All plugins

DSH / BUNDLE / BUNDLES

dsh-kubectl-guard

v0.2.1gengwg / dsh-kubectl-guard867c973f6b

InstallableBundlesBundles & other modulesCommunity · Topic auto-analysis

Overview

dsh-kubectl-guard

A dsh policy plugin that gates kubectl writes by kubeconfig context: hard-deny irreversible verbs outside local clusters, ask for the rest.

README / EN

Package documentation

Registry summary

A dsh policy plugin that gates kubectl writes by kubeconfig context: hard-deny irreversible verbs outside local clusters, ask for the rest.

dsh.pub verifies the pinned bundle contract, runtime facts, and distribution semantics. The complete README remains in the source repository.

Read the full README on GitHub

LIMITATIONS

Known limitations

- Only `kubectl`. helm, argocd and flux are not covered; the verb table is data, so adding them is an edit to `src/verbs.js`. - Pass-through wrappers (`sudo`, `time`, `nice`, ...) are seen through, but only until a bare-token wrapper argument: `timeout 30 kubectl delete ...` is not gated, because `30` ends the wrapper chain. - `current-context` is read with a line-anchored regex, not a YAML parser. Unreadable or unmatched means production, so the failure direction is safe. - The pseudonym salt is per-process: ids are stable within a session, not across restarts. - Guards are synchronous, so the deny path does no I/O beyond a cached `readFileSync`.