feat(privacy): scan ingested sources for customer-identifying data

Detection-only scan (internal/privacy) attached to every AnalysisResult:
a customer-domain guess plus a findings list (category, file, line, match,
hint), ported from the KB grep playbook. Runs on archive uploads and the
serialized Redfish tree; gated by LOGPILE_PRIVACY_SCAN (default on).

Surfaced at GET /api/privacy-scan, in the "Customer data" UI panel, and as
privacy_report.json in the raw-export bundle. IP policy keeps RFC1918 and
example ranges out of findings; allowlist covers standards-body and vendor
infrastructure domains. No customer tokens in the repo. See ADL-066 and
bible-local/docs/privacy-scan.md.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Mikhail Chusavitin
2026-09-02 15:24:32 +03:00
co-authored by Claude Sonnet 5
parent 3311bafd8e
commit 4a4910f207
23 changed files with 1466 additions and 33 deletions
+22
View File
@@ -2,12 +2,14 @@ package ingest
import (
"bytes"
"encoding/json"
"fmt"
"strings"
"git.mchus.pro/mchus/logpile/internal/collector"
"git.mchus.pro/mchus/logpile/internal/models"
"git.mchus.pro/mchus/logpile/internal/parser"
"git.mchus.pro/mchus/logpile/internal/privacy"
)
type Service struct{}
@@ -59,5 +61,25 @@ func (s *Service) AnalyzeRedfishRawPayloads(rawPayloads map[string]any, meta Red
result.Filename = "redfish://snapshot"
}
}
if scan := scanRedfishTreePrivacy(rawPayloads); scan != nil {
result.PrivacyScan = scan
}
return result, "redfish", nil
}
// scanRedfishTreePrivacy runs the customer-data scan over the serialized Redfish
// tree (the only text corpus a live/replayed collection carries).
func scanRedfishTreePrivacy(rawPayloads map[string]any) *models.PrivacyScan {
if !parser.PrivacyScanEnabled() || rawPayloads == nil {
return nil
}
tree, ok := rawPayloads["redfish_tree"]
if !ok {
return nil
}
body, err := json.Marshal(tree)
if err != nil || len(body) == 0 {
return nil
}
return privacy.Scan([]privacy.File{{Path: "redfish_tree.json", Content: body}})
}