완전한 오프라인 실행 (에어갭)
영어 원문 -- 번역은 기술 검토 대기 중입니다
Surfaces used: Python / Node SDK in Local mode, self-hosted gateway Modes supported: Local Tiers: Free (baseline), Self-Hosted enterprise for full air-gap deployment Status: Local-mode SDK is GA. Self-Hosted air-gap deployment is PRIVATE PREVIEW.
수행할 내용
영어 원문 -- 번역은 기술 검토 대기 중입니다
Run Control Zero with zero outbound calls. Policy lives in a local YAML or JSON file on disk (both use the identical schema). Audit writes to a local file (or your own internal log sink). No telemetry, no dashboard calls, no license check-ins.
이 방법이 적합한 경우
- 환경이 단절되어 있고(기밀, 규제 대상 또는 정책상 오프라인)
api.controlzero.ai를 호출할 수 없다면 이 방법이 맞습니다. - 개인 개발자나 소규모 오프라인 워크로드라면 Local 모드의 SDK로 충분합니다.
영어 원문 -- 번역은 기술 검토 대기 중입니다
- For an organization running air-gapped, you want the Self-Hosted deployment: the dashboard, audit store, and signing infrastructure, all inside your boundary.
이 방법을 사용하지 말아야 할 경우
영어 원문 -- 번역은 기술 검토 대기 중입니다
If you have internet egress and just want privacy, you do not need air-gap. Hosted mode already keeps prompts in-memory and only stores redacted audit metadata. Air-gap is for environments where outbound is not allowed, not just not preferred.
5분 설정 (개인 개발자, Local 모드)
pip install controlzero
policy.yaml을 만듭니다:
rules:
- id: block-shell-execute
deny: 'shell:execute'
reason: 'Destructive shell commands are not allowed.'
- id: allow-everything-else
allow: '*'
reason: 'Default-allow for everything else.'
# DLP rules scan tool args for sensitive data. Built-in patterns
# (AWS keys, GitHub tokens, SSNs, etc.) are always active. Add custom
# patterns here.
dlp_rules:
- id: block-internal-codes
pattern: 'PROJ-[A-Z]{3}-\d{6}'
category: custom
action: block
reason: 'Internal project codes must not leave the agent.'
사용 방법:
from controlzero import Client
cz = Client(policy_file="./policy.yaml")
decision = cz.guard(tool="shell", args={"command": "rm -rf /"})
assert not decision.allowed
감사는 ./controlzero.log에 기록됩니다(log_path=로 재정의할 수 있음).