Skip to content

feat(honeytoken): background usage poller (epic #256 Task 3) - #267

Open
LiorFink00 wants to merge 1 commit into
feat/honeytoken-apifrom
feat/honeytoken-poller
Open

LiorFink00 wants to merge 1 commit into
feat/honeytoken-apifrom
feat/honeytoken-poller

Conversation

@LiorFink00

Copy link
Copy Markdown
Collaborator

What

Task 3 of epic #256 — closes the honeytoken detection loop. On an interval the poller asks each configured platform's plugin to poll_usage, records each use of an active honeytoken, raises an alert, and fans it out via the existing alerting path. With Tasks 1–3 the feature works end-to-end server-side (a provider plugin makes it real).

  • services/honeytoken_poller.py — poll_once() + an asyncio interval loop, started from the app lifespan and cancelled on shutdown (try/finally).
  • config.py — THUMPER_HONEYTOKEN_POLL_INTERVAL (default 60s).
  • main.py — wire start_poller into lifespan.

Dedup happens before alerting (record_honeytoken_usage returns None for an already-seen event id), so a use surfacing across overlapping poll windows alerts exactly once — test_poll_once_dedupes_repeated_event.

Testing

7 poller tests (detect, dedup, skip-unconfigured, no-active-tokens, continue-on-plugin-error, survive-poll-failure); full suite 400 passed, 1 skipped; ruff clean.

Stacked

Based on #266 (Task 2) → #265 (Task 1). Provider plugins + UI follow.

Note: CI's macOS leg hit a known agent-shell timing flake (test_heartbeat_success_is_logged) unrelated to this server-only diff; re-running. ubuntu + lint + build all green.

🤖 Generated with Claude Code

Task 3 of epic #256. Closes the honeytoken detection loop: on an interval the
poller asks each configured platform's plugin to poll its audit log for use of
any active honeytoken, records each use, raises an alert, and fans it out via the
existing alerting path.

- services/honeytoken_poller.py: poll_once + an asyncio interval loop, started
  from the app lifespan and cancelled on shutdown (try/finally).
- config.py: THUMPER_HONEYTOKEN_POLL_INTERVAL (default 60s).
- main.py: wire start_poller into lifespan.

Dedup happens before alerting (record_honeytoken_usage returns None for an
already-seen event id), so a use surfacing across overlapping poll windows alerts
exactly once - covered by test_poll_once_dedupes_repeated_event. 7 poller tests
(detect, dedup, skip-unconfigured, continue-on-error, survive-poll-failure, ...);
full suite 400 passed.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018DARDAxeg4NM8FKoyGMQZy
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant