Add AST-based security middleware and enforcement wiring
This commit is contained in:
@@ -38,6 +38,15 @@
|
||||
- `AGENT_PORT_PRIMARY_OFFSET`
|
||||
- `AGENT_PORT_LOCK_DIR`
|
||||
- `AGENT_DISCOVERY_FILE_RELATIVE_PATH`
|
||||
- Security middleware controls:
|
||||
- `AGENT_SECURITY_VIOLATION_MODE`
|
||||
- `AGENT_SECURITY_ALLOWED_BINARIES`
|
||||
- `AGENT_SECURITY_COMMAND_TIMEOUT_MS`
|
||||
- `AGENT_SECURITY_AUDIT_LOG_PATH`
|
||||
- `AGENT_SECURITY_ENV_INHERIT`
|
||||
- `AGENT_SECURITY_ENV_SCRUB`
|
||||
- `AGENT_SECURITY_DROP_UID`
|
||||
- `AGENT_SECURITY_DROP_GID`
|
||||
|
||||
## Documentation Standards
|
||||
- Update `README.md` for user-facing behavior.
|
||||
|
||||
Reference in New Issue
Block a user