Rebrand the project from Fence to Greywall, the sandboxing layer of the GreyHaven platform. This updates: - Go module path to gitea.app.monadical.io/monadical/greywall - Binary name, CLI help text, and all usage examples - Config paths (~/.config/greywall/greywall.json), env vars (GREYWALL_*) - Log prefixes ([greywall:*]), temp file prefixes (greywall-*) - All documentation, scripts, CI workflows, and example files - README rewritten with GreyHaven branding and Fence attribution Directory/file renames: cmd/fence → cmd/greywall, pkg/fence → pkg/greywall, docs/why-fence.md → docs/why-greywall.md, example JSON files, and banner.
37 lines
598 B
Markdown
37 lines
598 B
Markdown
# Recipe: `pip` / `poetry`
|
|
|
|
Goal: allow Python dependency fetching while keeping egress minimal.
|
|
|
|
## Start restrictive (PyPI)
|
|
|
|
```json
|
|
{
|
|
"network": {
|
|
"allowedDomains": ["pypi.org", "files.pythonhosted.org"]
|
|
},
|
|
"filesystem": {
|
|
"allowWrite": [".", "/tmp"]
|
|
}
|
|
}
|
|
```
|
|
|
|
Run:
|
|
|
|
```bash
|
|
greywall --settings ./greywall.json pip install -r requirements.txt
|
|
```
|
|
|
|
For Poetry:
|
|
|
|
```bash
|
|
greywall --settings ./greywall.json poetry install
|
|
```
|
|
|
|
## Iterate with monitor mode
|
|
|
|
```bash
|
|
greywall -m --settings ./greywall.json poetry install
|
|
```
|
|
|
|
If you use private indexes, add those domains explicitly.
|