K

Kranz command protection

Reviews Kranz action execution, runtime lifecycle changes, configuration replacement, and retained evidence deletion.

command.kranz · v1.0.0 · Other extensions

By Community contributorExternal · opt-inCommand coverage
Protection rules
10
Permission checks
10
Mapped commands
10

Overview

What this coverage does

Reviews Kranz action execution, runtime lifecycle changes, configuration replacement, and retained evidence deletion.

Key facts

Catalog ID
command.kranz
Version
v1.0.0
Kind
Command coverage
Category
Other extensions
Protection rules
10
Permission checks
10
Mapped commands
10
Maintainer
Community contributor(community, provenance recorded)
Source commit
0c6483f
Protection model
External · opt-in
External · opt-in

External coverage. It must be enabled through Guard controls; this page does not activate it.

Stated limits

  • Coverage is limited to the reviewed operations and the surrounding Guard policy.
  • A maintainer profile is not a security certification or an official upstream endorsement.

Command mapping

Every command this extension recognizes, with the catalog default floor Guard applies before workspace policy. Search the table, then open an operation for safe variants and the permission ID.

10 operations · 10 reviewed by default These are catalog defaults, not your workspace policy.

10 operations10 reviewed
Default floor

Showing 10 of 10 operations

  • Reviewed Guard intercepts the command for review before it runs.High
    • kranz actions run api/seed --param env=staging
    Kranz action execution
    Default floor
    Reviewed by default. Guard intercepts the command for review before it runs.
    Detector mode
    review
    What it matches
    Runs a configured action, including commands with typed parameters and plan-bound CLI confirmation.
    Documented safe variants
    Command helpVersion informationskip this operation when they are the documented preview or help form.
    Permission ID
    command.kranz.permission.actions-run
  • Reviewed Guard intercepts the command for review before it runs.High
    • kranz down
    Kranz runtime shutdown
    Default floor
    Reviewed by default. Guard intercepts the command for review before it runs.
    Detector mode
    review
    What it matches
    Stops the whole project runtime and removes its retained in-memory state; --force recovers an unresponsive runtime.
    Documented safe variants
    Command helpVersion informationskip this operation when they are the documented preview or help form.
    Permission ID
    command.kranz.permission.down
  • Reviewed Guard intercepts the command for review before it runs.High
    • kranz init --from Procfile --force
    Kranz configuration replacement
    Default floor
    Reviewed by default. Guard intercepts the command for review before it runs.
    Detector mode
    review
    What it matches
    Allows non-interactive replacement of an existing Kranz configuration file.
    Documented safe variants
    Command helpVersion informationskip this operation when they are the documented preview or help form.
    Permission ID
    command.kranz.permission.init-force
  • Reviewed Guard intercepts the command for review before it runs.High
    • kranz logs clear api
    Kranz log buffer deletion
    Default floor
    Reviewed by default. Guard intercepts the command for review before it runs.
    Detector mode
    review
    What it matches
    Discards retained log output for a target, or for every stream when --force is supplied.
    Documented safe variants
    Command helpVersion informationskip this operation when they are the documented preview or help form.
    Permission ID
    command.kranz.permission.logs-clear
  • Reviewed Guard intercepts the command for review before it runs.High
    • kranz reload
    Kranz runtime reload
    Default floor
    Reviewed by default. Guard intercepts the command for review before it runs.
    Detector mode
    review
    What it matches
    Applies changed configuration to the running runtime and can update, start, or stop services.
    Documented safe variants
    Command helpVersion informationskip this operation when they are the documented preview or help form.
    Permission ID
    command.kranz.permission.reload
  • Reviewed Guard intercepts the command for review before it runs.High
    • kranz restart api
    Kranz service restart
    Default floor
    Reviewed by default. Guard intercepts the command for review before it runs.
    Detector mode
    review
    What it matches
    Restarts selected services and may affect dependent services.
    Documented safe variants
    Command helpVersion informationskip this operation when they are the documented preview or help form.
    Permission ID
    command.kranz.permission.restart
  • Reviewed Guard intercepts the command for review before it runs.High
    • kranz start api
    Kranz service start
    Default floor
    Reviewed by default. Guard intercepts the command for review before it runs.
    Detector mode
    review
    What it matches
    Starts selected services and their dependencies in an existing runtime.
    Documented safe variants
    Command helpVersion informationskip this operation when they are the documented preview or help form.
    Permission ID
    command.kranz.permission.start
  • Reviewed Guard intercepts the command for review before it runs.High
    • kranz stop api
    Kranz service stop
    Default floor
    Reviewed by default. Guard intercepts the command for review before it runs.
    Detector mode
    review
    What it matches
    Stops selected services and may affect dependent services.
    Documented safe variants
    Command helpVersion informationskip this operation when they are the documented preview or help form.
    Permission ID
    command.kranz.permission.stop
  • Reviewed Guard intercepts the command for review before it runs.High
    • kranz up -d --start
    Kranz runtime creation
    Default floor
    Reviewed by default. Guard intercepts the command for review before it runs.
    Detector mode
    review
    What it matches
    Creates a runtime and can start selected or all enabled services.
    Documented safe variants
    Command helpVersion informationskip this operation when they are the documented preview or help form.
    Permission ID
    command.kranz.permission.up
  • Reviewed Guard intercepts the command for review before it runs.Medium
    • kranz runs delete api#3 --confirm
    Kranz retained run deletion
    Default floor
    Reviewed by default. Guard intercepts the command for review before it runs.
    Detector mode
    review
    What it matches
    Permanently deletes a completed run and its buffered output after explicit CLI confirmation.
    Documented safe variants
    Command helpVersion informationskip this operation when they are the documented preview or help form.
    Permission ID
    command.kranz.permission.runs-delete

Tool state mapping

No per-tool overrides are declared. Command defaults above resolve through the workspace Guard policy unless a later policy layer changes them.

Runtime identity

Catalog ID
command.kranz
Guard enforcement ID
command.kranz
Source path
contributions/extensions/command.kranz.json
Contribution digest
sha256…d9655e

Action classes

Kranz action execution commandKranz runtime lifecycle commandKranz retained evidence deletion commandKranz configuration replacement command

Technical profile

No independent profile published

This extension has no current independent technical profile. Catalog facts and any legacy launch remain separate and are not presented as profile evidence.

FAQ

Frequently asked questions

Reviews Kranz action execution, runtime lifecycle changes, configuration replacement, and retained evidence deletion. The listing declares 10 rules and 10 permission checks. 10 operations · 10 reviewed by default. Coverage is limited to these reviewed operations and the surrounding Guard policy.

External · opt-in: External coverage. It must be enabled through Guard controls; this page does not activate it. Enabling state is always controlled through Guard policy, never from this directory.

This listing entered the catalog as a community contribution through a public pull request with recorded provenance. Credit is attribution only. A verified publisher profile and the claim flow verify authority separately; neither is an upstream endorsement or a HOL safety certification.

No. Every listing documents source, activation model, maintainer identity, and stated limitations so you can evaluate coverage before enabling it. Review the stated limitations and the exact source tree before relying on any single control.

10 operations · 10 reviewed by default. Examples: kranz actions run api/seed --param env=staging (reviewed by default); kranz down (reviewed by default); kranz init --from Procfile --force (reviewed by default); kranz logs clear api (reviewed by default); kranz reload (reviewed by default); kranz restart api (reviewed by default); kranz start api (reviewed by default); kranz stop api (reviewed by default). The remaining 2 operations are listed in the command mapping table. These are catalog defaults, not your workspace policy.

External coverage. It must be enabled through Guard controls; this page does not activate it. Enablement is managed through your workspace's Guard policy and controls — never from this directory. Open the install guidance for the setup flow, then adjust the command coverage for command.kranz in Guard's policy surface.

The matching action is stopped at Guard's pre-action boundary before it executes, and the decision is recorded with evidence your workspace can review. Exact behavior follows your Guard policy combined with this entry's 10 rules and 10 permission checks.

No. Guard is local-first: interception, decisions, and evidence stay on your machine unless your workspace explicitly configures cloud features. This page is documentation only — it never executes a command or changes protection state.

Guard runs locally alongside the major AI coding agents and MCP-capable harnesses, so this coverage applies wherever Guard intercepts actions. See the supported harness guides at https://hol.org/guard/harnesses for per-tool approval behavior and limitations.

Guard has a free local tier that includes command interception, evidence, and the policy controls this listing documents. Team plans add shared policy, review queues, and audit surfaces. Current plans: https://hol.org/guard/pricing

Open an issue or pull request against the hol-guard repository, where the canonical catalog lives: https://github.com/hashgraph-online/hol-guard Listings are corrected through the same public review process that adds them.

Yes. Community extensions are merged through public pull requests with recorded provenance, and you can claim the publisher page for a contribution you maintain through the Publisher Studio.

The command mapping table is the audit trail for covered commands and catalog default floors. Pair it with the reviewed rule and permission counts, the per-tool state mapping, and the exact source tree linked from View exact source at the reviewed commit. Guard records enforcement decisions with evidence locally, so what ships matches what you reviewed.