본문으로 건너뛰기
이 페이지는 기계 번역이며 충분한 검토를 거치지 않았습니다. 영어 원문이 기준입니다. 보안, 개인정보 보호, 데이터 처리, 규정 준수 및 라이선스에 관한 설명은 기술 검토가 끝날 때까지 영어로 유지됩니다. 영어 원문 보기

완전한 오프라인 실행 (에어갭)

영어 원문 -- 번역은 기술 검토 대기 중입니다

Surfaces used: Python / Node SDK in Local mode, self-hosted gateway Modes supported: Local Tiers: Free (baseline), Self-Hosted enterprise for full air-gap deployment Status: Local-mode SDK is GA. Self-Hosted air-gap deployment is PRIVATE PREVIEW.

수행할 내용​

영어 원문 -- 번역은 기술 검토 대기 중입니다

Run Control Zero with zero outbound calls. Policy lives in a local YAML or JSON file on disk (both use the identical schema). Audit writes to a local file (or your own internal log sink). No telemetry, no dashboard calls, no license check-ins.

이 방법이 적합한 경우​

  • 환경이 단절되어 있고(기밀, 규제 대상 또는 정책상 오프라인) api.controlzero.ai를 호출할 수 없다면 이 방법이 맞습니다.
  • 개인 개발자나 소규모 오프라인 워크로드라면 Local 모드의 SDK로 충분합니다.

영어 원문 -- 번역은 기술 검토 대기 중입니다

  • For an organization running air-gapped, you want the Self-Hosted deployment: the dashboard, audit store, and signing infrastructure, all inside your boundary.

이 방법을 사용하지 말아야 할 경우​

영어 원문 -- 번역은 기술 검토 대기 중입니다

주의

If you have internet egress and just want privacy, you do not need air-gap. Hosted mode already keeps prompts in-memory and only stores redacted audit metadata. Air-gap is for environments where outbound is not allowed, not just not preferred.

5분 설정 (개인 개발자, Local 모드)​

pip install controlzero

policy.yaml을 만듭니다:

rules:
- id: block-shell-execute
deny: 'shell:execute'
reason: 'Destructive shell commands are not allowed.'
- id: allow-everything-else
allow: '*'
reason: 'Default-allow for everything else.'

# DLP rules scan tool args for sensitive data. Built-in patterns
# (AWS keys, GitHub tokens, SSNs, etc.) are always active. Add custom
# patterns here.
dlp_rules:
- id: block-internal-codes
pattern: 'PROJ-[A-Z]{3}-\d{6}'
category: custom
action: block
reason: 'Internal project codes must not leave the agent.'

사용 방법:

from controlzero import Client

cz = Client(policy_file="./policy.yaml")

decision = cz.guard(tool="shell", args={"command": "rm -rf /"})
assert not decision.allowed

감사는 ./controlzero.log에 기록됩니다(log_path=로 재정의할 수 있음).

네트워크 호출이 없는지 확인​

# Block egress as a smoke test
sudo pfctl -e # or your firewall of choice
python your_app.py

영어 원문 -- 번역은 기술 검토 대기 중입니다

The SDK should continue to work: policy is local, audit is local, nothing reaches out.

Self-Managed 에어갭 배포 PRIVATE PREVIEW​

영어 원문 -- 번역은 기술 검토 대기 중입니다

For an organization running fully air-gapped, Self-Managed gives you the full experience: dashboard, policy signing, and audit store, all inside your boundary, with offline (signed-manifest) license validation and no outbound calls.

영어 원문 -- 번역은 기술 검토 대기 중입니다

Self-Managed is delivered under a PRIVATE PREVIEW license. You receive a signed install package, a private install runbook, and a named support contact.

설치 절차는 여기에 게시되지 않고 해당 패키지와 함께 제공됩니다.

파일럿을 진행하려면 Self-Managed를 참고하거나 문의해 주세요.

작동 확인​

  1. 송신을 차단한 상태에서 위의 SDK 스모크 테스트를 실행합니다. 정책 평가와 감사가 계속되어야 합니다.

영어 원문 -- 번역은 기술 검토 대기 중입니다

  1. For Self-Managed: follow the verification steps in the install runbook delivered with your package; all components should report ok with no outbound attempts.
  1. 트래픽이 흐르면서 감사 파일(Local 모드) 또는 대시보드(Self-Hosted)가 늘어나는지 확인합니다.

자주 이어지는 질문​

참고 자료​