跳转至

编写

启用插件并编写策略工件。属于 openclaw policy 参考文档的一部分。

快速开始

openclaw plugins enable policy

即使缺少 policy.jsonc,插件仍保持启用状态,因此 doctor 可以报告缺失的工件,而不是静默跳过检查。

手动编写 policy.jsonc;它不会从当前设置生成。每个顶层部分都是一个规则命名空间:只有当其下存在具体规则时,检查才会运行(不支持的部分或键将作为 policy/policy-jsonc-invalid 失败,而不是被静默忽略)。以下是最小示例,涵盖所有受支持的部分:

jsonc validate=false { "channels": { "denyRules": [ { "id": "no-telegram", "when": { "provider": "telegram" }, "reason": "Telegram is not approved for this workspace.", }, ], }, "mcp": { "servers": { "allow": ["docs"], "deny": ["untrusted"], }, }, "models": { "providers": { "allow": ["openai", "anthropic"], "deny": ["openrouter"], }, }, "network": { "privateNetwork": { "allow": false, }, }, "routing": { "requireBindings": true, "requireConfiguredChannels": true, "probes": [ { "id": "family-dm", "route": { "channel": "imessage", "peer": { "kind": "direct", "id": "+15555550123" }, }, "expect": { "agentId": "family", "matchedBy": ["binding.peer"], }, }, ], }, "ingress": { "session": { "requireDmScope": "per-channel-peer", }, "channels": { "allowDmPolicies": ["pairing", "allowlist", "disabled"], "denyOpenGroups": true, "requireMentionInGroups": true, }, }, "gateway": { "exposure": { "allowNonLoopbackBind": false, "allowTailscaleFunnel": false, }, "auth": { "requireAuth": true, "requireExplicitRateLimit": true, }, "controlUi": { "allowInsecure": false, }, "remote": { "allow": false, }, "http": { "denyEndpoints": ["chatCompletions", "responses"], "requireUrlAllowlists": true, }, "nodes": { "denyCommands": ["system.run"], }, }, "agents": { "workspace": { "allowedAccess": ["none", "ro"], "denyTools": ["exec", "process", "write", "edit", "apply_patch"], }, }, "dataHandling": { "sensitiveLogging": { "requireRedaction": true, }, "telemetry": { "denyContentCapture": true, }, "retention": { "requireSessionMaintenance": true, }, "memory": { "denySessionTranscriptIndexing": true, }, }, "secrets": { "requireManagedProviders": true, "denySources": ["exec"], "allowInsecureProviders": false, }, "auth": { "profiles": { "requireMetadata": ["provider", "mode"], "allowModes": ["api_key", "token"], }, }, "execApprovals": { "requireFile": true, "defaults": { "allowSecurity": ["deny"] }, "agents": { "allowSecurity": ["deny", "allowlist"], "allowAutoAllowSkills": false, "allowlist": { "expected": ["deploy", "status"] }, }, }, "tools": { "requireMetadata": ["risk", "sensitivity", "owner"], "profiles": { "allow": ["messaging", "minimal"], }, "fs": { "requireWorkspaceOnly": true, }, "exec": { "allowSecurity": ["deny", "allowlist"], "requireAsk": ["always"], "allowHosts": ["sandbox"], }, "elevated": { "allow": false, }, "denyTools": ["group:runtime", "group:fs"], }, }

以下是从规则表中不易看出的横切注意事项:

  • 在禁止非环回绑定的同时省略 gateway.bind,意味着你接受运行时默认值;如需严格符合,请设置 gateway.bind: "loopback"。
  • 对于只读 agent,请在适用的 defaults/agent 上将沙箱 mode 设置为 all 或 non-main,并将 workspaceAccess 设置为 none 或 ro。缺失或为 off 的沙箱模式不满足只读策略。
  • agents.workspace.denyTools 接受 exec、process、write、edit、apply_patch。配置中的工具拒绝组 group:fs(文件变更)和 group:runtime(shell/进程)可满足等效的防护姿态。
  • 仅当存在 execApprovals 规则时,exec-approvals 检查才会读取实时的 SQLite 审批文档;缺失或无效的工件属于不可观测的证据,而非合成式通过。
  • secret 和 auth-profile 证据仅记录 provider/source 的防护姿态及 SecretRef 元数据,绝不记录原始值。策略不会读取或证明诸如 openclaw-agent.sqlite 之类的逐 agent 凭据存储。
  • data-handling 证据是配置层面的防护姿态(遥测捕获开关、会话维护模式、转录索引设置),外加始终开启的日志脱敏不变量。它不会检查日志、遥测导出、转录或内存文件,且通过结果并不能证明其中不存在个人数据或机密信息。
  • 路由探测复用 OpenClaw 的运行时绑定解析器。路由证据仅记录探测 id、解析出的 agent、匹配类型以及经过编辑的绑定元数据。它从不记录 peer、account、guild、team 或 role 标识符。添加 routing 部分会刻意改变策略和证明哈希;没有 routing 的策略会保持其现有的证据形态。

本页原文 Markdown:在 AtomGit 查看·内容源自开源项目 cl/openclaw