Skip to content

ai-gov: http and path policies - #26060

Draft
craig-osterhout wants to merge 1 commit into
docker:mainfrom
craig-osterhout:docs-sbx-l7-policy
Draft

craig-osterhout wants to merge 1 commit into
docker:mainfrom
craig-osterhout:docs-sbx-l7-policy

Conversation

@craig-osterhout

@craig-osterhout craig-osterhout commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

Description

Document HTTP method and path rules for organization policies. An organization
network rule can match specific HTTP methods and URL paths on a destination.

Local policy support shipped in #26162, so this PR covers
the organization side.

Page What changed
organization.md The network rule composer, including the All traffic and HTTP rule types, the accepted destinations, and how the composer's any (*) differs from the CLI's --method ANY. Note that HTTP rules are evaluated per request
network.md Routes to both configuration paths, the composer and the CLI
concepts.md Table comparing what organization and local HTTP rules accept for methods, destinations, and paths
local.md That --path takes one path per rule
monitoring.md How the SUMMARY column counts one decision with entries at both layers
_index.md & _index.md Network bullet no longer limits HTTP rules to local policy

Related issues or tickets

ENGDOCS-3373

Reviews

  • Technical review
  • Editorial review
  • Product review

@netlify

netlify Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for docsdocker ready!

Name Link
🔨 Latest commit c959171
🔍 Latest deploy log https://app.netlify.com/projects/docsdocker/deploys/6ab6ede9bd664c00080580d8
😎 Deploy Preview https://deploy-preview-26060--docsdocker.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

Comment thread content/manuals/ai/sandboxes/governance/access-controls/organization.md Outdated
@craig-osterhout
craig-osterhout marked this pull request as draft September 22, 2026 22:34
craig-osterhout added a commit that referenced this pull request Sep 23, 2026
## Description

Document HTTP method and path rules for local policy. A local network
rule can
match specific HTTP methods and URL paths on a destination. No org/admin
updates in this update.

Supersedes #26060 without ask policies.


| Page | What changed |
| --- | --- |
|
[`concepts.md`](https://deploy-preview-26162--docsdocker.netlify.app/ai/sandboxes/governance/concepts/)
| Method, destination, and path syntax, plus how HTTP and network rules
combine. Nested under Network rules, since an HTTP rule is a network
rule with a method and path. Notes that L7 evaluation needs the sandbox
HTTP proxy, so a connection it can't inspect is blocked rather than
evaluated |
|
[`network.md`](https://deploy-preview-26162--docsdocker.netlify.app/ai/sandboxes/governance/access-controls/network/)
| Introduces the capability and routes to the local CLI |
|
[`local.md`](https://deploy-preview-26162--docsdocker.netlify.app/ai/sandboxes/governance/access-controls/local/)
| `--method` and `--path` how-to, split out from the existing rule
management. Path must be canonical, and each rule takes one path.
Troubleshooting entry for a method or path blocked on an allowed host |
|
[`monitoring.md`](https://deploy-preview-26162--docsdocker.netlify.app/ai/sandboxes/governance/monitor-and-enforce/monitoring/)
| `--type http` listing with the method and path columns, and the `(L4)`
and `(L7)` labels in the summary |
|
[`_index.md`](https://deploy-preview-26162--docsdocker.netlify.app/ai/sandboxes/governance/access-controls/)
&
[`_index.md`](https://deploy-preview-26162--docsdocker.netlify.app/ai/sandboxes/governance/)
| Network bullet notes that a local policy rule can match a host, or an
HTTP method and path |

## Related issues or tickets

ENGDOCS-3373

## Reviews

- [ ] Technical review
- [ ] Editorial review
- [ ] Product review

---------

Signed-off-by: Craig Osterhout <craig.osterhout@docker.com>

@derekmisler derekmisler left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

left 1 issue, 3 questions, and 3 nitpicks inline. the stale "don't combine approval with HTTP rules" guidance in organization.md is the one to check first, it isn't reconciled with network.md/concepts.md and chrispatrick already flagged it as outdated.

Comment thread content/manuals/ai/sandboxes/governance/access-controls/organization.md Outdated
Comment thread content/manuals/ai/sandboxes/governance/concepts.md Outdated
Comment thread content/manuals/ai/sandboxes/governance/access-controls/local.md
Comment thread content/manuals/ai/sandboxes/governance/concepts.md Outdated
Comment thread content/manuals/ai/sandboxes/governance/access-controls/organization.md Outdated
Comment thread content/manuals/ai/sandboxes/governance/access-controls/network.md Outdated
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Craig Osterhout <craig.osterhout@docker.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants