@aegiskit/observability
v0.1.0
Published
Aegis observability: a pluggable EventStore, deterministic posture scoring, and ingestion signature verification for the security dashboard.
Downloads
50
Maintainers
Readme
@aegiskit/observability
The read/consumer side of Aegis: a pluggable EventStore, a deterministic posture score, the canonical severity table, and the ingestion signature verifier. Runs in your dashboard / ingestion service — never on the request hot path.
import {
createMemoryEventStore,
computePostureScore,
verifyBatchSignature,
} from '@aegiskit/observability';
const store = createMemoryEventStore(); // dev/self-host default; Upstash/Supabase adapters for prod
await store.append(events); // idempotent on event id
const summary = await store.summary({ since, until });
const { score, grade } = computePostureScore(summary); // 0–100, A–F — monotonic & deterministic
// On the ingestion endpoint (verify the RAW body, not a re-serialized object):
const ok = await verifyBatchSignature(secret, rawBody, timestamp, signatureHeader);EventStore—append/query(newest-first, filtered) /summary(counts, block-rate, time buckets).createMemoryEventStoreis a single-instance ring buffer; production adapters live in@aegiskit/store-supabase(and the Upstash store).computePostureScore— pure, deterministic, monotonic (adding any event never raises the score), recency-decayed.csp_violationis weighted low on purpose (attacker-controllable → can't be used to tank a victim's score).verifyBatchSignature— HMAC-SHA-256 overtimestamp + "." + rawBody, constant-time (subtle.verify), with a replay window. The counterpart to@aegiskit/core'screateHttpSink.
License
MIT
