Skip to main content

maf-sandbox-bicep

Experimental. This package is early-stage (pre-1.0, Development Status :: 4 - Beta) — its API may change or be removed in a future release without notice. Importing it emits a one-time MafSandboxBicepExperimentalWarning; suppress it with warnings.filterwarnings("ignore", category=maf_sandbox_bicep.MafSandboxBicepExperimentalWarning) once you've read the notice.

This package is not affiliated with, endorsed by, or a product of Microsoft — it is a third-party reference implementation of microsoft/agent-framework#7568 for Microsoft Agent Framework.

Sandboxed Bicep validation as a Microsoft Agent Framework tool: bicep_validate writes the files an agent authored into a sandbox, runs bicep build and bicep lint there, and returns the compiler's SARIF diagnostics as structured text — T2 (compiler truth) instead of T0 (the model checking its own work).

app  ->  maf_sandbox  ->  a backend (maf-sandbox-acas, ...)  ->  this workload

This package is a sandbox kind in the sense of maf-sandbox's protocol. It contains no Azure import and no sandbox lifecycle code; it asks a SandboxRouter for a sandbox and gets back write_file and exec, so the same tool runs unchanged against ACA Sandboxes, a local Docker container or an in-process fake. Tests enforce both boundaries: one scans this package's sources for any Azure import, the other for any import outside what its manifest declares.

Quickstart

pip install maf-sandbox-bicep
from maf_sandbox_bicep import make_bicep_tools

tools = make_bicep_tools(router, workspace_store, "devops-engineer", context,
                         image="bicep-sandbox:0.46.1")

Pass router=None — or a router with no backend — and you get [] back: an unconfigured host attaches no tool rather than one that fails when called.

router, workspace_store and context are the host's, and this snippet shows none of them being built. samples/01_acas_bicep is the whole wiring as a runnable program: a one-turn agent that validates a deliberately flawed Bicep file and prints the compiler's diagnostics.

Threat model

Fixed command templates. No agent-authored text is interpolated into a shell command — the only substitution is a filesystem path, and only after that path is validated against the sandbox's own workspace listing (the injection guard: a name that isn't in the listing, or that resolves outside the workspace, is rejected before it reaches a template). Sanitized error surfaces. Failures the sandbox reports are cleaned before the model sees them, so a compiler or shell error cannot smuggle sandbox-internal detail back into the conversation. The egress allowlist. The only hosts Bicep is allowed to reach are the four an AVM module restore reads from — mcr.microsoft.com and *.data.mcr.microsoft.com for the artifacts, aka.ms and live-data.bicep.azure.com for the public module index — stated as a property of the spec (SandboxSpec.egress_allow), not of runtime configuration, because a deployment that could widen Bicep's egress after the fact could undo the containment the tool's design rests on. Nothing else is reachable, ARM above all.

What is Bicep-specific

What is Bicep-specific — the command templates, the accepted extensions, the SARIF parsing, the hosts Bicep is allowed to reach (the four an AVM module restore reads from) — lives here and only here. The spec pins the egress allowlist and work directory as properties of the workload, not of configuration: a deployment that could widen Bicep's egress could undo the containment the tool's design rests on.

Its companion artefacts live outside this package, because a container image and a registry are not Python: a pinned Bicep image on Azure Linux, and the registry and pull identity that serve it. The hard-won behaviours of the pinned CLI — SARIF on stderr for build but stdout for lint, build-params for .bicepparam, config discovery only by walking up from the source file — are documented where they bite, in _tool.py.

Provenance

Split out of maf-sandbox-acas (which keeps the ACAS backend and nothing else) so this workload's dependency set states its portability: maf-sandbox + agent-framework-core, nothing more. Extracted from a production agent application, where it runs against real infrastructure code an agent wrote — which is where every behaviour documented above was learned.


Maintained by SOKOLAI BV.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

maf_sandbox_bicep-0.3.1.tar.gz (17.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

maf_sandbox_bicep-0.3.1-py3-none-any.whl (19.1 kB view details)

Uploaded Python 3

File details

Details for the file maf_sandbox_bicep-0.3.1.tar.gz.

File metadata

  • Download URL: maf_sandbox_bicep-0.3.1.tar.gz
  • Upload date:
  • Size: 17.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for maf_sandbox_bicep-0.3.1.tar.gz
Algorithm Hash digest
SHA256 daaf064a3771310b5266220f3cf919cd6e16404c61c6680a4111bb9c54a82a4f
MD5 1dca7edef5c30d3ffae2e265a1503a31
BLAKE2b-256 09ef8bafa5720c8980fb4260359adea174a16a7cd323c002bc506756e458823f

See more details on using hashes here.

Provenance

The following attestation bundles were made for maf_sandbox_bicep-0.3.1.tar.gz:

Publisher: publish-packages.yml on sokolaidev/maf-extensions

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file maf_sandbox_bicep-0.3.1-py3-none-any.whl.

File metadata

File hashes

Hashes for maf_sandbox_bicep-0.3.1-py3-none-any.whl
Algorithm Hash digest
SHA256 c1482c9c8e23eda618f795fac9afe829e49eed35f27b4330cf0edec5320aa45b
MD5 51e02208c2da7016ecfe91ff852aee55
BLAKE2b-256 d287574864eb20e07136b6cf3e58a9bdd84b83a9e225d9a4f7a7255cecbd8af1

See more details on using hashes here.

Provenance

The following attestation bundles were made for maf_sandbox_bicep-0.3.1-py3-none-any.whl:

Publisher: publish-packages.yml on sokolaidev/maf-extensions

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page