Replaces the separate SQL-only /query and text-only /search endpoints with one pipe-syntax query language (plus raw SQL escape hatch) that compiles to a single IR and execution plan across both backends, so a query like `message:"connection refused" | stats count by host` runs as one request instead of two disjoint tools. - api/internal/querylang: lexer -> ast -> parser -> ir -> planner -> executor, each layer independently tested. - Execution generalizes Phase 1's proven Tantivy-prefilter pattern into a 4-way routing table (pure ClickHouse / text-only / text + aggregation / raw SQL passthrough). - Unified web query page and `sentryctl query`, both hitting the same POST /query endpoint. - Benchmarked against a real 1,022,000-row dataset (hack/benchmark-fixture); caught and fixed a real bug where the Tantivy prefilter cap (10,000) produced an IN-clause exceeding ClickHouse's default max_query_size -- lowered to 5,000, documented in docs/query-language-design.md and docs/phase-2-runbook.md. - docs/query-language-reference.md: customer-facing syntax reference.
25 lines
466 B
Plaintext
25 lines
466 B
Plaintext
# Rust
|
|
agent/target/
|
|
search/target/
|
|
|
|
# Go build cache (go build ./... without -o doesn't normally leave
|
|
# binaries in-tree, but be defensive)
|
|
/ingest/ingest
|
|
/api/api
|
|
/cli/sentryctl
|
|
/hack/windows-fixture/windows-fixture
|
|
/hack/benchmark-fixture/benchmark-fixture
|
|
|
|
# Node / SvelteKit (web/ has its own more detailed .gitignore too)
|
|
web/node_modules/
|
|
web/build/
|
|
web/.svelte-kit/
|
|
|
|
# Dev-only generated secrets
|
|
hack/dev-certs/out/
|
|
|
|
# OS / editor
|
|
.DS_Store
|
|
Thumbs.db
|
|
*.swp
|