Jalankan sepenuhnya offline (air-gap)
Teks asli berbahasa Inggris -- terjemahan menunggu tinjauan teknis
Surfaces used: Python / Node SDK in Local mode, self-hosted gateway Modes supported: Local Tiers: Free (baseline), Self-Hosted enterprise for full air-gap deployment Status: Local-mode SDK is GA. Self-Hosted air-gap deployment is PRIVATE PREVIEW.
Yang akan Anda lakukan
Teks asli berbahasa Inggris -- terjemahan menunggu tinjauan teknis
Run Control Zero with zero outbound calls. Policy lives in a local YAML or JSON file on disk (both use the identical schema). Audit writes to a local file (or your own internal log sink). No telemetry, no dashboard calls, no license check-ins.
Mengapa ini jalur yang tepat untuk Anda
- Jika lingkungan Anda terputus (rahasia, teregulasi, atau sekadar offline karena kebijakan) dan Anda tidak dapat memanggil
api.controlzero.ai, ini untuk Anda. - Untuk satu developer atau beban kerja offline kecil, SDK dalam mode Local sudah cukup.
Teks asli berbahasa Inggris -- terjemahan menunggu tinjauan teknis
- For an organization running air-gapped, you want the Self-Hosted deployment: the dashboard, audit store, and signing infrastructure, all inside your boundary.
Kapan TIDAK menggunakan pendekatan ini
Teks asli berbahasa Inggris -- terjemahan menunggu tinjauan teknis
If you have internet egress and just want privacy, you do not need air-gap. Hosted mode already keeps prompts in-memory and only stores redacted audit metadata. Air-gap is for environments where outbound is not allowed, not just not preferred.
Penyiapan 5 menit (developer tunggal, mode Local)
pip install controlzero
Buat policy.yaml:
rules:
- id: block-shell-execute
deny: 'shell:execute'
reason: 'Destructive shell commands are not allowed.'
- id: allow-everything-else
allow: '*'
reason: 'Default-allow for everything else.'
# DLP rules scan tool args for sensitive data. Built-in patterns
# (AWS keys, GitHub tokens, SSNs, etc.) are always active. Add custom
# patterns here.
dlp_rules:
- id: block-internal-codes
pattern: 'PROJ-[A-Z]{3}-\d{6}'
category: custom
action: block
reason: 'Internal project codes must not leave the agent.'
Gunakan:
from controlzero import Client
cz = Client(policy_file="./policy.yaml")
decision = cz.guard(tool="shell", args={"command": "rm -rf /"})
assert not decision.allowed
Audit ditulis ke ./controlzero.log (ubah dengan log_path=).
Verifikasi tidak ada panggilan jaringan
# Block egress as a smoke test
sudo pfctl -e # or your firewall of choice
python your_app.py
Teks asli berbahasa Inggris -- terjemahan menunggu tinjauan teknis
The SDK should continue to work: policy is local, audit is local, nothing reaches out.
Deployment air-gap Self-Managed PRIVATE PREVIEW
Teks asli berbahasa Inggris -- terjemahan menunggu tinjauan teknis
For an organization running fully air-gapped, Self-Managed gives you the full experience: dashboard, policy signing, and audit store, all inside your boundary, with offline (signed-manifest) license validation and no outbound calls.
Teks asli berbahasa Inggris -- terjemahan menunggu tinjauan teknis
Self-Managed is delivered under a PRIVATE PREVIEW license. You receive a signed install package, a private install runbook, and a named support contact.
Langkah instalasi disertakan dalam paket instalasi dan tidak dipublikasikan di sini.
Untuk melakukan pilot, lihat Self-Managed atau hubungi kami.
Memverifikasi bahwa berfungsi
- Dengan egress diblokir, jalankan smoke test SDK di atas. Evaluasi kebijakan dan audit harus tetap berjalan.
Teks asli berbahasa Inggris -- terjemahan menunggu tinjauan teknis
- For Self-Managed: follow the verification steps in the install runbook delivered with your package; all components should report
okwith no outbound attempts.
- Pastikan file audit (mode Local) atau dasbor (Self-Hosted) bertambah seiring lalu lintas mengalir.
Tindak lanjut umum
- "Saya ingin panduan Python lengkap" -> Kendalikan aplikasi AI dengan Python
- "Saya ingin pola offline yang sama di Node" -> Kendalikan aplikasi AI dengan Node.js
- "Saya ingin melakukan pilot Self-Hosted" -> Self-Hosted
- "Bagaimana sebenarnya mode Local bekerja?" -> Jalankan sepenuhnya offline (mode Local)
Referensi
- Halaman titik penerapan: SDK Python, SDK Node.js, Mode Local-only, Self-Hosted
- Konsep: Kebijakan
- API: Referensi API