Team Ai
Datasetpublic

codekingpro/portable-devtools

sourceHugging Faceupdated 5mo agoView on Hugging Face
1likes14kdownloads
attribute_context.proto351 linesDownload Raw Back to context
1// Copyright 2026 Google LLC2//3// Licensed under the Apache License, Version 2.0 (the "License");4// you may not use this file except in compliance with the License.5// You may obtain a copy of the License at6//7//     http://www.apache.org/licenses/LICENSE-2.08//9// Unless required by applicable law or agreed to in writing, software10// distributed under the License is distributed on an "AS IS" BASIS,11// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.12// See the License for the specific language governing permissions and13// limitations under the License.14 15syntax = "proto3";16 17package google.rpc.context;18 19import "google/protobuf/any.proto";20import "google/protobuf/duration.proto";21import "google/protobuf/struct.proto";22import "google/protobuf/timestamp.proto";23 24option go_package = "google.golang.org/genproto/googleapis/rpc/context/attribute_context;attribute_context";25option java_multiple_files = true;26option java_outer_classname = "AttributeContextProto";27option java_package = "com.google.rpc.context";28 29// This message defines the standard attribute vocabulary for Google APIs.30//31// An attribute is a piece of metadata that describes an activity on a network32// service. For example, the size of an HTTP request, or the status code of33// an HTTP response.34//35// Each attribute has a type and a name, which is logically defined as36// a proto message field in `AttributeContext`. The field type becomes the37// attribute type, and the field path becomes the attribute name. For example,38// the attribute `source.ip` maps to field `AttributeContext.source.ip`.39//40// This message definition is guaranteed not to have any wire breaking change.41// So you can use it directly for passing attributes across different systems.42//43// NOTE: Different system may generate different subset of attributes. Please44// verify the system specification before relying on an attribute generated45// a system.46message AttributeContext {47  // This message defines attributes for a node that handles a network request.48  // The node can be either a service or an application that sends, forwards,49  // or receives the request. Service peers should fill in50  // `principal` and `labels` as appropriate.51  message Peer {52    // The IP address of the peer.53    string ip = 1;54 55    // The network port of the peer.56    int64 port = 2;57 58    // The labels associated with the peer.59    map<string, string> labels = 6;60 61    // The identity of this peer. Similar to `Request.auth.principal`, but62    // relative to the peer instead of the request. For example, the63    // identity associated with a load balancer that forwarded the request.64    string principal = 7;65 66    // The CLDR country/region code associated with the above IP address.67    // If the IP address is private, the `region_code` should reflect the68    // physical location where this peer is running.69    string region_code = 8;70  }71 72  // This message defines attributes associated with API operations, such as73  // a network API request. The terminology is based on the conventions used74  // by Google APIs, Istio, and OpenAPI.75  message Api {76    // The API service name. It is a logical identifier for a networked API,77    // such as "pubsub.googleapis.com". The naming syntax depends on the78    // API management system being used for handling the request.79    string service = 1;80 81    // The API operation name. For gRPC requests, it is the fully qualified API82    // method name, such as "google.pubsub.v1.Publisher.Publish". For OpenAPI83    // requests, it is the `operationId`, such as "getPet".84    string operation = 2;85 86    // The API protocol used for sending the request, such as "http", "https",87    // "grpc", or "internal".88    string protocol = 3;89 90    // The API version associated with the API operation above, such as "v1" or91    // "v1alpha1".92    string version = 4;93  }94 95  // This message defines request authentication attributes. Terminology is96  // based on the JSON Web Token (JWT) standard, but the terms also97  // correlate to concepts in other standards.98  message Auth {99    // The authenticated principal. Reflects the issuer (`iss`) and subject100    // (`sub`) claims within a JWT. The issuer and subject should be `/`101    // delimited, with `/` percent-encoded within the subject fragment. For102    // Google accounts, the principal format is:103    // "https://accounts.google.com/{id}"104    string principal = 1;105 106    // The intended audience(s) for this authentication information. Reflects107    // the audience (`aud`) claim within a JWT. The audience108    // value(s) depends on the `issuer`, but typically include one or more of109    // the following pieces of information:110    //111    // *  The services intended to receive the credential. For example,112    //    ["https://pubsub.googleapis.com/", "https://storage.googleapis.com/"].113    // *  A set of service-based scopes. For example,114    //    ["https://www.googleapis.com/auth/cloud-platform"].115    // *  The client id of an app, such as the Firebase project id for JWTs116    //    from Firebase Auth.117    //118    // Consult the documentation for the credential issuer to determine the119    // information provided.120    repeated string audiences = 2;121 122    // The authorized presenter of the credential. Reflects the optional123    // Authorized Presenter (`azp`) claim within a JWT or the124    // OAuth client id. For example, a Google Cloud Platform client id looks125    // as follows: "123456789012.apps.googleusercontent.com".126    string presenter = 3;127 128    // Structured claims presented with the credential. JWTs include129    // `{key: value}` pairs for standard and private claims. The following130    // is a subset of the standard required and optional claims that would131    // typically be presented for a Google-based JWT:132    //133    //    {'iss': 'accounts.google.com',134    //     'sub': '113289723416554971153',135    //     'aud': ['123456789012', 'pubsub.googleapis.com'],136    //     'azp': '123456789012.apps.googleusercontent.com',137    //     'email': 'jsmith@example.com',138    //     'iat': 1353601026,139    //     'exp': 1353604926}140    //141    // SAML assertions are similarly specified, but with an identity provider142    // dependent structure.143    google.protobuf.Struct claims = 4;144 145    // A list of access level resource names that allow resources to be146    // accessed by authenticated requester. It is part of Secure GCP processing147    // for the incoming request. An access level string has the format:148    // "//{api_service_name}/accessPolicies/{policy_id}/accessLevels/{short_name}"149    //150    // Example:151    // "//accesscontextmanager.googleapis.com/accessPolicies/MY_POLICY_ID/accessLevels/MY_LEVEL"152    repeated string access_levels = 5;153  }154 155  // This message defines attributes for an HTTP request. If the actual156  // request is not an HTTP request, the runtime system should try to map157  // the actual request to an equivalent HTTP request.158  message Request {159    // The unique ID for a request, which can be propagated to downstream160    // systems. The ID should have low probability of collision161    // within a single day for a specific service.162    string id = 1;163 164    // The HTTP request method, such as `GET`, `POST`.165    string method = 2;166 167    // The HTTP request headers. If multiple headers share the same key, they168    // must be merged according to the HTTP spec. All header keys must be169    // lowercased, because HTTP header keys are case-insensitive.170    map<string, string> headers = 3;171 172    // The HTTP URL path, excluding the query parameters.173    string path = 4;174 175    // The HTTP request `Host` header value.176    string host = 5;177 178    // The HTTP URL scheme, such as `http` and `https`.179    string scheme = 6;180 181    // The HTTP URL query in the format of `name1=value1&name2=value2`, as it182    // appears in the first line of the HTTP request. No decoding is performed.183    string query = 7;184 185    // The timestamp when the `destination` service receives the last byte of186    // the request.187    google.protobuf.Timestamp time = 9;188 189    // The HTTP request size in bytes. If unknown, it must be -1.190    int64 size = 10;191 192    // The network protocol used with the request, such as "http/1.1",193    // "spdy/3", "h2", "h2c", "webrtc", "tcp", "udp", "quic". See194    // https://www.iana.org/assignments/tls-extensiontype-values/tls-extensiontype-values.xhtml#alpn-protocol-ids195    // for details.196    string protocol = 11;197 198    // A special parameter for request reason. It is used by security systems199    // to associate auditing information with a request.200    string reason = 12;201 202    // The request authentication. May be absent for unauthenticated requests.203    // Derived from the HTTP request `Authorization` header or equivalent.204    Auth auth = 13;205 206    // The values from Origin header from the HTTP request, such as207    // "https://console.cloud.google.com". Modern browsers can only have one208    // origin. Special browsers and/or HTTP clients may require multiple209    // origins.210    string origin = 14;211  }212 213  // This message defines attributes for a typical network response. It214  // generally models semantics of an HTTP response.215  message Response {216    // The HTTP response status code, such as `200` and `404`.217    int64 code = 1;218 219    // The HTTP response size in bytes. If unknown, it must be -1.220    int64 size = 2;221 222    // The HTTP response headers. If multiple headers share the same key, they223    // must be merged according to HTTP spec. All header keys must be224    // lowercased, because HTTP header keys are case-insensitive.225    map<string, string> headers = 3;226 227    // The timestamp when the `destination` service sends the last byte of228    // the response.229    google.protobuf.Timestamp time = 4;230 231    // The amount of time it takes the backend service to fully respond to a232    // request. Measured from when the destination service starts to send the233    // request to the backend until when the destination service receives the234    // complete response from the backend.235    google.protobuf.Duration backend_latency = 5;236  }237 238  // This message defines core attributes for a resource. A resource is an239  // addressable (named) entity provided by the destination service. For240  // example, a file stored on a network storage service.241  message Resource {242    // The name of the service that this resource belongs to, such as243    // `pubsub.googleapis.com`. The service may be different from the DNS244    // hostname that actually serves the request.245    string service = 1;246 247    // The stable identifier (name) of a resource on the `service`. A resource248    // can be logically identified as "//{resource.service}/{resource.name}".249    // The differences between a resource name and a URI are:250    //251    // *   Resource name is a logical identifier, independent of network252    //     protocol and API version. For example,253    //     `//pubsub.googleapis.com/projects/123/topics/news-feed`.254    // *   URI often includes protocol and version information, so it can255    //     be used directly by applications. For example,256    //     `https://pubsub.googleapis.com/v1/projects/123/topics/news-feed`.257    //258    // See https://cloud.google.com/apis/design/resource_names for details.259    string name = 2;260 261    // The type of the resource. The syntax is platform-specific because262    // different platforms define their resources differently.263    //264    // For Google APIs, the type format must be "{service}/{kind}", such as265    // "pubsub.googleapis.com/Topic".266    string type = 3;267 268    // The labels or tags on the resource, such as AWS resource tags and269    // Kubernetes resource labels.270    map<string, string> labels = 4;271 272    // The unique identifier of the resource. UID is unique in the time273    // and space for this resource within the scope of the service. It is274    // typically generated by the server on successful creation of a resource275    // and must not be changed. UID is used to uniquely identify resources276    // with resource name reuses. This should be a UUID4.277    string uid = 5;278 279    // Annotations is an unstructured key-value map stored with a resource that280    // may be set by external tools to store and retrieve arbitrary metadata.281    // They are not queryable and should be preserved when modifying objects.282    //283    // More info:284    // https://kubernetes.io/docs/concepts/overview/working-with-objects/annotations/285    map<string, string> annotations = 6;286 287    // Mutable. The display name set by clients. Must be <= 63 characters.288    string display_name = 7;289 290    // Output only. The timestamp when the resource was created. This may291    // be either the time creation was initiated or when it was completed.292    google.protobuf.Timestamp create_time = 8;293 294    // Output only. The timestamp when the resource was last updated. Any295    // change to the resource made by users must refresh this value.296    // Changes to a resource made by the service should refresh this value.297    google.protobuf.Timestamp update_time = 9;298 299    // Output only. The timestamp when the resource was deleted.300    // If the resource is not deleted, this must be empty.301    google.protobuf.Timestamp delete_time = 10;302 303    // Output only. An opaque value that uniquely identifies a version or304    // generation of a resource. It can be used to confirm that the client305    // and server agree on the ordering of a resource being written.306    string etag = 11;307 308    // Immutable. The location of the resource. The location encoding is309    // specific to the service provider, and new encoding may be introduced310    // as the service evolves.311    //312    // For Google Cloud products, the encoding is what is used by Google Cloud313    // APIs, such as `us-east1`, `aws-us-east-1`, and `azure-eastus2`. The314    // semantics of `location` is identical to the315    // `cloud.googleapis.com/location` label used by some Google Cloud APIs.316    string location = 12;317  }318 319  // The origin of a network activity. In a multi hop network activity,320  // the origin represents the sender of the first hop. For the first hop,321  // the `source` and the `origin` must have the same content.322  Peer origin = 7;323 324  // The source of a network activity, such as starting a TCP connection.325  // In a multi hop network activity, the source represents the sender of the326  // last hop.327  Peer source = 1;328 329  // The destination of a network activity, such as accepting a TCP connection.330  // In a multi hop network activity, the destination represents the receiver of331  // the last hop.332  Peer destination = 2;333 334  // Represents a network request, such as an HTTP request.335  Request request = 3;336 337  // Represents a network response, such as an HTTP response.338  Response response = 4;339 340  // Represents a target resource that is involved with a network activity.341  // If multiple resources are involved with an activity, this must be the342  // primary one.343  Resource resource = 5;344 345  // Represents an API operation that is involved to a network activity.346  Api api = 6;347 348  // Supports extensions for advanced use cases, such as logs and metrics.349  repeated google.protobuf.Any extensions = 8;350}351 
codekingpro/portable-devtools · Team Ai