Skip to content

Flag and block invasive assessments #244

Description

@eddie-knight

User story

As a highly regulated user running compliance validation against live infrastructure, I would like a way to guarantee that Privateer and its plugins cannot make changes to any resources — so that a misconfigured or misbehaving plugin can never mutate infrastructure it was only supposed to observe.

Context

The invasive flag exists, but it's a config option — which means it can be misconfigured, overridden, or simply omitted. In a regulated environment, a compliance tool modifying live infrastructure would itself be an audit finding. A config flag doesn't provide the hard guarantee needed to satisfy that concern.

Potential Solution

These are notes from Claude, intended only to kickoff brainstorming:

  • A runtime flag (e.g. --read-only) that disables all invasive capabilities at the harness level, regardless of plugin or config
  • When active, any plugin attempting a write operation should fail with a clear error — not silently skip
  • Ideally enforced in the SDK so plugin authors can't accidentally bypass it

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions