You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
feat(evaluate): send a directory of policies as one bundle
--policy may name a directory, and every file below it travels keyed by
its path relative to that directory. Nothing is left out by name: what a
bundle may hold, and what its modules may import, is for the evaluator
that runs it to judge. The published file and byte caps, and an empty
directory, are still named here rather than sent to be refused.
A policy now comes from this machine only. Fetching one from a URL is on
its way out, so this command does not offer it.
Slice 6 of kosli-dev/server#6920.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Copy file name to clipboardExpand all lines: docs/handover/6920-evaluate-an-inline-policy-and-record-its-decis.md
+5-3Lines changed: 5 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -22,7 +22,7 @@ Server-side evaluation reaches the CLI today only through the hidden `--server-s
22
22
- A denial is a decision, recorded as non-compliant with its violations. A policy that cannot run is not: it records nothing and must never print a denial.
23
23
- Destination flags without `--control` are refused, and a control or a destination the caller cannot write to is refused before the evaluation is queued.
24
24
- The command always waits for a terminal status; `--assert` exits non-zero on denial and changes nothing else.
25
-
-`--policy` accepts a single file or a directory, within the published bundle caps.
25
+
-`--policy` accepts a single file or a directory on this machine, within the published bundle caps. A URL is refused.
26
26
- Output and `--output json` match `kosli evaluate trail`, so a caller switching commands does not re-parse.
27
27
- An organisation without the server-side evaluation entitlement is refused in words that name it.
28
28
-`--name` defaults to `<control>-decision`, so the common case names only the control.
@@ -42,7 +42,7 @@ Transcribed from [docs/plans/6920-evaluate-policy.md](../plans/6920-evaluate-pol
42
42
-[x] Slice 3 — `--context` names what is evaluated, and is always required.
43
43
-[x] Slice 4 — `--control` records a decision, with `--flow` and `--trail` as its destination.
44
44
-[x] Slice 5 — refusals travel in the API's own words, and a classified failure is never a denial.
45
-
-[] Slice 6 — a directory of policy files as one bundle, with the caps refused here.
45
+
-[x] Slice 6 — a directory of policy files as one bundle, with the caps refused here.
46
46
-[ ] Slice 7 — help text, docs, changelog, lint, full test run, and a staging check against an entitled organisation.
47
47
48
48
---
@@ -60,6 +60,8 @@ Transcribed from [docs/plans/6920-evaluate-policy.md](../plans/6920-evaluate-pol
60
60
- The command declares its own options rather than inheriting the evaluate commands' shared ones, because four of those flags have no meaning here and inheriting them only to hide them is how two commands drift apart.
61
61
- Asserting is opt-in on this command and the default is silent, which is the reverse of `evaluate trail`. A command that records a decision should not fail a pipeline unless the caller asked it to, and the flag that asks is the one the tutorial already publishes.
62
62
- What is evaluated and where a decision lands are named separately: `--context` is the only way to say what to evaluate and is always required, while `--flow` and `--trail` name the destination alone. Neither is refused for being present without `--control`, because a pipeline sets them as environment variables for every command it runs, and refusing them would refuse an ordinary run that asked for no decision. The ticket's example predates this split.
63
+
- A policy comes from the machine that runs the command: this command does not fetch one from a URL, though the older evaluate commands do, because that way of naming a policy is on its way out and a new command should not take it on.
64
+
- A directory of policy files travels whole, with nothing left out by name and nothing here reading the modules. What a bundle may hold, and what its modules may import, is for the evaluator that runs it to judge; a rule here would refuse bundles the evaluator would have accepted, and would go stale as the evaluator changes. Only the published caps and an empty directory are refused here, because those the caller can act on before sending.
63
65
- Refusals are passed on as the API worded them rather than being classified here, and the slice that was to give each case a sentence of its own was cut back to two tests. A list of cases in the CLI would go stale against the server that writes them, and the one thing that must not vary — a failed policy never reading as a denial — is pinned by a test instead.
64
66
- The destination is read as a resolved value rather than as a flag the caller typed, so `KOSLI_FLOW` and `KOSLI_TRAIL` satisfy `--control` exactly as the flags do.
65
67
- The first cut of the command is synchronous only, and `--sync` is not offered: with nothing to opt into, the flag would name the one behaviour there is. A command whose purpose is recording a decision should not return before the decision exists. An asynchronous mode, and the `--sync` flag that would pair with it, belong to a later ticket if anyone asks for them.
@@ -76,5 +78,5 @@ Transcribed from [docs/plans/6920-evaluate-policy.md](../plans/6920-evaluate-pol
76
78
77
79
## Next Steps
78
80
79
-
-[ ] Slice 6: a directory of policy files as one bundle, with the caps refused here.
81
+
-[ ] Slice 7: help text, docs, changelog, the full integration run, and a staging check against an entitled organisation.
80
82
-[ ] Check what the create endpoint refuses for each destination failure, against staging, so Slice 5's messages are written from real answers rather than guessed.
Copy file name to clipboardExpand all lines: docs/plans/6920-evaluate-policy.md
+3-3Lines changed: 3 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -76,7 +76,7 @@ The evaluation resource gains `decision_attestation_id`: the id of the decision
76
76
| Flag | Required | Meaning |
77
77
|---|---|---|
78
78
|`--context`| yes | Repeatable `trail=<flow>/<trail>`. What is evaluated, all of it at one instant. |
79
-
|`--policy`, `-p`| yes | A `.rego` file, a directory, or an `http(s)://` URL. |
79
+
|`--policy`, `-p`| yes | A `.rego` file or a directory on this machine. |
80
80
|`--params`| no | Inline JSON or `@file.json`, unchanged, read by the policy as `data.params`. |
81
81
|`--control`| no | The control the decision answers. Present, a decision is recorded; absent, nothing is. |
82
82
|`--flow`, `-f`| with `--control`| Flow the decision is recorded in. |
@@ -136,7 +136,7 @@ The ticket asks for denial, a broken policy and a fault of ours to be three dist
136
136
137
137
### 4.6 A directory of policy files
138
138
139
-
`--policy` pointing at a directory uploads every file below it as one bundle, keyed by path relative to that directory, within the published 100-file and 1 MiB caps. Paths stay inside the bundle. A single file keeps today's behaviour: one entry named after the file, no extension imposed.
139
+
`--policy` pointing at a directory uploads every file below it as one bundle, keyed by path relative to that directory, within the published 100-file and 1 MiB caps. Nothing is left out by name, and nothing here reads the modules: what a bundle may hold, and what its modules may import, is the evaluator's to judge, and a rule here would refuse bundles the evaluator would have accepted. An empty directory is named here, because the API takes at least one file. A single file keeps today's behaviour: one entry named after the file, no extension imposed. A URL is refused: fetching a policy from one is on its way out, so this command never offers it.
140
140
141
141
### 4.7 `--context`
142
142
@@ -200,7 +200,7 @@ Deliberately shallow. A refusal is reported as the status the API answered with
200
200
201
201
### Slice 6: a directory of policy files
202
202
203
-
Relative keys, the file and byte caps refused here with the cap named, paths that would climb out of the bundle refused.
203
+
Relative keys, the file and byte caps refused here with the cap named, an empty directory named here, the bundle's contents left for the evaluator to judge, and a URL refused.
0 commit comments