Add device data model and ITAM service

Introduce device, posture, and enrollment-token entities with ITAM
service policies for agent-managed fleet inventory.

Signed-off-by: Ludovic Vielle <ludovic@probo.com>
This commit is contained in:
Ludovic Vielle
2026-07-14 20:38:38 +02:00
parent fa3b7dc2b3
commit 1f79453386
21 changed files with 3591 additions and 0 deletions

37
pkg/itam/actions.go Normal file
View File

@@ -0,0 +1,37 @@
// Copyright (c) 2025-2026 Probo Inc <hello@probo.com>.
//
// Permission is hereby granted, free of charge, to any person obtaining a copy
// of this software and associated documentation files (the "Software"), to deal
// in the Software without restriction, including without limitation the rights
// to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
// copies of the Software, and to permit persons to whom the Software is
// furnished to do so, subject to the following conditions:
//
// The above copyright notice and this permission notice shall be included in
// all copies or substantial portions of the Software.
//
// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
// IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
// FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
// AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
// LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
// OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
// SOFTWARE.
package itam
// ITAM Service Actions
// Format: itam:<entity>:<action>
const (
// Device actions
ActionDeviceList = "itam:device:list"
ActionEmployeeDeviceList = "itam:employee-device:list"
ActionDeviceGet = "itam:device:get"
ActionDeviceCreate = "itam:device:create"
ActionDeviceEnroll = "itam:device:enroll"
ActionDeviceRevoke = "itam:device:revoke"
ActionDeviceAssignOwner = "itam:device:assign"
// DevicePosture actions
ActionDevicePostureList = "itam:device-posture:list"
)