ai-gov: http and path policies - #26060
Draft
craig-osterhout wants to merge 1 commit into
Draft
craig-osterhout wants to merge 1 commit into
craig-osterhout wants to merge 1 commit into
Conversation
✅ Deploy Preview for docsdocker ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
This was referenced Sep 10, 2026
craig-osterhout
requested review from
chrispatrick,
derekmisler and
smnovick
September 10, 2026 18:30
craig-osterhout
marked this pull request as ready for review
September 21, 2026 18:54
3 tasks
craig-osterhout
marked this pull request as draft
September 22, 2026 22:34
craig-osterhout
added a commit
that referenced
this pull request
Sep 23, 2026
## Description Document HTTP method and path rules for local policy. A local network rule can match specific HTTP methods and URL paths on a destination. No org/admin updates in this update. Supersedes #26060 without ask policies. | Page | What changed | | --- | --- | | [`concepts.md`](https://deploy-preview-26162--docsdocker.netlify.app/ai/sandboxes/governance/concepts/) | Method, destination, and path syntax, plus how HTTP and network rules combine. Nested under Network rules, since an HTTP rule is a network rule with a method and path. Notes that L7 evaluation needs the sandbox HTTP proxy, so a connection it can't inspect is blocked rather than evaluated | | [`network.md`](https://deploy-preview-26162--docsdocker.netlify.app/ai/sandboxes/governance/access-controls/network/) | Introduces the capability and routes to the local CLI | | [`local.md`](https://deploy-preview-26162--docsdocker.netlify.app/ai/sandboxes/governance/access-controls/local/) | `--method` and `--path` how-to, split out from the existing rule management. Path must be canonical, and each rule takes one path. Troubleshooting entry for a method or path blocked on an allowed host | | [`monitoring.md`](https://deploy-preview-26162--docsdocker.netlify.app/ai/sandboxes/governance/monitor-and-enforce/monitoring/) | `--type http` listing with the method and path columns, and the `(L4)` and `(L7)` labels in the summary | | [`_index.md`](https://deploy-preview-26162--docsdocker.netlify.app/ai/sandboxes/governance/access-controls/) & [`_index.md`](https://deploy-preview-26162--docsdocker.netlify.app/ai/sandboxes/governance/) | Network bullet notes that a local policy rule can match a host, or an HTTP method and path | ## Related issues or tickets ENGDOCS-3373 ## Reviews - [ ] Technical review - [ ] Editorial review - [ ] Product review --------- Signed-off-by: Craig Osterhout <craig.osterhout@docker.com>
derekmisler
reviewed
Sep 25, 2026
derekmisler
left a comment
Contributor
There was a problem hiding this comment.
left 1 issue, 3 questions, and 3 nitpicks inline. the stale "don't combine approval with HTTP rules" guidance in organization.md is the one to check first, it isn't reconciled with network.md/concepts.md and chrispatrick already flagged it as outdated.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Signed-off-by: Craig Osterhout <craig.osterhout@docker.com>
craig-osterhout
force-pushed
the
docs-sbx-l7-policy
branch
from
September 25, 2026 21:55
f8def90 to
c959171
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Document HTTP method and path rules for organization policies. An organization
network rule can match specific HTTP methods and URL paths on a destination.
Local policy support shipped in #26162, so this PR covers
the organization side.
organization.md--method ANY. Note that HTTP rules are evaluated per requestnetwork.mdconcepts.mdlocal.md--pathtakes one path per rulemonitoring.mdSUMMARYcolumn counts one decision with entries at both layers_index.md&_index.mdRelated issues or tickets
ENGDOCS-3373
Reviews