-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathctrlrun.example.yaml
More file actions
41 lines (36 loc) · 1.55 KB
/
Copy pathctrlrun.example.yaml
File metadata and controls
41 lines (36 loc) · 1.55 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
# ctrlrun.yaml — how much autonomy each action gets.
# Unknown actions are DENIED. There is no default-allow. List what is safe.
schema: ctrlrun.policy/v2
actions:
# Reads: autonomous. Declare no effect on these; nothing to reserve.
customer.read:
decision: allow
invoice.read:
decision: allow
# External communication: autonomous here. Add a rule on the recipient's domain
# before an agent can reach anyone outside the building.
# `effect` because a send is a consequence: two attempts with the same message_id are
# one email, and `ctrlrun scan` says so if you leave it off.
email.send:
effect: "email:{message_id}"
decision: allow
# Money: autonomy depends on the amount. First matching rule wins.
# Amounts are integer minor units (cents). Floats are rejected.
# Bound both ends: `amount_lte` alone lets a negative amount through, and a refund of
# a negative amount is a charge. An upper bound is not a range.
# `effect` names the consequence, so the same refund from two workers runs once.
stripe.refund:
effect: "refund:{payment_id}"
rules:
- when: { amount_gte: 0, amount_lte: 50000 } # €0.00 to €500.00
decision: allow
- when: { amount_gte: 0, amount_lte: 500000 } # €0.00 to €5,000.00
decision: approve
- decision: deny
# Privilege changes: never autonomous.
iam.grant_admin:
decision: deny
# Destructive infrastructure: a human every time, and one delete per namespace.
k8s.delete_namespace:
effect: "namespace:{cluster}:{name}"
decision: approve