メインコンテンツまでスキップ
このページは機械翻訳であり、十分なレビューを経ていません。英語の原文が正となります。セキュリティ、プライバシー、データの取り扱い、コンプライアンス、ライセンスに関する記述は、技術レビューが完了するまで英語のまま掲載しています。 英語の原文を読む

完全オフラインで実行する(エアギャップ)

英語の原文 -- 翻訳は技術レビュー待ちです

Surfaces used: Python / Node SDK in Local mode, self-hosted gateway Modes supported: Local Tiers: Free (baseline), Self-Hosted enterprise for full air-gap deployment Status: Local-mode SDK is GA. Self-Hosted air-gap deployment is PRIVATE PREVIEW.

実施すること​

英語の原文 -- 翻訳は技術レビュー待ちです

Run Control Zero with zero outbound calls. Policy lives in a local YAML or JSON file on disk (both use the identical schema). Audit writes to a local file (or your own internal log sink). No telemetry, no dashboard calls, no license check-ins.

このパスが適している理由​

  • 環境が切り離されていて(機密、規制対象、またはポリシー上オフライン)、api.controlzero.ai を呼び出せない場合は、これが適しています。
  • 個人の開発者や小規模なオフラインのワークロードには、Local モードの SDK で十分です。

英語の原文 -- 翻訳は技術レビュー待ちです

  • For an organization running air-gapped, you want the Self-Hosted deployment: the dashboard, audit store, and signing infrastructure, all inside your boundary.

このアプローチを使うべきでない場合​

英語の原文 -- 翻訳は技術レビュー待ちです

注意

If you have internet egress and just want privacy, you do not need air-gap. Hosted mode already keeps prompts in-memory and only stores redacted audit metadata. Air-gap is for environments where outbound is not allowed, not just not preferred.

5分でできるセットアップ(個人の開発者、Local モード)​

pip install controlzero

policy.yaml を作成します。

rules:
- id: block-shell-execute
deny: 'shell:execute'
reason: 'Destructive shell commands are not allowed.'
- id: allow-everything-else
allow: '*'
reason: 'Default-allow for everything else.'

# DLP rules scan tool args for sensitive data. Built-in patterns
# (AWS keys, GitHub tokens, SSNs, etc.) are always active. Add custom
# patterns here.
dlp_rules:
- id: block-internal-codes
pattern: 'PROJ-[A-Z]{3}-\d{6}'
category: custom
action: block
reason: 'Internal project codes must not leave the agent.'

使用します。

from controlzero import Client

cz = Client(policy_file="./policy.yaml")

decision = cz.guard(tool="shell", args={"command": "rm -rf /"})
assert not decision.allowed

監査は ./controlzero.log に書き込まれます(log_path= で上書きできます)。

ネットワーク呼び出しがないことを確認する​

# Block egress as a smoke test
sudo pfctl -e # or your firewall of choice
python your_app.py

英語の原文 -- 翻訳は技術レビュー待ちです

The SDK should continue to work: policy is local, audit is local, nothing reaches out.

セルフマネージドのエアギャップ展開 PRIVATE PREVIEW​

英語の原文 -- 翻訳は技術レビュー待ちです

For an organization running fully air-gapped, Self-Managed gives you the full experience: dashboard, policy signing, and audit store, all inside your boundary, with offline (signed-manifest) license validation and no outbound calls.

Self-Managed is delivered under a PRIVATE PREVIEW license. You receive a signed install package, a private install runbook, and a named support contact. The install steps ship with that package rather than being published here.

パイロットについては、セルフマネージドを参照するか、お問い合わせください。

動作の確認​

  1. 外向きの通信をブロックした状態で、上記の SDK のスモークテストを実行します。ポリシーの評価と監査は継続されなければなりません。

英語の原文 -- 翻訳は技術レビュー待ちです

  1. For Self-Managed: follow the verification steps in the install runbook delivered with your package; all components should report ok with no outbound attempts.
  1. トラフィックが流れるのに合わせて、監査ファイル(Local モード)またはダッシュボード(セルフホスト)が増えることを確認します。

よくある次のステップ​

リファレンス​