Elinpf/dsh-ops-plugins--packages-ops-access-gate ↗★ 1

@elinpf/dsh-ops-access-gate

Ops access gate — per-session credential brokering. Owns an in-process grant ledger keyed by agent.id and registers a pure-decision broker (ro/rw) into the ops-access seam. Never touches credential fields. 适合需要对敏感运维操作进行会话级动态授权、限时审批和审计的团队。

パッケージ
@elinpf/dsh-ops-access-gate
互換性
未検証
Harness ピア範囲
^0.1.0-rc.8
Cordis ピア範囲
^4.0.1
バージョン
0.4.1
最終更新
2026/09/18

インストール

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:Elinpf/dsh-ops-plugins#64b1d76649bf24155173c74254d0fb61d12815d5&path:packages/ops-access/gate

ドキュメント

README 全文を読む ↗

Configuration

KeyDefaultMeaning
approvalRequiredKinds['ssh']Kinds with no ro tier — any use requires a grant
defaultTtlMinutes30Grant lifetime when request_access omits ttlMinutes
maxTtlMinutes480Upper bound for a requested grant lifetime
auditFile~/.dsh-ops/audit.logJSONL audit log path (~ expands)
grantTtlOptions[10, 30, 60, 120]TTL choices the access panel offers
pendingRequestTimeoutMinutes5How long a parked request awaits a human before auto-rejecting
deniedFile~/.dsh-ops/denied.jsonPersisted lockdown state (survives restarts)