RuleStack

Configs

Stacks

Compare

Diff

RuleStack

Configs

Stacks

Compare

Diff

Read API

RuleStack

Configs

Stacks

Compare

Diff

Read API

Configs/AGENTS.md/grpc/grpc

AGENTS.md

src/core/lib/security/authorization/AGENTS.md
AGENTS.md

Quality

48/100

Scores the file, not the repository.

Length

434 words

6 headings · 0 code blocks

Repository

45k

— · pushed 0 days ago

Last changed

3 days ago

First indexed 3 days ago.
grpc/grpc/src/core/lib/security/authorization/AGENTS.mdRawGitHub
1# Authorization
2 
3This directory contains the implementation of the gRPC authorization framework.
4 
5## Overarching Purpose
6 
7The authorization framework provides a mechanism for authorizing incoming requests based on a set of rules defined in an authorization policy. This can be used to control access to gRPC services and methods based on the authenticated user's identity and other request metadata.
8 
9## Core Concepts
10 
11The authorization framework is built around a few key abstractions:
12 
13* **`AuthorizationEngine`**: The `AuthorizationEngine` is the main interface for making authorization decisions. It takes a set of evaluation arguments and returns an authorization decision.
14* **`AuthorizationPolicyProvider`**: The `AuthorizationPolicyProvider` is responsible for providing the authorization policy to the `AuthorizationEngine`. This allows the authorization policy to be loaded from a variety of sources, such as a local file or a remote server.
15* **`EvaluateArgs`**: The `EvaluateArgs` struct contains the information that is needed to make an authorization decision. This includes the request headers, the peer identity, and other information about the request.
16 
17## Implementations
18 
19The authorization framework includes two main implementations of the `AuthorizationEngine`:
20 
21* **`GrpcAuthorizationEngine`**: This implementation is based on the [Envoy RBAC filter](https://www.envoyproxy.io/docs/envoy/latest/configuration/http/http_filters/rbac_filter). It uses a set of RBAC policies to make authorization decisions.
22* **`CelAuthorizationEngine`**: This implementation is based on the [Common Expression Language (CEL)](https://cel-spec.dev/). It uses a set of CEL expressions to make authorization decisions. This implementation is still experimental.
23 
24## Files
25 
26* **`authorization_engine.h`**: Defines the `AuthorizationEngine` interface.
27* **`grpc_authorization_engine.h`, `grpc_authorization_engine.cc`**: These files define the `GrpcAuthorizationEngine` class.
28* **`cel_authorization_engine.h`, `cel_authorization_engine.cc`**: These files define the `CelAuthorizationEngine` class.
29* **`grpc_server_authz_filter.h`, `grpc_server_authz_filter.cc`**: These files define the `GrpcServerAuthzFilter` class, which is a server-side filter that uses an `AuthorizationEngine` to authorize incoming requests.
30* **`rbac_policy.h`, `rbac_policy.cc`**: These files define the `Rbac` struct, which represents an RBAC policy.
31* **`authorization_policy_provider.h`**: Defines the `AuthorizationPolicyProvider` interface.
32* **`grpc_authorization_policy_provider.h`, `grpc_authorization_policy_provider.cc`**: These files define a concrete implementation of the `AuthorizationPolicyProvider` interface that loads the authorization policy from a static string.
33* **`audit_logging.h`, `audit_logging.cc`**: These files define the interfaces for audit logging. Audit logging can be used to record information about authorization decisions.
34 
35## Notes
36 
37* The authorization framework is a powerful tool for securing gRPC services. It can be used to implement a wide range of authorization policies, from simple access control lists to complex, attribute-based policies.
38* The framework is designed to be used in conjunction with xDS, which can be used to dynamically update the authorization policy at runtime.
39* The CEL-based authorization engine is still experimental and is not yet recommended for production use.
40* Audit logging can be used to record information about authorization decisions. This can be useful for security auditing and for debugging authorization policies.
41 

Sections

  • Authorization
  • Overarching Purpose
  • Core Concepts
  • Implementations
  • Files
  • Notes

What it covers

security

Stack — with the evidence

swift

(1.00)

csharp

(1.00)

cpp

(1.00)

python

(0.60)

ruby

(0.60)

php

(0.60)

dotnet

(0.60)

ruff

(0.60)

github-actions

(0.60)

Format

AGENTS.md

A plain-markdown README for coding agents, deliberately unopinionated: no frontmatter, no globs, no vendor keys. That minimalism is why it became the one file a dozen different agents will read, and why it carries the least per-file targeting power of any format here.

What the corpus says about it

Repository

Owner
grpc
Language
—
License
—
Archived
no

All configs in this repo

Also in grpc/grpc

Diff this repo’s formats

One repository carrying more than one format is the comparison this product exists for: does anyone actually write different content in each file, or is one a copy of the other?

The other instruction files in this repository
RepositoryFormatStackCoversScoreChanged
grpc/grpcsrc/core/ext/filters/census/AGENTS.md · 45kAGENTS.mdswiftcsharp+7no sections25/1003 days ago
grpc/grpcsrc/core/ext/filters/gcp_authentication/AGENTS.md · 45kAGENTS.mdswiftcsharp+7security44/1003 days ago
grpc/grpcsrc/core/ext/filters/http/AGENTS.md · 45kAGENTS.mdswiftcsharp+7no sections44/1003 days ago
grpc/grpcsrc/core/ext/filters/stateful_session/AGENTS.md · 45kAGENTS.mdswiftcsharp+7no sections44/1003 days ago
grpc/grpcsrc/core/ext/transport/chaotic_good/AGENTS.md · 45kAGENTS.mdswiftcsharp+7no sections48/1003 days ago
grpc/grpcsrc/core/ext/transport/inproc/AGENTS.md · 45kAGENTS.mdswiftcsharp+7no sections44/1003 days ago
grpc/grpcsrc/core/filter/AGENTS.md · 45kAGENTS.mdswiftcsharp+7no sections44/1003 days ago
grpc/grpcsrc/core/handshaker/AGENTS.md · 45kAGENTS.mdswiftcsharp+7no sections39/1003 days ago
grpc/grpcsrc/core/server/AGENTS.md · 45kAGENTS.mdswiftcsharp+7no sections44/1003 days ago
grpc/grpcsrc/core/service_config/AGENTS.md · 45kAGENTS.mdswiftcsharp+7no sections44/1003 days ago
grpc/grpcsrc/core/telemetry/AGENTS.md · 45kAGENTS.mdswiftcsharp+7no sections39/1003 days ago
grpc/grpcsrc/core/transport/AGENTS.md · 45kAGENTS.mdswiftcsharp+7no sections39/1003 days ago
grpc/grpcsrc/core/credentials/transport/AGENTS.md · 45kAGENTS.mdswiftcsharp+7security39/1003 days ago
grpc/grpcsrc/core/ext/filters/backend_metrics/AGENTS.md · 45kAGENTS.mdswiftcsharp+7no sections44/1003 days ago
grpc/grpcsrc/core/credentials/AGENTS.md · 45kAGENTS.mdswiftcsharp+7security39/1003 days ago
grpc/grpcsrc/core/tsi/AGENTS.md · 45kAGENTS.mdswiftcsharp+7security39/1003 days ago
grpc/grpcsrc/core/tsi/alts/AGENTS.md · 45kAGENTS.mdswiftcsharp+7no sections39/1003 days ago
grpc/grpcsrc/core/credentials/call/AGENTS.md · 45kAGENTS.mdswiftcsharp+7security39/1003 days ago
grpc/grpcsrc/core/ext/transport/chttp2/AGENTS.md · 45kAGENTS.mdswiftcsharp+7testarchdependencies48/1003 days ago
grpc/grpcAGENTS.md · 45kAGENTS.mdswiftcsharp+7styledependenciesdo-not54/1003 days ago
Diff against src/core/ext/filters/census/AGENTS.md Diff against src/core/ext/filters/gcp_authentication/AGENTS.md Diff against src/core/ext/filters/http/AGENTS.md Diff against src/core/ext/filters/stateful_session/AGENTS.md Diff against src/core/ext/transport/chaotic_good/AGENTS.md Diff against src/core/ext/transport/inproc/AGENTS.md Diff against src/core/filter/AGENTS.md Diff against src/core/handshaker/AGENTS.md Diff against src/core/server/AGENTS.md Diff against src/core/service_config/AGENTS.md Diff against src/core/telemetry/AGENTS.md Diff against src/core/transport/AGENTS.md Diff against src/core/credentials/transport/AGENTS.md Diff against src/core/ext/filters/backend_metrics/AGENTS.md Diff against src/core/credentials/AGENTS.md Diff against src/core/tsi/AGENTS.md Diff against src/core/tsi/alts/AGENTS.md Diff against src/core/credentials/call/AGENTS.md Diff against src/core/ext/transport/chttp2/AGENTS.md Diff against AGENTS.md

Similar configs

Same format, overlapping stack, ranked by quality.

Same format, overlapping stack, ranked by quality
RepositoryFormatStackCoversScoreChanged
vllm-project/vllmAGENTS.md · 88kAGENTS.mdpythonpytorch+3setuptestlint-formatstyle+5100/1003 days ago
duckduckgo/content-scope-scriptsspecial-pages/AGENTS.md · 70AGENTS.mdtypescriptjavascript+5buildteststylearch+3100/1003 days ago
react/react-nativepackages/react-native-compatibility-check/AGENTS.md · 126kAGENTS.mdreactreact-native+11testlint-formatstylearch+499/1003 days ago
netdata/netdatasrc/go/plugin/ibm.d/AGENTS.md · 80kAGENTS.mddockerinfrastructure+7buildtestlint-formatarch+399/1003 days ago
dragonflydb/dragonflyAGENTS.md · 31kAGENTS.mdcppredis+6setupbuildtestlint-format+1096/1002 days ago
dotnet/aspnetcoresrc/Components/AGENTS.md · 38kAGENTS.mdcsharpdotnet+5buildteststylearch+396/1003 days ago
duckdb/duckdbAGENTS.md · 40kAGENTS.mdcppswift+1buildtestlint-formatstyle+896/100today
steipete/CodexBarAGENTS.md · 20kAGENTS.mdswiftgithub-actionsbuildteststylearch+493/1003 days ago
RuleStack

Built by

Kynth Studio

Directory

Configs
Stacks
Compare formats
Diff two configs
Best AGENTS.md examples

Formats

AGENTS.md
CLAUDE.md
Cursor rules
Copilot instructions

Reference

Read API
Corpus health
Privacy Policy
Terms

RuleStack

RuleStack

Built by

Kynth Studio

Directory

Configs
Stacks
Compare formats
Diff two configs
Best AGENTS.md examples

Formats

AGENTS.md
CLAUDE.md
Cursor rules
Copilot instructions

Reference

Read API
Corpus health
Privacy Policy
Terms

RuleStack

RuleStack

Built by

Kynth Studio

Directory

Configs
Stacks
Compare formats
Diff two configs
Best AGENTS.md examples

Formats

AGENTS.md
CLAUDE.md
Cursor rules
Copilot instructions

Reference

Read API
Corpus health
Privacy Policy
Terms

RuleStack