Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

feat(core): YAML policy format with transformation functions via `!` tags

Đang mở
#375 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức phù hợp với người mới
35/100
Loại issue
Tính năng
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
python
Lĩnh vực
cli, security

Hướng nghiên cứu

Bắt đầu với luồng xác thực và đánh giá policy JSON hiện có, sau đó lần theo các entry point tirith lint và tirith fmt được đề cập trong issue cùng phần công việc liên quan trong #366. Được xem là hoàn tất khi các policy YAML được đánh giá giống như JSON, các tag được phê duyệt biến đổi các giá trị với lỗi cho từng giá trị, các tag không xác định thất bại một cách rõ ràng, lint/format và các round-trip của builder hoạt động, đồng thời tài liệu bao gồm phần so sánh JSON/YAML.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

enhancement

Policies are JSON-only today. Support YAML as a first-class policy format: the same schema (YAML is
a superset, so every existing policy has a 1:1 YAML twin), plus YAML custom tags — the ! prefix —
as declarative transformation functions inline in the policy:

meta:
  version: v1
  provider: stackguardian/terraform_plan
evaluators:
  - id: task_def_count
    provider_args:
      operation_type: attribute
      terraform_resource_type: aws_ecs_task_definition
      terraform_resource_attribute: !json_decode container_definitions
    condition:
      type: LessThanEqualTo
      value: !length

Design constraints

  • Tags are data, not code: a fixed whitelist of transformation tags (e.g. !length,
    !json_decode, !lower) parsed with a safe YAML loader — an unknown tag is a validation error,
    never an arbitrary constructor. This keeps the format Builder-friendly.
  • The tags are surface syntax over the same transformation pipeline planned for
    condition.transform — one implementation, two spellings. A minimal function set can ship with
    the format; the fuller coercion layer (dates, CIDR, sizes) extends it later.
  • Each transformation step wraps errors per value (a failed decode is a provider error on that
    resource, not a crashed run).
  • tirith lint / tirith fmt (#366) must accept and format YAML policies; validation and the
    interactive builder round-trip both formats.

Acceptance. A .yaml policy evaluates identically to its JSON twin; ! tags apply the shared
transformations with per-value error handling; an unknown tag fails validation with a clear
message; tirith lint/fmt handle YAML; docs show a side-by-side JSON/YAML example.

Ngôn ngữ chính
Python
Star
167
Fork
47
Merge trung bình
1 ngày 21 giờ
Pull request đã merge (30 ngày)
7

Chuẩn bị môi trường

Mở trong Codespaces

Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của StackGuardian/tirith

Tất cả issue của StackGuardian/tirith

Issue tương tự

Thêm issue về Python

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.