Documentation
¶
Index ¶
Constants ¶
const BindingID = "reasoning"
BindingID is the stable host binding identity for reasoning host composition.
Variables ¶
var ErrNilBinding = errors.New("reasoninghost: binding is nil")
ErrNilBinding is returned when a reasoninghost binding is nil.
Functions ¶
This section is empty.
Types ¶
type Binding ¶
type Binding struct {
EgressPolicies map[string]EgressPolicy
MatcherResolver sdk.MatcherResolver
}
Binding envelopes host-provided egress policy and secret matcher resolver for standard reasoning feature composition. It implements featurehost.Binding.
func (*Binding) HostBindingID ¶
HostBindingID returns the stable identifier for reasoning host bindings. It is nil-safe and returns BindingID even when the receiver is typed-nil.
func (*Binding) Registration ¶
func (b *Binding) Registration() featurehost.Registration
Registration returns a featurehost.Registration wrapping this binding.
func (*Binding) ValidateHostBinding ¶
ValidateHostBinding checks the host binding configuration. It is nil-safe and returns ErrNilBinding if the receiver is nil.
type EgressAction ¶
type EgressAction uint8
EgressAction is the bounded public egress decision.
const ( EgressDeny EgressAction = iota EgressAllow EgressRedactThenAllow )
func (EgressAction) String ¶
func (a EgressAction) String() string
type EgressDecision ¶
type EgressDecision struct {
Action EgressAction
PolicyVersion string
}
EgressDecision is the trusted public policy decision.
type EgressInput ¶
type EgressInput struct {
Route string
Purpose string
SourceClass string
// contains filtered or unexported fields
}
EgressInput is the narrow public egress policy input. Scope is held privately and returned as a defensive clone via Scope().
func NewEgressInput ¶
func NewEgressInput(route, purpose, sourceClass string, s scope.PrincipalScopeView) EgressInput
NewEgressInput constructs a public input with defensive clone of scope.
func (EgressInput) Scope ¶
func (i EgressInput) Scope() scope.PrincipalScopeView
Scope returns a defensive clone of the principal scope.
type EgressPolicy ¶
type EgressPolicy interface {
Decide(ctx context.Context, in EgressInput) (EgressDecision, error)
}
EgressPolicy is the trusted public data-egress decision seam for host composition. Enabled compression without host policy fails closed.