Expand description
Governed remote-media ingestion.
A model-provider URL is an egress bypass: the provider, not this plane, resolves and fetches it. This module makes dereferencing explicit and replayable. A fetch is bound to the exact labelled URL, resolves every hop, refuses any non-public answer, pins the checked addresses into the HTTP client, validates each redirect, streams under a hard byte ceiling, refuses content coding and ungranted media types, runs operator validators, and stores only a content digest in the journal.
The policy is deny-by-default. There is no wildcard host grant, no system proxy, no cookie jar, no automatic redirect, no ambient credential, and no switch that accepts private addresses. Network segmentation remains useful defence in depth; application checks are not a firewall.
Structs§
- Fetched
Media - A fetched immutable artifact. The journal carries this metadata and digest, while the potentially erasable bytes live in the configured blob store.
- Governed
Fetch - The effect used internally by
StepCtx::fetch_media. - Governed
Media - A configured governed-media fetcher.
- Media
Candidate - Metadata exposed to malware, file-format, and content-policy validators.
- Media
Hop - Auditable transport provenance for one origin or redirect hop.
- Media
Policy - The complete, digest-covered policy for one media fetch.
Enums§
- Media
Retention - How fetched media is made erasable.
- Verdict
- What a validator concluded about an artifact.
Traits§
- Media
Validator - An operator-supplied content validator.