Struct SecurityConfig
pub struct SecurityConfig {
pub nat64_prefixes: Vec<String>,
pub audit: AuditConfig,
pub leak_detection: LeakDetectionConfig,
pub otp: OtpConfig,
pub estop: EstopConfig,
pub nevis: NevisConfig,
pub webauthn: WebAuthnConfig,
}Expand description
Security configuration for audit logging, OTP, e-stop, IAM/SSO, WebAuthn, and the host’s NAT64 egress boundary.
Sandbox backend and resource limits live on per-agent risk profiles
(see RiskProfileConfig::sandbox_* and RiskProfileConfig::max_*); the
runtime resolves them via Config::active_risk_profile(agent_alias).
Fields§
§nat64_prefixes: Vec<String>Network-specific RFC 6052 NAT64 prefixes deployed on this host’s
network, for example
[security] nat64_prefixes = ["2001:db8:122:344::/96"]. Default: [].
A NAT64 translator delivers any IPv6 destination inside one of these
prefixes to the IPv4 address embedded in it. The prefix is an
organization’s own choice and nothing in the address reveals it, so
without this list an attacker-controlled hostname can resolve to an
apparently-global IPv6 address that the local translator maps to
10.0.0.1 or 169.254.169.254, and the outbound SSRF checks accept
it. Declaring the prefixes in use makes the address they translate to
part of the validation boundary for http_request, web_fetch, and
text_browser.
Each entry is <ipv6>/<length> with one of RFC 6052 §2.2’s lengths —
32, 40, 48, 56, 64, or 96 — and no bits set beyond that length. A
malformed entry fails construction of the tools that read this list
rather than being skipped, so a typo cannot silently narrow the
boundary.
The default is correct for deployments that run no NAT64 translator and
for those that use only the well-known 64:ff9b::/96 prefix, which is
classified without configuration.
RFC 8215 also standardizes 64:ff9b:1::/48 as the local-use NAT64
block, and it still needs declaring. The public-address validator
already denies the whole block as non-global, so the default is safe on
its own. But that non-global check is precisely what the private-host
opt-in relaxes, and the metadata gate that remains unconditional
underneath it decodes only the well-known /96, not this block. A
deployment that translates from 64:ff9b:1::/48 must therefore declare
the specific prefix it uses here; otherwise, once a host is allowed
through allowed_private_hosts, an address in that block reaches the
translator’s embedded IPv4 destination without that destination being
classified.
Declared prefixes may overlap, and an address inside several of them decodes to a different IPv4 destination under each. Validation is conservative: an address is accepted only when every declared translation it matches lands somewhere acceptable, so a nested prefix that decodes an address to a private or metadata destination denies it even when a broader prefix decodes the same address globally. If that refuses destinations you consider legitimate, narrow the declared prefixes to the translations actually deployed.
audit: AuditConfigAudit logging configuration
leak_detection: LeakDetectionConfigOutbound credential leak detection and redaction configuration. See
[security.leak_detection] for the detector controls.
otp: OtpConfigOTP gating configuration for sensitive actions/domains.
estop: EstopConfigEmergency-stop state machine configuration.
nevis: NevisConfigNevis IAM integration for SSO/MFA authentication and role-based access.
webauthn: WebAuthnConfigWebAuthn / FIDO2 hardware key authentication configuration.
Implementations§
Source§impl SecurityConfig
impl SecurityConfig
Sourcepub fn configurable_prefix() -> &'static str
pub fn configurable_prefix() -> &'static str
Returns the #[prefix] value for this Configurable struct.
Sourcepub fn init_requires_explicit_config() -> bool
pub fn init_requires_explicit_config() -> bool
True when this struct has a required leaf field that a
bare/ancestor-prefix init_defaults scaffold must not
materialize (it would fill the field with its Rust
Default, which prune_empty_leaves then strips on save,
leaving a partial sub-table that fails strict reload).
Explicitly targeting this section (or a descendant of it)
still scaffolds regardless of this flag, so the section can
be materialized for the operator to fill in.
Sourcepub fn secret_fields(&self) -> Vec<SecretFieldInfo>
pub fn secret_fields(&self) -> Vec<SecretFieldInfo>
Returns metadata about all #[secret] fields on this struct and nested children.
pub fn secret_field_terminals() -> Vec<&'static str>
Sourcepub fn encrypt_secrets(&mut self, store: &SecretStore) -> Result<(), Error>
pub fn encrypt_secrets(&mut self, store: &SecretStore) -> Result<(), Error>
Encrypt all secret fields in place using the provided store.
Sourcepub fn decrypt_secrets(&mut self, store: &SecretStore) -> Result<(), Error>
pub fn decrypt_secrets(&mut self, store: &SecretStore) -> Result<(), Error>
Decrypt all secret fields in place using the provided store.
Sourcepub fn set_secret(&mut self, name: &str, value: String) -> Result<(), Error>
pub fn set_secret(&mut self, name: &str, value: String) -> Result<(), Error>
Set a secret field by its full dotted name, dispatching to nested children.
Sourcepub fn prop_fields(&self) -> Vec<PropFieldInfo>
pub fn prop_fields(&self) -> Vec<PropFieldInfo>
Returns metadata about all property fields on this struct and nested children.
Sourcepub fn get_prop(&self, name: &str) -> Result<String, Error>
pub fn get_prop(&self, name: &str) -> Result<String, Error>
Get a property value by its full dotted name, returning it as a display string.
Sourcepub fn set_prop(&mut self, name: &str, value_str: &str) -> Result<(), Error>
pub fn set_prop(&mut self, name: &str, value_str: &str) -> Result<(), Error>
Set a property value by its full dotted name, parsing from string.
Sourcepub fn prop_is_secret(name: &str) -> bool
pub fn prop_is_secret(name: &str) -> bool
Check if a property name refers to a secret field (static, no instance needed).
Sourcepub fn init_defaults(&mut self, prefix: Option<&str>) -> Vec<&'static str>
pub fn init_defaults(&mut self, prefix: Option<&str>) -> Vec<&'static str>
Instantiate None nested sections whose prefix matches.
Returns the prefixes that were initialized.
Sourcepub fn map_key_sections() -> Vec<MapKeySection>
pub fn map_key_sections() -> Vec<MapKeySection>
Enumerate every map-keyed (HashMap<String, T>) and list-shaped
(Vec<T>) section discoverable from this Configurable’s tree.
The dashboard / CLI consume this to surface “+ Add” affordances
without hardcoding the section list.
Sourcepub fn nested_section_help(name: &str) -> Option<&'static str>
pub fn nested_section_help(name: &str) -> Option<&'static str>
Help blurb for a #[nested] field on this struct, sourced from
the field-level /// docstring. Returns None for unknown
names so callers can fall through to a different lookup.
pub fn nested_section_group(name: &str) -> Option<&'static str>
Sourcepub fn get_map_keys(&self, section_path: &str) -> Option<Vec<String>>
pub fn get_map_keys(&self, section_path: &str) -> Option<Vec<String>>
Return the current alias keys at section_path, or None if
the path doesn’t resolve to a map-keyed section in this tree.
pub fn nested_option_entries(&self) -> Vec<NestedOptionEntry>
pub fn create_map_key( &mut self, section_path: &str, map_key: &str, ) -> Result<bool, String>
pub fn delete_map_key( &mut self, section_path: &str, map_key: &str, ) -> Result<bool, String>
pub fn rename_map_key( &mut self, section_path: &str, map_key: &str, new_key: &str, ) -> Result<bool, String>
Trait Implementations§
Source§impl Clone for SecurityConfig
impl Clone for SecurityConfig
Source§fn clone(&self) -> SecurityConfig
fn clone(&self) -> SecurityConfig
1.0.0 (const: unstable) · §fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreSource§impl Debug for SecurityConfig
impl Debug for SecurityConfig
Source§impl Default for SecurityConfig
impl Default for SecurityConfig
Source§fn default() -> SecurityConfig
fn default() -> SecurityConfig
Source§impl<'de> Deserialize<'de> for SecurityConfig
impl<'de> Deserialize<'de> for SecurityConfig
Source§fn deserialize<__D>(
__deserializer: __D,
) -> Result<SecurityConfig, <__D as Deserializer<'de>>::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(
__deserializer: __D,
) -> Result<SecurityConfig, <__D as Deserializer<'de>>::Error>where
__D: Deserializer<'de>,
Source§impl JsonSchema for SecurityConfig
impl JsonSchema for SecurityConfig
Source§fn schema_id() -> Cow<'static, str>
fn schema_id() -> Cow<'static, str>
Source§fn json_schema(generator: &mut SchemaGenerator) -> Schema
fn json_schema(generator: &mut SchemaGenerator) -> Schema
Source§fn inline_schema() -> bool
fn inline_schema() -> bool
$ref keyword. Read moreSource§impl MaskSecrets for SecurityConfig
impl MaskSecrets for SecurityConfig
fn mask_secrets(&mut self)
fn restore_secrets_from(&mut self, current: &SecurityConfig)
Source§impl Serialize for SecurityConfig
impl Serialize for SecurityConfig
Source§fn serialize<__S>(
&self,
__serializer: __S,
) -> Result<<__S as Serializer>::Ok, <__S as Serializer>::Error>where
__S: Serializer,
fn serialize<__S>(
&self,
__serializer: __S,
) -> Result<<__S as Serializer>::Ok, <__S as Serializer>::Error>where
__S: Serializer,
Auto Trait Implementations§
impl Freeze for SecurityConfig
impl RefUnwindSafe for SecurityConfig
impl Send for SecurityConfig
impl Sync for SecurityConfig
impl Unpin for SecurityConfig
impl UnsafeUnpin for SecurityConfig
impl UnwindSafe for SecurityConfig
Blanket Implementations§
§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more