hey <@U08V7MASW> / <@U09M563C7> - so just picking ...
# general
i
hey @marpaia / @theopolis - so just picking up the conversation again about extensions... as far as I understand it, the current mechanism is: - run osquery with the extension socket enabled - initiate a Thrift connection over the unix socket - register an extension - retrieve the extension UUID from osquery - create a Thrift unix socket server using
extensions_socket
.
uuid
as identifier - handle incoming request from osquery, produce an Extension(Response|Exception) i believe it's possible to have a threaded Thrift server, which would then make extensions more easily usable because you could have several running behind the same server, to decouple the extension from the server, as it were. i'm just thinking about how great it would be to have a vast array of extensions that could be mixed & matched, which would grow the osquery ecosystem and make it more general-purpose. thoughts?