Conversation
Replace ToS-derived endpoint visibility with internal/external locality decided by ordered registry rules (tos_anonymized, prefixes, addresses or address files). Stats tables store src_locality/dst_locality pairs that map to ingress, egress, lateral, and transit. The canonical rules join the product identity as counts and digests, and table/contract versions bump.
Replace the visibility scope picker and srcVisibility/dstVisibility params with a shared direction filter (all, ingress, egress, lateral, transit) mapped to the new src_locality/dst_locality columns, with a Drizzle migration that keeps only locality-independent rollup rows.
Registry loading now checks locality rule syntax only, so one unreadable address file no longer breaks feed and pipeline for every dataset; the pipeline reads files for the datasets it runs. IPv4-mapped IPv6 prefixes, addresses and endpoints are canonicalized to IPv4. The unused Rust Direction enum is removed. datasets gains has_locality (Rust DDL and upsert, Drizzle migration, local schema). The dashboard hides the direction filter and queries all traffic for datasets without rules. Docs keep private address lists under data/ and fix the coordinated-subset example to use /16 prefixes. The 10m rollup joins the locality additivity check, and the locality migration test covers every stats table.
flamboh
added this pull request to stack #113
September 25, 2026 10:02
…files from the config directory
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Note
🤖 Claude Opus 5.5 on behalf of Oliver
ELI5
Instead of guessing "inside vs outside" from a network-specific anonymization flag, each dataset now lists rules for what counts as internal, and the dashboard can filter traffic by direction: incoming, outgoing, inside-to-inside, or neither.
Why
Endpoint "visibility" came from the anonymizer's ToS bits, which only works on our network and misclassifies known literal internal hosts. Direction (ingress/egress/lateral) is what analyses actually need.
Implementation
localityrules:tos_anonymized(the old behavior),prefixes(CIDRs),addresses(inline list or file). An endpoint is internal if any rule matches. Validation is strict; IPv4-mapped IPv6 is canonicalized.src_locality/dst_locality(internal/external/all) replacesrc_visibility/dst_visibility.daily_active_sourcesselection migrated to locality.datasets.has_locality).Review path
datasets.json:pipeline --dataset <id>for one day. Expected: rows usesrc_locality/dst_locality; the four directions sum exactly toall;datasets.has_locality = 1. Relative paths resolve from the repository root."locality": [...]at the top level of a pipeline config (a per-datasetlocalityinside a config is rejected), with a relative address file next to the config. Runpipeline --config <path>from another directory. Expected: the file resolves from the config's directory, and every dataset in the product getshas_locality = 1.netflow.sqlite(withsrc_visibilitycolumns and nohas_locality) underdata/, including one that reuses a current dataset ID. Expected: the dashboard lists only current products; the old DB is skipped and doesn't shadow the current one or break the listing.Edge cases and decisions
bucket_coverageordatasets.has_locality, or that has a stats table without both locality columns. It doesn't error on them.--src-locality/--dst-locality,daily_active_sources) without rules is rejected, because every endpoint would be external.data/.0003keeps onlyall/allrows: literal/anonymized can't be mapped to internal/external. Migration0004addsdatasets.has_locality.Verification
bun run format,bun run lint,bun run typecheck,bun run test:web(includes the pre-locality/duplicate-ID discovery regression and the migrations for all five stats tables),bun run test:db(rule evaluation, direction mapping, fingerprint changes, registry errors, rollup parity, config-modehas_localityand config-relative address files),bun run test:e2e(passes; the fixture now uses the shared local schema and checks the served dataset metadata),cargo fmt --check,cargo clippy -D warnings.Made by Claude Opus 5.5 (with Opus 5.5 subagents) via Claude Code.