作用域覆盖
将指定的代理或频道置于比基线更严格的规则之下。属于 openclaw policy 参考的一部分。
作用域覆盖¶
当特定代理或频道需要比顶层基线更严格的策略时,使用 scopes.<scopeName>。作用域名称只是一个标签;匹配使用作用域内的选择器。覆盖是叠加的:全局规则仍然运行,作用域规则可以针对同一证据添加自己的发现。
| 选择器 | 支持的配置部分 | 适用场景 |
|---|---|---|
agentIds |
tools、agents.workspace、sandbox、dataHandling.memory、execApprovals |
一个或多个运行时代理需要更严格的规则。 |
channelIds |
ingress.channels |
一个或多个频道需要更严格的入口规则。 |
如果某个 agentIds 条目不在 agents.entries.* 中,OpenClaw 会针对该运行时代理 id 所继承的全局/默认状态来评估作用域规则,而不是跳过它。
{
"tools": {
"exec": {
"allowHosts": ["sandbox", "node"],
},
},
"sandbox": {
"requireMode": ["all", "non-main"],
},
"scopes": {
"release-workspace": {
"agentIds": ["release-agent", "review-agent"],
"agents": {
"workspace": {
"allowedAccess": ["none", "ro"],
},
},
},
"release-lockdown": {
"agentIds": ["release-agent"],
"tools": {
"exec": {
"allowHosts": ["sandbox"],
"allowSecurity": ["deny", "allowlist"],
"requireAsk": ["always"],
},
"denyTools": ["exec", "process", "write", "edit", "apply_patch"],
},
"sandbox": {
"requireMode": ["all"],
"allowBackends": ["docker"],
},
"dataHandling": {
"memory": {
"denySessionTranscriptIndexing": true,
},
},
},
"shell-sandbox": {
"agentIds": ["shell-agent"],
"sandbox": {
"allowBackends": ["openshell"],
"containers": {
"requireReadOnlyMounts": false,
},
},
},
"telegram-ingress": {
"channelIds": ["telegram"],
"ingress": {
"channels": {
"allowDmPolicies": ["pairing"],
"denyOpenGroups": true,
"requireMentionInGroups": true,
},
},
},
},
}
如上述示例所示,只要每个作用域管理不同的字段,同一个代理可以出现在多个作用域中。同一代理的重复作用域字段必须同等或更严格;较弱的重复声明会被拒绝(允许列表是子集,拒绝列表是超集,必需的布尔值固定不变)。
容器状态规则(sandbox.containers.*)仅针对匹配代理的沙箱后端可暴露的证据进行检查。Docker 和 Podman 后端暴露相同的 sandbox.docker.* 容器状态设置。如果某个后端无法观察你为其启用的规则,策略会报告 policy/sandbox-container-posture-unobservable,而不是通过;请将容器规则限定到使用能够暴露这些规则的后端的代理组。
后端授权使用配置的身份。backend: "docker" 要求 allowBackends: ["docker"],而 backend: "podman" 要求 allowBackends: ["podman"]。
顶层 ingress.session.requireDmScope 保持全局;session.dmScope 不是可归因于频道的证据,因此不能通过 channelIds 进行作用域限定。
policy.jsonc 中出现的每个作用域都必须有效且可强制执行。
本页原文 Markdown:在 AtomGit 查看·内容源自开源项目 cl/openclaw