profiles
profiles
¶
Allowlist profile loading and composition.
Finds, reads, and merges .txt allowlist profiles from user and
bundled directories. User profiles override bundled ones with the
same name, so site-specific customisation works without forking.
Profiles are unified +/- policy files; a loaded profile yields
its admitted (+) targets. The bundled profiles ship under
resources/examples as samples a caller names explicitly; the curated
egress sets belong to terok, and the OS-package and provider hosts to
terok-executor.
ProfileLoader(*, user_dir, bundled_dir=None)
¶
Loads and composes .txt allowlist profiles.
Searches user profiles first (overriding bundled), then falls back to the bundled profiles shipped with the package.
Create a profile loader.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
user_dir
|
Path
|
User profiles directory (overrides bundled). |
required |
bundled_dir
|
Path | None
|
Bundled profiles directory (auto-detected if None). |
None
|
Source code in src/terok_shield/profiles.py
load_profile(name)
¶
Load a profile by name and return its admitted (+) targets.
User profiles take precedence over bundled profiles.
Raises:
| Type | Description |
|---|---|
UnknownProfileError
|
If no profile carries name; the message names the available profiles. |
Source code in src/terok_shield/profiles.py
compose_profiles(names)
¶
Load and merge multiple profiles, deduplicating entries.
Preserves insertion order (first occurrence wins).
Raises:
| Type | Description |
|---|---|
UnknownProfileError
|
If any name carries no profile. |
Source code in src/terok_shield/profiles.py
UnknownProfileError
¶
Bases: ValueError
A requested name matches no profile, user or bundled.