Skip to content

docs: add optional HOL Guard boundary to infra-clickhouse - #46

Open
kantorcodes wants to merge 1 commit into
ClickHouse:mainfrom
kantorcodes:hol-guard-runtime-safety
Open

docs: add optional HOL Guard boundary to infra-clickhouse#46
kantorcodes wants to merge 1 commit into
ClickHouse:mainfrom
kantorcodes:hol-guard-runtime-safety

Conversation

@kantorcodes

Copy link
Copy Markdown

Summary

  • adds an opt-in HOL Guard setup to infra-clickhouse for supported local coding-agent harnesses before state-changing clickhousectl workflows
  • keeps ClickHouse authentication, RBAC, quotas, and audit controls authoritative; it explicitly does not claim Guard protects ClickHouse itself or the remote Cloud API
  • bumps the skill and metadata version together to 0.3.1

Why

infra-clickhouse already guides agents through workflows that can create or mutate local and cloud resources. This gives users who want it a separate local agent-runtime boundary before tool execution without replacing ClickHouse-native controls.

Validation

  • version is aligned between SKILL.md and metadata.json
  • no ClickHouse command behavior is changed
  • runtime execution is not claimed; this is a docs-only integration

@kantorcodes
kantorcodes requested a review from doneyli as a code owner August 28, 2026 11:41
@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants