pub struct PolicyEngine { /* private fields */ }Expand description
Thread-safe Cedar policy engine.
Wraps the Cedar Authorizer + PolicySet + Schema + entity store.
All state is behind an RwLock so policies and entities can be updated
at runtime without restart.
Implementations§
Source§impl PolicyEngine
impl PolicyEngine
Sourcepub fn new(
schema_text: &str,
policies: &[(&str, &str)],
) -> Result<PolicyEngine, PolicyError>
pub fn new( schema_text: &str, policies: &[(&str, &str)], ) -> Result<PolicyEngine, PolicyError>
Create a new policy engine from schema and policy files.
Validates the schema and all policies at construction time. Returns an error if any schema or policy is invalid.
Sourcepub fn open_mode() -> PolicyEngine
pub fn open_mode() -> PolicyEngine
Create a policy engine in open mode: all requests are allowed.
Used when the cedar feature is disabled or for development/testing.
§Warning
Open mode is unsafe for production. Every authorization request is
permitted without any policy evaluation. A tracing::error! is emitted
at construction time so that production monitoring surfaces the
misconfiguration. Configure policies_dir to enable Cedar evaluation.
Sourcepub fn load_from_brain(brain_dir: &Path) -> Result<PolicyEngine, PolicyError>
pub fn load_from_brain(brain_dir: &Path) -> Result<PolicyEngine, PolicyError>
Load policies from a brain directory.
Reads {brain_dir}/policies/hirn.cedarschema (or uses default schema)
and all *.cedar files in {brain_dir}/policies/.
Fails closed when no policy files are present. Use
Self::load_from_brain_insecure_dev_mode to explicitly opt into the
built-in permit-all development policy.
Sourcepub fn load_from_brain_insecure_dev_mode(
brain_dir: &Path,
) -> Result<PolicyEngine, PolicyError>
pub fn load_from_brain_insecure_dev_mode( brain_dir: &Path, ) -> Result<PolicyEngine, PolicyError>
Load policies from a brain directory, permitting the built-in default
open policy when no *.cedar files are present.
This is intended only for explicit development/test posture. A
tracing::error! is emitted to surface this misconfiguration.
Sourcepub fn is_open_mode(&self) -> bool
pub fn is_open_mode(&self) -> bool
Check whether this engine is in open mode (all requests allowed).
Sourcepub fn is_enabled(&self) -> bool
pub fn is_enabled(&self) -> bool
Whether Cedar policy evaluation is active (not open mode).
Sourcepub fn policy_count(&self) -> usize
pub fn policy_count(&self) -> usize
Returns the number of loaded policies.
Sourcepub fn entity_count(&self) -> usize
pub fn entity_count(&self) -> usize
Returns the number of registered entities.
Sourcepub fn registered_namespaces(&self) -> Vec<(String, String)>
pub fn registered_namespaces(&self) -> Vec<(String, String)>
List all registered namespace IDs and their associated realms.
Sourcepub fn list_policies(&self) -> Vec<(String, String)>
pub fn list_policies(&self) -> Vec<(String, String)>
List all policy source names and their raw Cedar text.
Authorize a request against loaded policies.
Returns an AuthzDecision indicating whether the request is allowed
or denied, along with diagnostic information.
Sourcepub fn allowed_namespaces_for(
&self,
agent_id: &str,
action: Action,
) -> Option<Vec<String>>
pub fn allowed_namespaces_for( &self, agent_id: &str, action: Action, ) -> Option<Vec<String>>
Resolve which namespaces an agent can access for a given action.
Returns None if engine is in open mode (permit all).
Returns Some(vec![...]) with allowed namespace IDs otherwise.
Sourcepub fn register_agent(
&self,
agent_id: &str,
reputation: i64,
created_at: &str,
teams: &[&str],
) -> Result<(), PolicyError>
pub fn register_agent( &self, agent_id: &str, reputation: i64, created_at: &str, teams: &[&str], ) -> Result<(), PolicyError>
Register an agent entity.
Sourcepub fn register_team(
&self,
team_id: &str,
description: &str,
organization: Option<&str>,
) -> Result<(), PolicyError>
pub fn register_team( &self, team_id: &str, description: &str, organization: Option<&str>, ) -> Result<(), PolicyError>
Register a team entity.
Sourcepub fn register_organization(
&self,
org_id: &str,
description: &str,
) -> Result<(), PolicyError>
pub fn register_organization( &self, org_id: &str, description: &str, ) -> Result<(), PolicyError>
Register an organization entity.
Sourcepub fn register_realm(
&self,
realm_id: &str,
description: &str,
) -> Result<(), PolicyError>
pub fn register_realm( &self, realm_id: &str, description: &str, ) -> Result<(), PolicyError>
Register a realm entity.
Sourcepub fn register_namespace(
&self,
namespace_id: &str,
classification: &str,
realm: &str,
) -> Result<(), PolicyError>
pub fn register_namespace( &self, namespace_id: &str, classification: &str, realm: &str, ) -> Result<(), PolicyError>
Register a namespace entity.
Sourcepub fn register_memory_layer(
&self,
layer_id: &str,
description: &str,
) -> Result<(), PolicyError>
pub fn register_memory_layer( &self, layer_id: &str, description: &str, ) -> Result<(), PolicyError>
Register a memory layer entity (Working, Episodic, Semantic, Procedural).
Sourcepub fn register_operation(
&self,
operation_id: &str,
description: &str,
) -> Result<(), PolicyError>
pub fn register_operation( &self, operation_id: &str, description: &str, ) -> Result<(), PolicyError>
Register an operation entity (Recall, Think, Remember, etc.).
Sourcepub fn register_tool(
&self,
tool_id: &str,
description: &str,
) -> Result<(), PolicyError>
pub fn register_tool( &self, tool_id: &str, description: &str, ) -> Result<(), PolicyError>
Register a tool entity for MCP tool-level access control.
Sourcepub fn remove_entity(&self, key: &str) -> Result<bool, PolicyError>
pub fn remove_entity(&self, key: &str) -> Result<bool, PolicyError>
Remove an entity by its Cedar key (e.g. Hirn::Agent::"agent-007").
Sourcepub fn add_policy(
&self,
name: &str,
policy_text: &str,
) -> Result<(), PolicyError>
pub fn add_policy( &self, name: &str, policy_text: &str, ) -> Result<(), PolicyError>
Add or replace a policy source.
Sourcepub fn add_policies(&self, policies: &[(&str, &str)]) -> Result<(), PolicyError>
pub fn add_policies(&self, policies: &[(&str, &str)]) -> Result<(), PolicyError>
Atomically add or replace multiple policy sources.
Sourcepub fn remove_policy(&self, name: &str) -> Result<bool, PolicyError>
pub fn remove_policy(&self, name: &str) -> Result<bool, PolicyError>
Remove a policy source by name.
Sourcepub fn save_to_brain(&self, brain_dir: &Path) -> Result<(), PolicyError>
pub fn save_to_brain(&self, brain_dir: &Path) -> Result<(), PolicyError>
Save the current policies and schema to a brain directory.
Trait Implementations§
Source§impl Clone for PolicyEngine
impl Clone for PolicyEngine
Source§fn clone(&self) -> PolicyEngine
fn clone(&self) -> PolicyEngine
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read moreAuto Trait Implementations§
impl Freeze for PolicyEngine
impl !RefUnwindSafe for PolicyEngine
impl Send for PolicyEngine
impl Sync for PolicyEngine
impl Unpin for PolicyEngine
impl UnsafeUnpin for PolicyEngine
impl !UnwindSafe for PolicyEngine
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> Downcast for Twhere
T: Any,
impl<T> Downcast for Twhere
T: Any,
Source§fn into_any(self: Box<T>) -> Box<dyn Any>
fn into_any(self: Box<T>) -> Box<dyn Any>
Box<dyn Trait> (where Trait: Downcast) to Box<dyn Any>, which can then be
downcast into Box<dyn ConcreteType> where ConcreteType implements Trait.Source§fn into_any_rc(self: Rc<T>) -> Rc<dyn Any>
fn into_any_rc(self: Rc<T>) -> Rc<dyn Any>
Rc<Trait> (where Trait: Downcast) to Rc<Any>, which can then be further
downcast into Rc<ConcreteType> where ConcreteType implements Trait.Source§fn as_any(&self) -> &(dyn Any + 'static)
fn as_any(&self) -> &(dyn Any + 'static)
&Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot
generate &Any’s vtable from &Trait’s.Source§fn as_any_mut(&mut self) -> &mut (dyn Any + 'static)
fn as_any_mut(&mut self) -> &mut (dyn Any + 'static)
&mut Trait (where Trait: Downcast) to &Any. This is needed since Rust cannot
generate &mut Any’s vtable from &mut Trait’s.Source§impl<T> DowncastSend for T
impl<T> DowncastSend for T
Source§impl<T> DowncastSync for T
impl<T> DowncastSync for T
Source§impl<T> FmtForward for T
impl<T> FmtForward for T
Source§fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
fn fmt_binary(self) -> FmtBinary<Self>where
Self: Binary,
self to use its Binary implementation when Debug-formatted.Source§fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
fn fmt_display(self) -> FmtDisplay<Self>where
Self: Display,
self to use its Display implementation when
Debug-formatted.Source§fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
fn fmt_lower_exp(self) -> FmtLowerExp<Self>where
Self: LowerExp,
self to use its LowerExp implementation when
Debug-formatted.Source§fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
fn fmt_lower_hex(self) -> FmtLowerHex<Self>where
Self: LowerHex,
self to use its LowerHex implementation when
Debug-formatted.Source§fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
fn fmt_octal(self) -> FmtOctal<Self>where
Self: Octal,
self to use its Octal implementation when Debug-formatted.Source§fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
fn fmt_pointer(self) -> FmtPointer<Self>where
Self: Pointer,
self to use its Pointer implementation when
Debug-formatted.Source§fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
fn fmt_upper_exp(self) -> FmtUpperExp<Self>where
Self: UpperExp,
self to use its UpperExp implementation when
Debug-formatted.Source§fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
fn fmt_upper_hex(self) -> FmtUpperHex<Self>where
Self: UpperHex,
self to use its UpperHex implementation when
Debug-formatted.Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§impl<T> Pipe for Twhere
T: ?Sized,
impl<T> Pipe for Twhere
T: ?Sized,
Source§fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
Source§fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read moreSource§fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read moreSource§fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
Source§fn pipe_borrow_mut<'a, B, R>(
&'a mut self,
func: impl FnOnce(&'a mut B) -> R,
) -> R
fn pipe_borrow_mut<'a, B, R>( &'a mut self, func: impl FnOnce(&'a mut B) -> R, ) -> R
Source§fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
self, then passes self.as_ref() into the pipe function.Source§fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
self, then passes self.as_mut() into the pipe
function.Source§fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
self, then passes self.deref() into the pipe function.Source§impl<T> Pointable for T
impl<T> Pointable for T
Source§impl<T> PolicyExt for Twhere
T: ?Sized,
impl<T> PolicyExt for Twhere
T: ?Sized,
Source§impl<T> Tap for T
impl<T> Tap for T
Source§fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
Borrow<B> of a value. Read moreSource§fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
BorrowMut<B> of a value. Read moreSource§fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
AsRef<R> view of a value. Read moreSource§fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
AsMut<R> view of a value. Read moreSource§fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
Deref::Target of a value. Read moreSource§fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
Deref::Target of a value. Read moreSource§fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
.tap() only in debug builds, and is erased in release builds.Source§fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
.tap_mut() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
.tap_borrow() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
.tap_borrow_mut() only in debug builds, and is erased in release
builds.Source§fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
.tap_ref() only in debug builds, and is erased in release
builds.Source§fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
.tap_ref_mut() only in debug builds, and is erased in release
builds.Source§fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
.tap_deref() only in debug builds, and is erased in release
builds.