Skip to main content

Crate praxis_policy

Crate praxis_policy 

Source
Expand description

PPE is a policy enforcement runtime for AI agents.

It is a deterministic reference monitor between an agent and every capability it invokes: tools, prompts, resources, inference providers, and A2A methods. Each operation runs through a policy-defined pipeline that can resolve identity, make an authorization decision (delegated to an engine like Cedar or CEL), exchange and reduce credentials before a downstream call, redact inputs and outputs, track information flow across calls, and audit. You write that policy declaratively in APL, the configuration that defines each operation’s pipeline; PPE evaluates and enforces it at the boundary, against state the model cannot observe or forge.

§This crate

praxis-policy is the host facade: one dependency that re-exports the PPE runtime (praxis-policy-core, praxis-policy-apl-core, praxis-policy-apl-cmf, praxis-policy-apl-runtime), so a host depends on this crate instead of pinning each of them separately.

By default it is the engine only: no builtin plugins are compiled in. The bundled plugins, PDPs and session stores are registered from here, each behind a feature, and only what you enable is compiled.

§Usage

Engine only (register your own factories):

use std::sync::Arc;
use praxis_policy::PolicyEngine;

let mgr = Arc::new(PolicyEngine::default());
// ... register host factories, then `praxis_policy_apl_runtime::register_apl(&mgr, opts)`.

With the bundled builtins (enable the builtins feature):

use std::sync::Arc;
use praxis_policy::PolicyEngine;

let mgr = Arc::new(PolicyEngine::default());
// Register every enabled builtin factory and install the APL config
// visitor (in-process defaults) in one call:
praxis_policy::install_builtins(&mgr);
// ... then load a config that references the enabled `kind`s.

§Features

No plugins are on by default (praxis-policy alone is the engine). builtins enables every bundled extension, including the Valkey session store; or pick a granular subset (jwt, oauth, elicitation-ciba, cedar, cel, opa, valkey). Any of them brings in the registration helpers, and each one re-exports its own concrete factory type here.

§Plugins the host supplies

A plugin does not have to be bundled. Implement PluginFactory and hand it to PolicyEngine::register_factory under the kind: your YAML names; prelude is the surface to write it against. An unrecognised kind is a load-time error, so a missing registration fails at startup rather than silently skipping the plugin.

reference/plugins/ in this repository holds two worked examples, a PII scanner and an audit logger. Neither is published or bundled; a host registers them.

Re-exports§

pub use praxis_policy_apl_cmf;
pub use praxis_policy_apl_core;
pub use praxis_policy_apl_runtime;
pub use praxis_policy_core;

Modules§

prelude
Curated re-exports for plugin authors, so a plugin crate can depend on this facade alone. See praxis_policy_core::prelude. Curated re-exports for plugin authors. Curated surface for plugin authors.

Structs§

AplOptions
Configuration for register_apl. All runtime collaborators APL needs to do its work are funneled through here so the call site reads as a single block instead of a multi-step builder.
CedarDirectPdpFactory
Factory for CedarDirectResolver. Reports kind() = "cedar-direct"; builds resolvers from the unified-config block via CedarDirectResolver::from_config.
CelPdpFactory
Factory for CelResolver. Reports kind() = "cel"; builds resolvers from the unified-config block via CelResolver::from_config.
CibaApproverFactory
Factory for kind: elicitation/ciba plugins. Instantiates a CibaApprover from the config: block and registers it on the elicit hook.
DispatchCache
Host-owned dispatch cache. Construct once, share via Arc<DispatchCache> across all CmfPluginInvoker::for_request calls so plans built for one request can be reused by the next.
JwtIdentityFactory
Factory for kind: identity/jwt plugins. Instantiates a JwtIdentityResolver from the config: block and registers it on the identity.resolve hook.
MemorySessionStore
In-process SessionStore backed by a HashMap of HashSets. Suitable for tests, single-process deployments, and as the default when no distributed store is configured. Cloning the store via Arc shares state across all consumers.
OAuthDelegatorFactory
Factory for kind: delegator/oauth plugins. Instantiates an OAuthDelegator from the config: block and registers it on the token.delegate hook.
OpaPdpFactory
Factory for OpaResolver. Reports kind() = "opa"; builds resolvers from the unified-config block via OpaResolver::from_config.
PluginInstance
The two types a host needs to accept a plugin it did not compile in: PolicyEngine::register_factory takes a Box<dyn PluginFactory>, and PluginInstance is what that factory returns.
PolicyEngine
Owns registered plugins and dispatches hook invocations to them.
ValkeyConfig
Parsed global.apl.session_store config for kind: valkey.
ValkeySessionStoreFactory
Factory the host registers via AplOptions.session_store_factories.

Constants§

CIBA_KIND
The plugin kind: string operators write in PPE YAML to declare a CIBA elicitation handler.
JWT_KIND
The plugin kind: string operators write in PPE YAML to declare a JWT identity resolver.
OAUTH_KIND
The plugin kind: string operators write in PPE YAML to declare an OAuth RFC 8693 token-exchange delegator.
VALKEY_KIND
The kind: discriminator this factory builds. Part of the public surface — it is the string operators write in their config.

Traits§

PdpFactory
Build a PdpResolver from a unified-config block. Implemented per PDP backend (cedar-direct, opa, …) and registered with the praxis-policy-apl-runtime visitor so unified-config YAML can declare PDPs without the host pre-constructing them in code.
PluginFactory
The two types a host needs to accept a plugin it did not compile in: PolicyEngine::register_factory takes a Box<dyn PluginFactory>, and PluginInstance is what that factory returns.
SessionStore
Pluggable session-state backend. Implementations must be Send + Sync — the same store is shared across all concurrent requests.
SessionStoreFactory
Factory the visitor consults when it encounters a global.apl.session_store block in the unified config. Mirrors praxis_policy_apl_core::step::PdpFactory: each factory advertises a kind() string matching the YAML block’s kind: field, and build turns the block into a live store. Registered up front via crate::AplOptions::session_store_factories; the visitor selects the active store from config during its global-config walk, before any route handler captures the store.

Functions§

builtin_pdp_factories
The enabled PDP factories, ready to drop into AplOptions::pdp_factories. A route’s cedar:, cel: or opa: step selects which one runs.
builtin_session_store_factories
The enabled session-store factories, ready to drop into AplOptions::session_store_factories. A global.apl.session_store: { kind: ... } config block selects one; absent that, the in-process MemorySessionStore default stays active.
install_builtins
Register every enabled plugin factory and install the APL config visitor on mgr with in-process defaults (a MemorySessionStore and the default baseline capabilities). The enabled PDP and session-store factories are wired in, so a later config load can reference any of them by kind.
register_apl
Build an AplConfigVisitor from the supplied options and register it on the engine. Returns the Arc<AplConfigVisitor> so the caller can stash it for later inspection (or call register_pdp on it after the fact for late-bound resolvers) — but in the typical case the return value is dropped and the visitor lives inside the engine’s visitor list.
register_builtin_plugins
Register every enabled by-kind plugin factory on mgr: identity (jwt), delegators (oauth), and elicitation approvers (elicitation-ciba). Call before loading a config so the engine can instantiate plugins whose YAML kind: matches.