Elinpf/dsh-ops-plugins--packages-ops-access-gate ↗★ 1
@elinpf/dsh-ops-access-gate
Ops access gate — per-session credential brokering. Owns an in-process grant ledger keyed by agent.id and registers a pure-decision broker (ro/rw) into the ops-access seam. Never touches credential fields. 适合需要对敏感运维操作进行会话级动态授权、限时审批和审计的团队。
Install
$
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:Elinpf/dsh-ops-plugins#64b1d76649bf24155173c74254d0fb61d12815d5&path:packages/ops-access/gateREADME
Read the full README ↗Configuration
| Key | Default | Meaning |
|---|---|---|
approvalRequiredKinds | ['ssh'] | Kinds with no ro tier — any use requires a grant |
defaultTtlMinutes | 30 | Grant lifetime when request_access omits ttlMinutes |
maxTtlMinutes | 480 | Upper bound for a requested grant lifetime |
auditFile | ~/.dsh-ops/audit.log | JSONL audit log path (~ expands) |
grantTtlOptions | [10, 30, 60, 120] | TTL choices the access panel offers |
pendingRequestTimeoutMinutes | 5 | How long a parked request awaits a human before auto-rejecting |
deniedFile | ~/.dsh-ops/denied.json | Persisted lockdown state (survives restarts) |