Rust SDK (HTTP client)¶
Governed actions added in v0.64.0 · Crate:
genesis-mesh-sdk(Git dependency) · Source:GenesisMeshLabs/sdk-rust· Rust ≥ 1.85
genesis-mesh-sdk is the Rust counterpart of the TypeScript, Go and .NET SDKs:
a thin client for the Network Authority’s HTTP API with Ed25519 operator
signing. Request and response bodies are serde_json::Value, matching the
wire JSON exactly. The gateway crate described in Rust is a separate
component.
[dependencies]
genesis-mesh-sdk = { git = "https://github.com/GenesisMeshLabs/sdk-rust", tag = "v0.64.0" }
Clients¶
Field |
Routes |
|---|---|
|
Boundary policy lifecycle: |
|
|
|
|
|
|
|
As before v0.64 |
Admin reads are signed GET requests whose signature covers {}.
Identifiers are encoded once per path segment; a resource ID such as
kv:vault/secret spans segments, and . or .. segments are refused before
any request is sent. Evidence submission is authenticated by the executor
signature and carries no operator headers.
resource_head uses GET /admin/evidence/resource-heads/<id> (v0.63.1) and,
against an older NA, falls back to the resource history; it refuses a history
that failed verification or was truncated rather than guess the head.
Governed actions¶
use genesis_mesh_sdk::{
governed_action, json, ActionError, ActionReport, ExecutionRecorder,
GovernedActionParams, GovernedVerification,
};
let recorder = ExecutionRecorder::new("secrets-controller", "secrets-controller", &executor_seed)?;
let result = governed_action(
&gm.boundary,
&gm.evidence_store,
&recorder,
GovernedActionParams {
evaluate: json!({
"attestation_id": attestation["attestation_id"],
"requested_capability": "sp-secret.rotate",
"context": {"request_parameters": {"app_id": "billing"}},
}),
resource_id: Some("kv:pilot-vault/billing-api".into()),
resource_action: Some("rotate".into()),
prior_resource: None, // read the head from the NA
verify: GovernedVerification {
operator_public_keys: vec![na_public_key],
expected_policies: vec![policy],
expected_attestation: Some(attestation),
..Default::default()
},
},
|_decision| async move {
let version = rotate_secret().await?;
Ok::<_, ActionError>(ActionReport {
value: Some(version.clone()),
execution_parameters: Some(json!({"secret_version": version})),
..Default::default()
})
},
)
.await?;
The action runs only after the decision verifies offline (signature, expiry,
context, attestation and exact policy bindings). A denial returns
authorized: false without running it. A failed action is recorded as a
failure record without its error text and returned as ActionFailed; if
that record cannot be submitted, ActionUnrecorded carries both errors.
Evidence metadata is checked for secret material and size before anything is
signed (SecretMaterial, code evidence_secret_material).
Offline verification¶
genesis_mesh_sdk::verify ports the Python reference with the same reason
codes: verify_boundary_decision, verify_evidence_events (store chain,
envelopes, every signature, decision and resource chains, retention
checkpoints), parse_export_lines, and per-artifact signature checks.
genesis_mesh_sdk::canonical gives the models’ canonical bodies and digests.
Both are tested against vectors produced by the Python core, and verifying the
Python export gives the same result as the NA’s GET /admin/evidence/verify.
Tests¶
cargo test --locked --all-targets
GM_E2E_PYTHON=../genesismesh/.venv/bin/python cargo test --locked --test live_na
The live test starts a disposable loopback NA and runs the governed lifecycle
using only SDK calls. CI runs it against core main.