Skip to main content

Module media

Module media 

Source
Expand description

Governed remote-media ingestion.

A model-provider URL is an egress bypass: the provider, not this plane, resolves and fetches it. This module makes dereferencing explicit and replayable. A fetch is bound to the exact labelled URL, resolves every hop, refuses any non-public answer, pins the checked addresses into the HTTP client, validates each redirect, streams under a hard byte ceiling, refuses content coding and ungranted media types, runs operator validators, and stores only a content digest in the journal.

The policy is deny-by-default. There is no wildcard host grant, no system proxy, no cookie jar, no automatic redirect, no ambient credential, and no switch that accepts private addresses. Network segmentation remains useful defence in depth; application checks are not a firewall.

Structs§

FetchedMedia
A fetched immutable artifact. The journal carries this metadata and digest, while the potentially erasable bytes live in the configured blob store.
GovernedFetch
The effect used internally by StepCtx::fetch_media.
GovernedMedia
A configured governed-media fetcher.
MediaCandidate
Metadata exposed to malware, file-format, and content-policy validators.
MediaHop
Auditable transport provenance for one origin or redirect hop.
MediaPolicy
The complete, digest-covered policy for one media fetch.

Enums§

MediaRetention
How fetched media is made erasable.
Verdict
What a validator concluded about an artifact.

Traits§

MediaValidator
An operator-supplied content validator.