Skip to content

shield

shield

Shield operations and CLI registry — public API surface.

Re-export catalog for the egress-firewall layer. Sources: terok.lib.integrations.sandbox for the high-level shield surface terok-sandbox owns (ShieldManager, ShieldHooks, RecoveryStatus), and terok.lib.integrations.shield for the lower-level CLI registry (COMMANDS, ArgDef, CommandDef, ExecError) that terok's terok shield bridge wires into its own command tree.

shield's CommandDef is aliased to ShieldCommandDef so it doesn't collide with sandbox's CommandDef (which already flows through terok.lib.api for the CLI tree).

__all__ = ['ArgDef', 'DnsTier', 'ExecError', 'RecoveryStatus', 'SHIELD_COMMANDS', 'ShieldCommandDef', 'ShieldManager', 'ShieldSetupError', 'shield_is_container_arg', 'shield_needs_container', 'shield_standalone_only'] module-attribute

__getattr__(name)

Resolve a re-exported name to its source module on first access (PEP 562).

Source code in src/terok/lib/api/shield.py
def __getattr__(name: str) -> object:
    """Resolve a re-exported name to its source module on first access (PEP 562)."""
    try:
        target = _LAZY[name]
    except KeyError:
        raise AttributeError(f"module {__name__!r} has no attribute {name!r}") from None
    module_path, _, source_name = target.partition(":")
    value = getattr(importlib.import_module(module_path), source_name or name)
    globals()[name] = value  # cache so subsequent lookups skip __getattr__
    return value

__dir__()

Expose the lazy names to dir() / autocompletion.

Source code in src/terok/lib/api/shield.py
def __dir__() -> list[str]:
    """Expose the lazy names to ``dir()`` / autocompletion."""
    return sorted({*globals(), *_LAZY})