Skip to content

[Command] AI Policy Creation #69

Description

@gemanor

This command allows developers to create a full policy schema using AI prompts. The command generates a whole Permit terraform template from a natural language prompt and then runs the permit env template apply to apply the policy to the active environment.

Implementation Details

  • The command is permit policy create ai
  • Prompt can be promotable (input) or as an argument (--prompt)
  • After the prompt runs and the TF is generated, the CLI should show a human-readable output of the created policy.
  • A --dry-run flag will print the terraform code to the console instead of creating it in Permit
  • The system prompt and LLM work shouldn't be part of the command or run locally but run on a tiny server endpoint. The endpoint should be placed in the terraform_server template. The name should change to server
  • System prompt should have Permit's TF in its context to minimize errors and wrong syntax/model
  • The system prompt should support at least RBAC and ABAC, with a stretch goal to ReBAC with role derivation

💡 Before participating in the issue or offering a bounty, please make sure you carefully read the contribution guidelines. PRs that do not adhere to the guidelines will be closed with no further notice.

Activity

  1. gemanor commented on Apr 9, 2025

    @gemanor
    CollaboratorAuthor

    Sub-tasks:

    • Setup simple server endpoint that gets policy prompt and runs it in multiple models using the Vercel AI SDK (should use the terraform_server folder in this repository and add endpoint to it)

    • Write the basic system prompt that gets policy prompts and fetches resources, actions, roles, and permissions from it

    • Normalize the system prompt response to be in table representation of the RBAC policy in JSON

    • Add our TF provider docs to the context (can be RAG or just other addition - need to understand how the AI SDK works with such)

    • Add the support in TF generation in the system prompt

    • Add the support of static validation of the TF response to be a valid TF file

    • Add support in the ReBAC entities to the policy table

    • Add support in ReBAC entities to the TF generation

    • Add support in the ABAC entities to the policy table

    • Add support in ABAC entities to the TF generation

    • Add rate limiting to the endpoint

    {
      resources: [{
        name: "test",
        actions: ["read", "write", "delete"]
      }, {
        
      }],
      roles: [{
        name: "test role",
        permissions: [{
          resource: "test",
          actions: ["read"]
        }]
      }]
    }
    
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions