Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
49 commits
Select commit Hold shift + click to select a range
5db3836
test: record golden agent configuration hashes before the config refa…
ccf-lisa[bot] Sep 30, 2026
0d39af6
refactor(config): adopt api/pkg/agentconfig as the declared config (G0)
ccf-lisa[bot] Sep 30, 2026
16d6c6b
feat(agent): stable instance ID, state dir and prepare-then-cancel re…
ccf-lisa[bot] Sep 30, 2026
f5bdf4d
feat(agent): report config and pull/apply the remote overlay (G2+G3)
ccf-lisa[bot] Sep 30, 2026
172b921
feat(agent): inline policy bundles (G3b); pin api to approved aa005f7
ccf-lisa[bot] Sep 30, 2026
2f0e3a1
docs: remote configuration, inline policy bundles and state (G4)
ccf-lisa[bot] Sep 30, 2026
b9c1cad
chore: pin compliance-framework/api to PR #465 head 9a512a6
ccf-lisa[bot] Sep 30, 2026
e785e4c
fix(inlinepolicy): never execute a denied builtin during checks
ccf-lisa[bot] Sep 30, 2026
4493064
fix(config): keep file configs that load on main loading (R34, R51, R60)
ccf-lisa[bot] Sep 30, 2026
f8c7c33
fix(inlinepolicy): follow a symlinked extends root, reject an empty tree
ccf-lisa[bot] Sep 30, 2026
0c1a8c7
fix(reconciler): address review of the reload and startup paths
ccf-lisa[bot] Sep 30, 2026
66af7bf
chore: pin compliance-framework/api to PR #465 head 6c801a3
ccf-lisa[bot] Oct 1, 2026
7077ef6
feat(runner): one archiver and a process-wide artifact uploader (R62)
ccf-lisa[bot] Oct 1, 2026
ebb5084
feat(inlinepolicy): policy contract checks and override hints (R63, R65)
ccf-lisa[bot] Oct 1, 2026
71c3da8
feat(inlinepolicy): stable per-bundle path for evidence identity (R67)
ccf-lisa[bot] Oct 1, 2026
33b12dd
feat(reconciler): stable inline paths, policy tree artifacts, duplica…
ccf-lisa[bot] Oct 1, 2026
3707736
self-review: address round-2 pass 1 findings
ccf-lisa[bot] Oct 1, 2026
f88bde9
self-review: address round-2 pass 2 findings
ccf-lisa[bot] Oct 1, 2026
0a594f2
merge: origin/main (#96/#97 source props, AGENTS.md)
ccf-lisa[bot] Oct 1, 2026
ac8a1d3
chore: pin compliance-framework/api to PR #465 head f511c44 (round 3)
ccf-lisa[bot] Oct 1, 2026
e6ec2af
feat(policy-manager): seed evidence with an optional policy_id (R74)
ccf-lisa[bot] Oct 1, 2026
ba47798
chore: pin compliance-framework/api to PR #465 head 5449a31
ccf-lisa[bot] Oct 1, 2026
2910ca6
test(policy-manager): a ./-relative local source continues its stream…
ccf-lisa[bot] Oct 1, 2026
779788c
feat(inlinepolicy): module identities and override streams (R75, R76)
ccf-lisa[bot] Oct 1, 2026
b8c4aa2
feat(reconciler): identity checks, plugin paths and the plugin librar…
ccf-lisa[bot] Oct 1, 2026
7d5a84e
docs: policy identity and plugin compatibility (R74-R79)
ccf-lisa[bot] Oct 1, 2026
3e367b2
self-review: address round-3 pass 1 findings
ccf-lisa[bot] Oct 1, 2026
2586322
self-review: address round-3 pass 2 findings
ccf-lisa[bot] Oct 1, 2026
5b12042
chore: pin api f50e4d8; gate inline policies on agent v0.8.0 final (R…
ccf-lisa[bot] Oct 1, 2026
06d9ad6
feat: report extends.plugin-path for R78 continuity
ccf-lisa[bot] Oct 1, 2026
2c0a96c
merge main (api v0.20.0 bump); keep the api 5baeb7812db2 pin
ccf-lisa[bot] Oct 1, 2026
2aac869
fix: gate inline policies on agent v0.9.0 (v0.8.0/v0.8.1 shipped with…
ccf-lisa[bot] Oct 1, 2026
b6e2f66
wip(R82): continue vendor evidence streams; local-source-style inline…
gusfcarvalho Oct 1, 2026
01a0ee4
wip(shadow): per-plugin path shadowing for inline bundles (prototype)
gusfcarvalho Oct 1, 2026
6a5fc34
wip(shadow): view collisions are plugin-owned, never fatal (rule 1)
gusfcarvalho Oct 1, 2026
da5360b
fix: address review feedback (R88-R91)
ccf-lisa[bot] Oct 1, 2026
bce3ad3
fix: warn per plugin when an extends bundle is not shadowed (R88)
ccf-lisa[bot] Oct 1, 2026
e8afe72
fix: re-report a remembered rejection after a restart
ccf-lisa[bot] Oct 1, 2026
81ec070
refactor: drop authored policy_id (R74); path shadowing keeps vendor …
gusfcarvalho Oct 2, 2026
cce28c6
chore: pin api e69e286
gusfcarvalho Oct 2, 2026
dd238df
refactor!: drop inline policy bundles, path shadowing and policy iden…
gusfcarvalho Oct 2, 2026
f5521fb
refactor!: drop policy errors and the plugin-lib compat gate
gusfcarvalho Oct 2, 2026
9c85d14
chore: pin api cce6baf
gusfcarvalho Oct 2, 2026
8efe38f
docs: scope remote configuration to the overlay, safeguards and repor…
gusfcarvalho Oct 2, 2026
eea7162
style: reflow comments
gusfcarvalho Oct 2, 2026
69083bc
refactor!: drop the report-time policy bundle inventory and uploads
gusfcarvalho Oct 2, 2026
1a1a667
chore: pin api b53be8f
gusfcarvalho Oct 2, 2026
d0fbdaa
fix!: remote_config.mode defaults to report
gusfcarvalho Oct 2, 2026
042e3d1
docs: drop the policy bundle inventory and describe redaction by value
gusfcarvalho Oct 2, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -114,6 +114,11 @@ change here must keep working with them.
and `_policy_data_digest`.
- **The agent never computes artifact digests.** It passes each evaluation's policy
directory, input and policy data through to the API, which canonicalises and hashes them.
- **Evidence identity.** `policy-manager`'s `newEvidence` seed is every evidence stream's UUID, and plugins in the
field compute it. Never change it. The golden test in `policy-manager/evidence_seed_test.go` pins the UUIDs.
- **Plugin library version.** `internal/pluginlib` reads the agent library a plugin binary was built with from its
Go build info. The config report lists it per plugin (`plugins[].lib-version`) as diagnostics only; nothing is
gated on it.
- **Storage failure doesn't drop evidence.** If artifact storage fails, the evidence is still
sent, without digests.
- **OCI policy bundles.** The agent evaluates the extracted `policies/` subdirectory, and that
Expand Down
2 changes: 1 addition & 1 deletion Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@ proto-gen: ## Generate objects from proto definitions
##@ Test
.PHONY: test
test: ## Run tests
@if ! go test ./... -coverprofile cover.out -v; then \
@if ! go test ./... -race -coverprofile cover.out -v; then \
$(WARN) "Tests failed"; \
exit 1; \
fi ; \
Expand Down
12 changes: 12 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -92,6 +92,18 @@ The API auth settings follow the same rule, so `api.auth.client_id` and `api.aut
`CCF_API_AUTH_CLIENT_ID` and `CCF_API_AUTH_CLIENT_SECRET`. These values must be configured together; setting only one
will fail agent startup validation. The `client_id` value must be a valid UUID.

Values that come from `CCF_PLUGINS_*` variables are masked in the configuration reports the agent sends to the API,
as are secret-like keys and values (see [configuration](./docs/configuration.md#envname-placeholders)).
Plugins never receive `CCF_API_AUTH_*` variables.

### Remote configuration and state

With `api.auth` credentials the agent reports its configuration to the API. With `remote_config.mode` set to
`apply_safe` or `apply_all` it also applies a configuration overlay stored there, including `${env:NAME}` placeholders
in plugin config; the default mode, `report`, never fetches or applies one. Each instance keeps a stable ID and a cache in a state directory (`--state-dir` / `CCF_STATE_DIR`;
`--instance-id` / `CCF_INSTANCE_ID`). See [configuration](./docs/configuration.md#remote-configuration) and
[ADR 0003](./docs/adr/0003-remote-config-overlay.md).

## Usage

To run the agent, you must first build the agent, and then run it with the `agent` command. It is recommended,
Expand Down
Loading
Loading