A transport-neutral resource policy and audit engine for MoonBit hosts
Dependencies
MoonBit 通用策略执行与审计引擎:让宿主在执行资源操作前,先得到可解释、可验证的决策。
let policy = @moonpod.Policy::new(
["plugin.invoke"],
resource_rules=[
@moonpod.ResourceRule::new(
tool="plugin.invoke",
action="run",
resource_prefix="tenant/acme/reports",
),
],
)
let session = @moonpod.Session::new(policy)
session.authorize(@moonpod.ResourceAccess(
tool="plugin.invoke",
action="run",
resource="tenant/acme/reports/monthly",
estimated_bytes=512,
))moon run cmd/main -- --policy-json '{"schema_version":1,"allowed_tools":["fs.read"],"read_roots":["/workspace"]}' > audit.jsonmoon run cmd/main -- --policy-json '{"schema_version":1,"allowed_tools":["fs.read","net.connect"],"read_roots":["/workspace"],"network_rules":[{"host":"api.example.com","allowed_ports":[443]}]}' --operations-json '[{"tool":"fs.read","path":"/workspace/README.md","estimated_bytes":128},{"tool":"net.connect","host":"api.example.com","port":443}]' > batch-audit.jsonmoon run cmd/main -- --policy-json '{"schema_version":1,"allowed_tools":["fs.read"],"read_roots":["/workspace"]}' --operations-json '[{"tool":"fs.read","path":"/workspace/README.md","estimated_bytes":128}]' --audit-jsonl >> audit.jsonlmoon add yadidyc/moonpod@0.2.0import {
"yadidyc/moonpod",
}git clone https://github.com/yadidyc/moonpod.git
cd moonpod
moon check --target all --deny-warn
moon test --target all --deny-warnmoon check
moon test
moon run cmd/mainmoon run examples/policy_guard
moon run examples/batch_auditmodel.mbt 操作、决策、拒绝原因和审计事件
resource_policy.mbt 通用资源规则
path_policy.mbt 跨平台路径归一化和边界判定
policy.mbt 不可变策略与规则求值
policy_restriction.mbt 策略共同权限计算
session.mbt 会话、预算、审批和审计状态
json_policy.mbt JSON 策略解码和审计导出
docs/integration-guide.md 宿主接入和 API 使用指南
docs/security-guide.md 安全配置、边界和验证清单
moonpermit_adapter MoonPermit Permit 的失败关闭适配
cmd/main 可运行演示fn CommandRule::new(program~ : String, argument_prefix~ : Array[String]) -> CommandRule raise PolicyConfigErrorpub(all) enum Decision {
Allow
ApprovalRequired(Int)
ApprovalGranted(Int)
ApprovalCancelled(Int)
Deny(DenyReason)
} derive(Eq, Debug)pub(all) enum DenyReason {
SessionClosed
ApprovalRejected(request_id~ : Int)
ApprovalNotPending(request_id~ : Int)
CallBudgetExceeded(limit~ : Int)
ToolCallQuotaExceeded(tool~ : String, limit~ : Int)
OperationByteLimitExceeded(limit~ : Int, requested~ : Int)
IoBudgetExceeded(limit~ : Int, requested~ : Int)
ToolNotAllowed(String)
PathNotAllowed(String)
HostNotAllowed(String)
PortNotAllowed(host~ : String, port~ : Int)
CommandNotAllowed(String)
CommandArgumentsNotAllowed(String)
ResourceNotAllowed(tool~ : String, action~ : String, resource~ : String)
InvalidByteEstimate(Int)
} derive(Eq, Debug)fn NetworkRule::new(host~ : String, allowed_ports~ : Array[Int]) -> NetworkRule raise PolicyConfigErrorpub(all) enum Operation {
ReadFile(path~ : String, estimated_bytes~ : Int)
WriteFile(path~ : String, bytes~ : Int)
Connect(host~ : String, port~ : Int)
RunCommand(program~ : String, arguments~ : Array[String], estimated_output_bytes~ : Int)
Invoke(tool~ : String, estimated_output_bytes~ : Int)
ResourceAccess(tool~ : String, action~ : String, resource~ : String, estimated_bytes~ : Int)
} derive(Eq, Debug)pub struct Policy {
allowed_tools : Array[String]
read_roots : Array[String]
write_roots : Array[String]
protected_paths : Array[String]
network_rules : Array[NetworkRule]
command_rules : Array[CommandRule]
resource_rules : Array[ResourceRule]
tool_quotas : Array[ToolQuota]
approval_required_tools : Array[String]
max_calls : Int
max_operation_bytes : Int
max_io_bytes : Int
}fn Policy::new(allowed_tools : Array[String], read_roots? : Array[String], write_roots? : Array[String], protected_paths? : Array[String], network_rules? : Array[NetworkRule], command_rules? : Array[CommandRule], tool_quotas? : Array[ToolQuota], max_calls? : Int, max_operation_bytes? : Int, max_io_bytes? : Int, approval_required_tools? : Array[String], resource_rules? : Array[ResourceRule]) -> Policy raise PolicyConfigErrorfn ResourceRule::new(tool~ : String, action~ : String, resource_prefix~ : String) -> ResourceRule raise PolicyConfigErrorpub struct Session {
policy : Policy
state : SessionState
attempts : Int
tool_attempts : Map[String, Int]
used_bytes : Int
reserved_bytes : Int
events : Array[AuditEvent]
approvals : Array[ApprovalRequest]
}Install
Download zipA transport-neutral resource policy and audit engine for MoonBit hosts
Dependencies