完全オフラインで実行する(エアギャップ)
英語の原文 -- 翻訳は技術レビュー待ちです
Surfaces used: Python / Node SDK in Local mode, self-hosted gateway Modes supported: Local Tiers: Free (baseline), Self-Hosted enterprise for full air-gap deployment Status: Local-mode SDK is GA. Self-Hosted air-gap deployment is PRIVATE PREVIEW.
実施すること
英語の原文 -- 翻訳は技術レビュー待ちです
Run Control Zero with zero outbound calls. Policy lives in a local YAML or JSON file on disk (both use the identical schema). Audit writes to a local file (or your own internal log sink). No telemetry, no dashboard calls, no license check-ins.
こ のパスが適している理由
- 環境が切り離されていて(機密、規制対象、またはポリシー上オフライン)、
api.controlzero.aiを呼び出せない場合は、これが適しています。 - 個人の開発者や小規模なオフラインのワークロードには、Local モードの SDK で十分です。
英語の原文 -- 翻訳は技術レビュー待ちです
- For an organization running air-gapped, you want the Self-Hosted deployment: the dashboard, audit store, and signing infrastructure, all inside your boundary.
このアプローチを使うべきでない場合
英語の原文 -- 翻訳は技術レビュー待ちです
If you have internet egress and just want privacy, you do not need air-gap. Hosted mode already keeps prompts in-memory and only stores redacted audit metadata. Air-gap is for environments where outbound is not allowed, not just not preferred.
5分でできるセットアップ(個人の開発者、Local モード)
pip install controlzero
policy.yaml を作成します。
rules:
- id: block-shell-execute
deny: 'shell:execute'
reason: 'Destructive shell commands are not allowed.'
- id: allow-everything-else
allow: '*'
reason: 'Default-allow for everything else.'
# DLP rules scan tool args for sensitive data. Built-in patterns
# (AWS keys, GitHub tokens, SSNs, etc.) are always active. Add custom
# patterns here.
dlp_rules:
- id: block-internal-codes
pattern: 'PROJ-[A-Z]{3}-\d{6}'
category: custom
action: block
reason: 'Internal project codes must not leave the agent.'
使用します。
from controlzero import Client
cz = Client(policy_file="./policy.yaml")
decision = cz.guard(tool="shell", args={"command": "rm -rf /"})
assert not decision.allowed
監査は ./controlzero.log に書き込まれます(log_path= で上書きできます)。
ネットワーク呼び出しがないことを確認する
# Block egress as a smoke test
sudo pfctl -e # or your firewall of choice
python your_app.py
英語の原文 -- 翻訳は技術レビュー待ちです
The SDK should continue to work: policy is local, audit is local, nothing reaches out.
セルフマネージドのエアギャップ展開 PRIVATE PREVIEW
英語の原文 -- 翻訳は技術レビュー待ちです
For an organization running fully air-gapped, Self-Managed gives you the full experience: dashboard, policy signing, and audit store, all inside your boundary, with offline (signed-manifest) license validation and no outbound calls.
Self-Managed is delivered under a PRIVATE PREVIEW license. You receive a signed install package, a private install runbook, and a named support contact. The install steps ship with that package rather than being published here.
パイロットについては、セルフマネージドを参照するか、お問い合わせください。
動作の確認
- 外向きの通信をブロックした状態で、上記の SDK のスモークテストを実行します。ポリシーの評価と監査は継続されなければなりません。
英語の原文 -- 翻訳は技術レビュー待ちです
- For Self-Managed: follow the verification steps in the install runbook delivered with your package; all components should report
okwith no outbound attempts.
- トラフィックが流れるのに合わせて、監査ファイル(Local モード)またはダッシュボード(セルフホスト)が増えることを確認します。
よくある次のステップ
- 「Python の完全なガイドが欲しい」 -> Python AI アプリを統制する
- 「Node でも同じオフラインのパターンが欲しい」 -> Node.js AI アプリを統制する
- 「セルフホストをパイロットしたい」 -> セルフホスト
- 「Local モードは実際にはどう動く?」 -> 完全オフラインで実行する(Local モード)
リファレンス
- 適用面のページ: Python SDK、Node.js SDK、Local 専用モード、セルフホスト
- コンセプト: ポリシー
- API: API リファレンス