Elinpf/dsh-ops-plugins--packages-ops-access-gate ↗★ 1

@elinpf/dsh-ops-access-gate

Ops access gate — per-session credential brokering. Owns an in-process grant ledger keyed by agent.id and registers a pure-decision broker (ro/rw) into the ops-access seam. Never touches credential fields. 适合需要对敏感运维操作进行会话级动态授权、限时审批和审计的团队。

패키지
@elinpf/dsh-ops-access-gate
호환성
미검증
Harness peer 범위
^0.1.0-rc.8
Cordis peer 범위
^4.0.1
버전
0.4.1
최근 업데이트
2026. 9. 18.

설치

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:Elinpf/dsh-ops-plugins#64b1d76649bf24155173c74254d0fb61d12815d5&path:packages/ops-access/gate

Configuration

KeyDefaultMeaning
approvalRequiredKinds['ssh']Kinds with no ro tier — any use requires a grant
defaultTtlMinutes30Grant lifetime when request_access omits ttlMinutes
maxTtlMinutes480Upper bound for a requested grant lifetime
auditFile~/.dsh-ops/audit.logJSONL audit log path (~ expands)
grantTtlOptions[10, 30, 60, 120]TTL choices the access panel offers
pendingRequestTimeoutMinutes5How long a parked request awaits a human before auto-rejecting
deniedFile~/.dsh-ops/denied.jsonPersisted lockdown state (survives restarts)