Skip to main content

maf-sandbox-bicep

PyPI Python License

Experimental. Releases before 1.0 may change or remove APIs. Importing this package emits MafSandboxBicepExperimentalWarning.

Compile and lint Bicep templates and parameter files from an agent's file store. The bicep_validate tool returns compiler diagnostics and fixed guidance about how to use them.

This is an independent package for Microsoft Agent Framework. It uses the maf-sandbox protocol and has no backend dependency.

Quickstart

pip install maf-sandbox-bicep
from maf_sandbox_bicep import make_bicep_tools

tools = make_bicep_tools(
    router,
    file_store,
    "devops-engineer",
    context,
    image="bicep-sandbox:0.46.1",
)

The host supplies router, file_store and CallerContext. The context lists the files this caller may share. With no router or no configured backend, the factory returns []. An incompatible backend is refused before attachment.

Build the Bicep image and follow the ACAS sample, WSLC sample or Docker sample for complete wiring.

Validation

The tool reads only requested names from the caller's listing. It stages all selected files before compiling, so local modules and parameter-file references resolve together.

Templates use bicep build; parameter files use bicep build-params. The tool also runs lint as applicable. Commands are fixed templates with validated paths. Model text is passed as file content.

The image supplies the CLI. The package supplies a complete bicepconfig.json and stages it before compilation in each fresh call directory below /maf-sandbox/work. Bicep finds that configuration by walking up from the source. A config upload failure leaves validation incomplete. Each call also owns its generated files, HOME, TMPDIR and module cache. A manifest accepts at most 63 source files, reserving one transfer slot for the config.

The packaged config lists every linter rule in its recorded upstream release, including disabled rules. It preserves upstream defaults except for no-unused-params=error and use-recent-api-versions=warning with maxAgeInDays=730. Compiler IDs live separately in compiler_codes.json; catalog_source.json records the release, commit and upstream settings. These files ship in the wheel and source archive. Updating the catalog does not upgrade the host-selected compiler.

exec_timeout_seconds defaults to 120 per compiler command. Cancellation waits for the bounded active command before cleanup. A cancelled host wait alone does not prove that the guest stopped.

Network access

The default Egress.ALLOWLIST permits public module restore through these fixed destinations:

Destination Purpose
mcr.microsoft.com Module manifests
*.data.mcr.microsoft.com Module layers
aka.ms Module-index redirect
live-data.bicep.azure.com Module-index data

The factory does not widen that list. A Docker or WSLC backend needs its filtering proxy configured to serve it.

Pass egress=Egress.CLOSED for offline validation. This adds --no-restore; local modules work, while unavailable external modules leave validation incomplete. A host may explicitly select UNRESTRICTED only with a backend that supports it.

The allowlist grants no Azure Resource Manager access and supplies no credentials.

Results and cleanup

This version requires maf-sandbox>=0.42.0,<0.43. bicep_validate returns SandboxResult, which the attached tool renders as a list[Content]: completion, an optional valid or invalid verdict, any trusted refusals and diagnostic summary, any untrusted diagnostics or file-listing hints, then fixed guidance. The item count varies. Incomplete calls have no verdict, and either output sequence may be empty.

Completion, verdict, refusals and the selected summary carry trusted integrity. Raw diagnostics retain untrusted integrity even with trusted inputs. The host supplies result confidentiality; fixed guidance remains trusted/public. When middleware hides diagnostics, the model reads the verdict and summary or reports the files as unvalidated if there is no verdict. Refused names, staging failures, timeouts, unreadable SARIF and failed module restores leave the call incomplete.

The summary is a separate JSON text item with type="bicep_diagnostics". Each record selects a catalog rule ID, a severity and a reference such as files[0] to an input argument. It contains no messages, raw paths, line numbers or counts. Records are deduplicated across build and lint, sorted and capped at 128. Boolean fields unrecognized_diagnostics, unattributed_locations and truncated identify gaps; unmatched locations use file="unattributed". Unknown IDs remain in the raw report. An empty recognized subset does not establish clean validation. The summary retains the call's confidentiality and does not restore a conversation that is already untrusted.

A restore failure reports MODULE RESTORE FAILED. Hidden, empty or unreadable diagnostics do not establish a successful validation. Forwarding hidden diagnostics to a file writer remains subject to that tool's policy.

Diagnostic formatting removes call-directory paths and applies permitted display names. It does not remove arbitrary compiler prose or every external URL.

Direct invoke(..., skip_parsing=True) callers must read each item's .text without assuming fixed indexes. Preserve the items and labels; do not turn the list into a Python string representation. Framework function-result content exposes .items and joins their text in .result.

Core disposes after each call by default. Explicit host opt-in can permit reclaim on a supporting backend. The kind's confinement declaration describes its file placement; it does not certify that a reused sandbox is clean.

See the Bicep guide for the full contract and information flow for labels.

Maintained by SOKOLAI BV.

Release files for maf-sandbox-bicep 0.20.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for maf-sandbox-bicep 0.20.0
File Size Uploaded
maf_sandbox_bicep-0.20.0.tar.gz 29.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for maf-sandbox-bicep 0.20.0
File Interpreter ABI Platform
maf_sandbox_bicep-0.20.0-py3-none-any.whl Python 3 none any Details

Total release size: 61.3 kB

Release files / maf_sandbox_bicep-0.20.0.tar.gz

Download URL maf_sandbox_bicep-0.20.0.tar.gz
Size 29.2 kB
Tags Source
SHA-256 checksum
How to use checksums
a10f14edfa65fda71d38ab181f4f939e2f1c5eb20cb17fdfb1eb8d0ab025d487
BLAKE2b-256 checksum
How to use checksums
4203822850e5b1a0a5057c0e6177ae395dcbc93771dab0a0fbecc100aab37b94
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.

Transparency log

Release files / maf_sandbox_bicep-0.20.0-py3-none-any.whl

Download URL maf_sandbox_bicep-0.20.0-py3-none-any.whl
Size 32.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
039ec44a0ae39a4e5289cde95649280f49c70d213861667cddf124a1392767b4
BLAKE2b-256 checksum
How to use checksums
080c98fdfd4c83868afcb59d27a6471bec3075173cd568bcecc90568cd494855
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.

Transparency log

Release history Release notifications | RSS feed

0.21.1

2 release files

0.21.0

2 release files

This release

0.20.0 This release

2 release files

0.19.0

2 release files

0.18.0

2 release files

0.17.0

2 release files

0.16.1

2 release files

0.16.0

2 release files

0.15.1

2 release files

0.15.0

2 release files

0.10.0

2 release files

0.9.8

2 release files

0.9.7

2 release files

0.9.6

2 release files

0.9.3

2 release files

0.9.2

2 release files

0.9.1

2 release files

0.9.0

2 release files

0.8.1

2 release files

0.8.0

2 release files

0.7.5

2 release files

0.7.4

2 release files

0.7.3

2 release files

0.7.2

2 release files

0.7.1

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.6

2 release files

0.5.5

2 release files

0.5.4

2 release files

0.5.3

2 release files

0.5.2

2 release files

0.5.1

2 release files

0.4.0

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page