is invalid, don't log anything
}
}