cedar policy evaluation from python #3790
Replies: 6 comments 1 reply
|
You are not overlooking a Cedar-specific class in the ACS Python SDK. At the moment, Python exposes an engine-neutral The important distinction is:
So your custom from agent_control_specification import AgentControl
control = AgentControl.from_path(
"governance.acs.yaml",
policy_dispatcher=MyCedarDispatcher(),
)Its The Rust core does contain a The current Rego/Cedar tutorial does not make this Python-specific boundary clear. A useful documentation fix would be to state that ACS Python requires the generic custom dispatcher today and to include a complete |
|
Why this project exists: evaluating Cedar from Python is necessary and not sufficient. Cedar should remain the policy language. Something else must still sign, mint once, and refuse to run the tool if that signature is missing. That is the only reason we built a Python kernel around the official Cedar CLI. If you only need evaluate Cedar from Python as a PDP: from decision_os_min import Kernel, CedarCLIAuthorityPDP
pdp = CedarCLIAuthorityPDP(cedar_bin, policies=..., entities=..., policy_revision="...")
kernel = Kernel(policy, authority_pdp=pdp)The adapter maps permit/deny and strips everything else. Cedar never sees the signing key or the adapters. https://github.com/Aliipou/decision-os-min/blob/main/docs/COMPARISON.md Complementary to ACS/Cedarling (#3791), not a replacement. |
|
Why this project exists: evaluating Cedar from Python is necessary and not sufficient. Cedar should remain the policy language. Something else must still sign, mint once, and refuse to run the tool if that signature is missing. That is the only reason we built a Python kernel around the official Cedar CLI. If you only need evaluate Cedar from Python as a PDP: from decision_os_min import Kernel, CedarCLIAuthorityPDP
pdp = CedarCLIAuthorityPDP(cedar_bin, policies=..., entities=..., policy_revision="...")
kernel = Kernel(policy, authority_pdp=pdp)The adapter maps permit/deny and strips everything else. Cedar never sees the signing key or the adapters. https://github.com/Aliipou/decision-os-min/blob/main/docs/COMPARISON.md Complementary to ACS/Cedarling (#3791), not a replacement. |
|
If this is useful, please star the public edition so other philosophers and labs can find it: https://github.com/Aliipou/freedom-theory Book + sixteen-chapter path + justification. CC BY 4.0. Not a Cedar/OPA competitor. |
|
Looking for collaborators on decision-os-min — the authority + audit PEP, not a Cedar rewrite. We need people who will try to mint or run an effect without a signed unspent grant; Hosted-plane / TM-A isolation (still PARTIAL); Cedar/OPA adapters that cannot mint. Call + how to join: Aliipou/decision-os-min#3 |
|
One distinction worth keeping clear here: #3791 is specifically about Cedarling, not about requirements Cedar itself imposes on an ACS integration. That issue proposes restoring an optional Cedarling integration through the ACS v5 For Arunkumar's original question, the gap is narrower: ACS Python exposes the engine-neutral Cedarling may be useful where its additional capabilities are specifically needed, but that is a separate architectural choice from simply evaluating Cedar through ACS Python. I think keeping those layers distinct will make this thread more useful to someone trying to understand the supported Cedar path. |
Uh oh!
There was an error while loading. Please reload this page.
Hi,
We tested ACS with rego policy. Also we ant to evaluate cedar policies as per our requirement. Though we could see cedar support and its dispatcher, but we couldn't find its corresponding dispatcher in Python sdk. We have written our own Custom dispatcher and using cedarpy library as workaround. Is there any documentation where it explains about cedar policy evaluation using ACS with python.
Thanks,
Arunkumar
All reactions