mirror of
https://github.com/meta-llama/llama-stack.git
synced 2025-06-27 18:50:41 +00:00
This allows a set of rules to be defined for determining access to resources. The rules are (loosely) based on the cedar policy format. A rule defines a list of action either to permit or to forbid. It may specify a principal or a resource that must match for the rule to take effect. It may also specify a condition, either a 'when' or an 'unless', with additional constraints as to where the rule applies. A list of rules is held for each type to be protected and tried in order to find a match. If a match is found, the request is permitted or forbidden depening on the type of rule. If no match is found, the request is denied. If no rules are specified for a given type, a rule that allows any action as long as the resource attributes match the user attributes is added (i.e. the previous behaviour is the default. Some examples in yaml: ``` model: - permit: principal: user-1 actions: [create, read, delete] comment: user-1 has full access to all models - permit: principal: user-2 actions: [read] resource: model-1 comment: user-2 has read access to model-1 only - permit: actions: [read] when: user_in: resource.namespaces comment: any user has read access to models with matching attributes vector_db: - forbid: actions: [create, read, delete] unless: user_in: role::admin comment: only user with admin role can use vector_db resources ``` --------- Signed-off-by: Gordon Sim <gsim@redhat.com>
116 lines
4 KiB
Python
116 lines
4 KiB
Python
# Copyright (c) Meta Platforms, Inc. and affiliates.
|
|
# All rights reserved.
|
|
#
|
|
# This source code is licensed under the terms described in the LICENSE file in
|
|
# the root directory of this source tree.
|
|
|
|
|
|
import pytest
|
|
|
|
from llama_stack.apis.models import ModelType
|
|
from llama_stack.distribution.datatypes import ModelWithOwner, User
|
|
from llama_stack.distribution.store.registry import CachedDiskDistributionRegistry
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_registry_cache_with_acl(cached_disk_dist_registry):
|
|
model = ModelWithOwner(
|
|
identifier="model-acl",
|
|
provider_id="test-provider",
|
|
provider_resource_id="model-acl-resource",
|
|
model_type=ModelType.llm,
|
|
owner=User("testuser", {"roles": ["admin"], "teams": ["ai-team"]}),
|
|
)
|
|
|
|
success = await cached_disk_dist_registry.register(model)
|
|
assert success
|
|
|
|
cached_model = cached_disk_dist_registry.get_cached("model", "model-acl")
|
|
assert cached_model is not None
|
|
assert cached_model.identifier == "model-acl"
|
|
assert cached_model.owner.principal == "testuser"
|
|
assert cached_model.owner.attributes["roles"] == ["admin"]
|
|
assert cached_model.owner.attributes["teams"] == ["ai-team"]
|
|
|
|
fetched_model = await cached_disk_dist_registry.get("model", "model-acl")
|
|
assert fetched_model is not None
|
|
assert fetched_model.identifier == "model-acl"
|
|
assert fetched_model.owner.attributes["roles"] == ["admin"]
|
|
|
|
new_registry = CachedDiskDistributionRegistry(cached_disk_dist_registry.kvstore)
|
|
await new_registry.initialize()
|
|
|
|
new_model = await new_registry.get("model", "model-acl")
|
|
assert new_model is not None
|
|
assert new_model.identifier == "model-acl"
|
|
assert new_model.owner.principal == "testuser"
|
|
assert new_model.owner.attributes["roles"] == ["admin"]
|
|
assert new_model.owner.attributes["teams"] == ["ai-team"]
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_registry_empty_acl(cached_disk_dist_registry):
|
|
model = ModelWithOwner(
|
|
identifier="model-empty-acl",
|
|
provider_id="test-provider",
|
|
provider_resource_id="model-resource",
|
|
model_type=ModelType.llm,
|
|
owner=User("testuser", None),
|
|
)
|
|
|
|
await cached_disk_dist_registry.register(model)
|
|
|
|
cached_model = cached_disk_dist_registry.get_cached("model", "model-empty-acl")
|
|
assert cached_model is not None
|
|
assert cached_model.owner is not None
|
|
assert cached_model.owner.attributes is None
|
|
|
|
all_models = await cached_disk_dist_registry.get_all()
|
|
assert len(all_models) == 1
|
|
|
|
model = ModelWithOwner(
|
|
identifier="model-no-acl",
|
|
provider_id="test-provider",
|
|
provider_resource_id="model-resource-2",
|
|
model_type=ModelType.llm,
|
|
)
|
|
|
|
await cached_disk_dist_registry.register(model)
|
|
|
|
cached_model = cached_disk_dist_registry.get_cached("model", "model-no-acl")
|
|
assert cached_model is not None
|
|
assert cached_model.owner is None
|
|
|
|
all_models = await cached_disk_dist_registry.get_all()
|
|
assert len(all_models) == 2
|
|
|
|
|
|
@pytest.mark.asyncio
|
|
async def test_registry_serialization(cached_disk_dist_registry):
|
|
attributes = {
|
|
"roles": ["admin", "researcher"],
|
|
"teams": ["ai-team", "ml-team"],
|
|
"projects": ["project-a", "project-b"],
|
|
"namespaces": ["prod", "staging"],
|
|
}
|
|
|
|
model = ModelWithOwner(
|
|
identifier="model-serialize",
|
|
provider_id="test-provider",
|
|
provider_resource_id="model-resource",
|
|
model_type=ModelType.llm,
|
|
owner=User("bob", attributes),
|
|
)
|
|
|
|
await cached_disk_dist_registry.register(model)
|
|
|
|
new_registry = CachedDiskDistributionRegistry(cached_disk_dist_registry.kvstore)
|
|
await new_registry.initialize()
|
|
|
|
loaded_model = await new_registry.get("model", "model-serialize")
|
|
assert loaded_model is not None
|
|
|
|
assert loaded_model.owner.attributes["roles"] == ["admin", "researcher"]
|
|
assert loaded_model.owner.attributes["teams"] == ["ai-team", "ml-team"]
|
|
assert loaded_model.owner.attributes["projects"] == ["project-a", "project-b"]
|
|
assert loaded_model.owner.attributes["namespaces"] == ["prod", "staging"]
|