reasoninghost

package
v0.1.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 5, 2026 License: Apache-2.0 Imports: 5 Imported by: 0

Documentation

Index

Constants

View Source
const BindingID = "reasoning"

BindingID is the stable host binding identity for reasoning host composition.

Variables

View Source
var ErrNilBinding = errors.New("reasoninghost: binding is nil")

ErrNilBinding is returned when a reasoninghost binding is nil.

Functions

This section is empty.

Types

type Binding

type Binding struct {
	EgressPolicies  map[string]EgressPolicy
	MatcherResolver sdk.MatcherResolver
}

Binding envelopes host-provided egress policy and secret matcher resolver for standard reasoning feature composition. It implements featurehost.Binding.

func (*Binding) HostBindingID

func (b *Binding) HostBindingID() string

HostBindingID returns the stable identifier for reasoning host bindings. It is nil-safe and returns BindingID even when the receiver is typed-nil.

func (*Binding) Registration

func (b *Binding) Registration() featurehost.Registration

Registration returns a featurehost.Registration wrapping this binding.

func (*Binding) ValidateHostBinding

func (b *Binding) ValidateHostBinding() error

ValidateHostBinding checks the host binding configuration. It is nil-safe and returns ErrNilBinding if the receiver is nil.

type EgressAction

type EgressAction uint8

EgressAction is the bounded public egress decision.

const (
	EgressDeny EgressAction = iota
	EgressAllow
	EgressRedactThenAllow
)

func (EgressAction) String

func (a EgressAction) String() string

type EgressDecision

type EgressDecision struct {
	Action        EgressAction
	PolicyVersion string
}

EgressDecision is the trusted public policy decision.

type EgressInput

type EgressInput struct {
	Route       string
	Purpose     string
	SourceClass string
	// contains filtered or unexported fields
}

EgressInput is the narrow public egress policy input. Scope is held privately and returned as a defensive clone via Scope().

func NewEgressInput

func NewEgressInput(route, purpose, sourceClass string, s scope.PrincipalScopeView) EgressInput

NewEgressInput constructs a public input with defensive clone of scope.

func (EgressInput) Scope

Scope returns a defensive clone of the principal scope.

type EgressPolicy

type EgressPolicy interface {
	Decide(ctx context.Context, in EgressInput) (EgressDecision, error)
}

EgressPolicy is the trusted public data-egress decision seam for host composition. Enabled compression without host policy fails closed.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL