Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
194 changes: 119 additions & 75 deletions docs/deployment/openclaw-sidecar.md
Original file line number Diff line number Diff line change
Expand Up @@ -131,99 +131,143 @@ curl http://localhost:9091/metrics

## Production Deployment on AKS

### Helm Values
> **Note:** The governance sidecar does **not** require PostgreSQL, Redis, or Event Grid. Those are optional components for the full enterprise AgentMesh cluster deployment. The sidecar is self-contained — policies load from a ConfigMap, audit logs go to stdout.

Use the AgentMesh Helm chart with OpenClaw-specific configuration:
### 1. Build the Governance Sidecar Image

**`values-openclaw.yaml`:**
The sidecar image is not published to a public registry. Build from source and push to your own container registry:

```yaml
global:
namespace: openclaw-governed
imageTag: "0.3.0"
tls:
enabled: true
certSecretName: openclaw-tls

# OpenClaw as the primary workload
openclaw:
enabled: true
image:
repository: ghcr.io/openclaw/openclaw
tag: latest
resources:
requests:
cpu: "1.0"
memory: "2Gi"
limits:
cpu: "2.0"
memory: "4Gi"
env:
- name: GOVERNANCE_PROXY
value: http://localhost:8081

# Governance sidecar
sidecar:
enabled: true
image:
repository: agentmesh/governance-sidecar
tag: "0.3.0"
resources:
requests:
cpu: "0.25"
memory: "256Mi"
limits:
cpu: "0.5"
memory: "512Mi"
ports:
proxy: 8081
metrics: 9091
env:
- name: POLICY_DIR
value: /policies
- name: TRUST_SCORE_INITIAL
value: "0.5"
- name: EXECUTION_RING
value: "3"
- name: OTEL_EXPORTER_OTLP_ENDPOINT
value: http://otel-collector:4318

# Policy ConfigMap
policies:
configMapName: openclaw-policies

# Monitoring
monitoring:
enabled: true
serviceMonitor:
enabled: true
interval: 15s
prometheusRule:
enabled: true
```bash
# Build from the agent-os package (bundles policy + trust + audit in one image)
cd packages/agent-os
docker build -t <YOUR_REGISTRY>/agentmesh/governance-sidecar:0.3.0 \
-f Dockerfile.sidecar .
docker push <YOUR_REGISTRY>/agentmesh/governance-sidecar:0.3.0
```

### Deploy
### 2. Create the Policy ConfigMap

```bash
# Create namespace
kubectl create namespace openclaw-governed

# Create policy ConfigMap
# Load your governance policies
kubectl create configmap openclaw-policies \
--from-file=policies/ \
-n openclaw-governed
```

# Deploy with Helm
helm install openclaw-governed \
packages/agent-mesh/charts/agentmesh \
-f values-openclaw.yaml \
-n openclaw-governed
### 3. Deploy OpenClaw + Governance Sidecar

# Verify
Use a standard Kubernetes Deployment with two containers in one pod — the agent and its governance sidecar:

**`openclaw-governed.yaml`:**

```yaml
apiVersion: apps/v1
kind: Deployment
metadata:
name: openclaw-governed
namespace: openclaw-governed
spec:
replicas: 1
selector:
matchLabels:
app: openclaw-governed
template:
metadata:
labels:
app: openclaw-governed
spec:
containers:
# --- The autonomous agent ---
- name: openclaw
image: ghcr.io/openclaw/openclaw:latest
ports:
- containerPort: 8080
env:
- name: GOVERNANCE_PROXY
value: http://localhost:8081

# --- Governance sidecar (AGT) ---
- name: governance-sidecar
image: <YOUR_REGISTRY>/agentmesh/governance-sidecar:0.3.0
ports:
- containerPort: 8081
name: proxy
- containerPort: 9091
name: metrics
env:
- name: POLICY_DIR
value: /policies
- name: LOG_LEVEL
value: INFO
volumeMounts:
- name: policies
mountPath: /policies
readOnly: true
resources:
requests:
cpu: 250m
memory: 256Mi
limits:
cpu: 500m
memory: 512Mi

volumes:
- name: policies
configMap:
name: openclaw-policies
---
apiVersion: v1
kind: Service
metadata:
name: openclaw-governed
namespace: openclaw-governed
spec:
selector:
app: openclaw-governed
ports:
- name: agent
port: 8080
targetPort: 8080
- name: metrics
port: 9091
targetPort: 9091
```

### 4. Deploy and Verify

```bash
kubectl apply -f openclaw-governed.yaml

# Verify both containers are running
kubectl get pods -n openclaw-governed

# Check governance sidecar logs
kubectl logs -l app=openclaw-governed -c governance-sidecar -n openclaw-governed

# Verify sidecar health
kubectl exec -n openclaw-governed deploy/openclaw-governed -c openclaw -- \
curl -s http://localhost:8081/health
```

### What About the AgentMesh Helm Chart?

The [AgentMesh Helm chart](../../packages/agent-mesh/charts/agentmesh/) deploys the **full 4-component enterprise architecture** (API Gateway, Trust Engine, Policy Server, Audit Collector). That is a different deployment model — use it when you need a centralized governance control plane serving multiple agents.

For the **OpenClaw sidecar** pattern (one governance instance per agent pod), use the plain Kubernetes manifests above. This is simpler, requires no external dependencies (no PostgreSQL, no Redis), and works immediately.

### What Secrets Do I Need?

| Secret | Purpose | Required for Sidecar? |
|---|---|---|
| **Ed25519 agent key** | Agent DID identity signing | Only if using DID identity |
| **TLS cert/key** | mTLS between components | No (sidecar uses localhost) |
| **Redis credentials** | Shared session/cache state | No (sidecar is self-contained) |
| **PostgreSQL credentials** | Persistent audit storage | No (sidecar logs to stdout) |

For a basic policy-enforcement sidecar, **no secrets are required** — just the policy ConfigMap.

---

## Governance Policies for OpenClaw
Expand Down
27 changes: 27 additions & 0 deletions examples/policies/production/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
# Production Policy Library
#
# These are production-ready policy sets for common enterprise scenarios.
# Unlike the sample policies in the parent directory, these are designed
# to be deployed as-is or with minimal customization.
#
# Each policy file is self-contained and includes:
# - Action rules (allow/deny/escalate)
# - Content filters (PII/PHI/PCI patterns)
# - Rate limits
# - Human escalation triggers
# - Audit requirements
#
# Choose the policy that matches your risk profile:
#
# | Policy | Risk Profile | Best For |
# |--------|-------------|----------|
# | minimal.yaml | Low | Startups, internal tools, experimentation |
# | enterprise.yaml | Medium | General enterprise, SaaS products |
# | healthcare.yaml | High | HIPAA-regulated, patient data |
# | financial.yaml | High | SOX/PCI-regulated, trading, banking |
# | strict.yaml | Maximum | Defense, critical infrastructure, ITAR |
#
# Usage:
# from agent_os.policies import PolicyEvaluator
# evaluator = PolicyEvaluator()
# evaluator.load_policies("examples/policies/production/enterprise.yaml")
82 changes: 82 additions & 0 deletions examples/policies/production/enterprise.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,82 @@
# Production Policy: Enterprise
# Risk profile: MEDIUM — general enterprise, SaaS products
# Philosophy: Allow common operations, escalate sensitive ones, block dangerous

version: "1.0"
name: enterprise
description: >
Standard enterprise governance. Balanced between productivity and safety.
Escalates sensitive operations to humans, blocks destructive actions.

rules:
# Safe operations — allow
- action: "web_search"
effect: allow
- action: "read_file"
effect: allow
- action: "api_call"
effect: allow
- action: "database_query"
effect: allow
- action: "calculator"
effect: allow
- action: "summarize"
effect: allow

# Sensitive operations — require human approval
- action: "write_file"
effect: escalate
reason: "File writes require human approval"
- action: "send_email"
effect: escalate
reason: "Outbound email requires human review"
- action: "deploy"
effect: escalate
reason: "Deployments require human sign-off"
- action: "create_pr"
effect: escalate
reason: "PR creation requires human review"
- action: "database_write"
effect: escalate
reason: "Database mutations require approval"

# Dangerous operations — deny
- action: "delete_file"
effect: deny
reason: "File deletion is not permitted"
- action: "execute_code"
effect: deny
reason: "Arbitrary code execution is blocked"
- action: "ssh_connect"
effect: deny
reason: "Direct SSH is not permitted"
- action: "drop_table"
effect: deny
reason: "Schema changes are not permitted"

# Default: deny unknown actions
- action: "*"
effect: deny
reason: "Unknown action — default deny"

content_filters:
blocked_patterns:
- '\b\d{3}-\d{2}-\d{4}\b' # SSN
- '\b(?:\d[ -]*?){13,16}\b' # Credit card numbers
- '(?i)password\s*[:=]\s*\S+' # Passwords in output

escalation:
actions_requiring_approval:
- write_file
- send_email
- deploy
- create_pr
- database_write
timeout_seconds: 300
default_on_timeout: deny

settings:
require_human_approval: true
max_tool_calls_per_session: 50
log_level: "audit"
audit_all_decisions: true
Loading
Loading