Skip to content

Repository files navigation

AIAC — AI-based Access Control

AIAC is a Rossoctl platform extension that automates access control policy enforcement for AI agents running on Kubernetes. It continuously translates natural-language access-control policy into concrete permission rules on the active Policy Decision Point (OPA), using an identity provider (currently Keycloak) for roles, scopes, and services.

See docs/specs/PRD.md for the full product requirements.

Architecture

AIAC enforces a strict three-layer model:

Layer Component Role
Policy Management AIAC Agent Translates natural-language policy into PDP configuration on every trigger
Policy Decision (PDP) OPA Evaluates LLM-generated Rego rules; decides what a caller may access
Policy Enforcement (PEP) AuthBridge Intercepts traffic; exchanges tokens; carries no policy knowledge

The AIAC Agent subscribes to an event stream (NATS JetStream) and reacts to entity lifecycle events — new services, role changes, policy updates — by consulting a Policy Rules Builder (LangGraph, LLM-backed) and applying the minimal resulting diff through a two-layer policy stack (policy model + Policy Computation Engine). Policy intent lives entirely in the PDP, never in per-pod configuration.

Repository layout

Discover the current concrete layout live rather than relying on this snapshot:

find src/aiac -maxdepth 2 -type d

Getting started

Requirements: Python >= 3.12, uv.

uv venv .venv
source .venv/bin/activate
uv pip install -e ".[test]"

Always use .venv for Python execution, tests, and dependency checks (.venv/bin/python, .venv/bin/pytest).

Running tests

.venv/bin/pytest test/

Bare pytest runs unit tests only — pyproject.toml excludes integration, eval_extended, eval_consistency, eval_robustness, eval_correctness_prb, and eval_correctness_e2e by default. llm is not itself excluded: the live-LLM Policy Rules Builder suite is marked both integration and llm, so it's deselected via not integration, not because llm is excluded. Opt into a marker explicitly to run it, e.g.:

set -a; . .env; set +a          # LLM_BASE_URL / LLM_MODEL / LLM_API_KEY
.venv/bin/pytest test/ -m llm   # live-LLM Policy Rules Builder suite, no cluster needed

Integration tests additionally need a live rossoctl/Kind cluster with the AuthBridge OPA pipeline wired in, plus Keycloak admin creds. Stand it up with k8s/opa-kind-enable.sh — see k8s/opa-kind-runbook.md for prerequisites and manual probe commands.

Deploying to Kubernetes

Build/load the per-service images and apply the manifests under k8s/; full instructions are in k8s/aiac-deployment-guide.md.

To try the end-to-end onboarding flow against a demo agent/tool, see demo/assets/INSTALL.md.

Documentation

Contributing

Pre-commit hooks (formatting, linting via ruff, YAML/JSON checks) are configured in .pre-commit-config.yaml:

pre-commit install

CI runs on every PR — see .github/workflows/.

About

AIAC lab — extracted from cortex/aiac (history preserved)

Resources

Stars

2 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages