全部插件

DSH / BUNDLE / BUNDLES

dsh-kubectl-guard

v0.2.1gengwg / dsh-kubectl-guard867c973f6b

可安装组合包组合包与其他模块社区 · Topic 自动分析

概览

dsh-kubectl-guard

A dsh policy plugin that gates kubectl writes by kubeconfig context: hard-deny irreversible verbs outside local clusters, ask for the rest.

README / ZH

插件文档

目录摘要

A dsh policy plugin that gates kubectl writes by kubeconfig context: hard-deny irreversible verbs outside local clusters, ask for the rest.

dsh.pub 核对固定版本的组合包契约、运行时事实与分发语义;完整 README 请查看源仓库。

在 GitHub 阅读完整 README

LIMITATIONS

已知限制

- Only `kubectl`. helm, argocd and flux are not covered; the verb table is data, so adding them is an edit to `src/verbs.js`. - Pass-through wrappers (`sudo`, `time`, `nice`, ...) are seen through, but only until a bare-token wrapper argument: `timeout 30 kubectl delete ...` is not gated, because `30` ends the wrapper chain. - `current-context` is read with a line-anchored regex, not a YAML parser. Unreadable or unmatched means production, so the failure direction is safe. - The pseudonym salt is per-process: ids are stable within a session, not across restarts. - Guards are synchronous, so the deny path does no I/O beyond a cached `readFileSync`.