feat(guard): read the Zerto task, and ask before guarding unknown tools (#6)
This commit was merged in pull request #6.
This commit is contained in:
+6
-2
@@ -34,8 +34,12 @@ A VPG whose status is MeetingSLA or a NotMeetingSLA variant, and whose substatus
|
||||
_Avoid_: healthy, in sync, Protecting (as status 0)
|
||||
|
||||
**Mutating catalog**:
|
||||
The opt-in list of MCP tools that must call `zerto_guard_before_mutate` first. Unlisted tools pass through. Users add entries; the starter list is not the whole world.
|
||||
_Avoid_: denylist, hold-everything
|
||||
The opt-in list of MCP tools that must call `zerto_guard_before_mutate` first. Paired with `read_only_tools`, the list known not to change a guest. A tool in neither is **unknown**, which is the normal case: the agent asks the human whether to checkpoint rather than assuming either way.
|
||||
_Avoid_: denylist, hold-everything, treating unknown as safe
|
||||
|
||||
**Zerto task**:
|
||||
Write operations return a task id, not a result. A 200 means queued. `GET /v1/tasks/{id}` carries the real outcome in `Status.State`: 1 InProgress, 4 Failed, 5 Stopped, 6 Completed (terminal is 4/5/6). A second tagged-checkpoint insert fired at a VPG while the first runs comes back Failed, which is only visible if the task is read.
|
||||
_Avoid_: treating HTTP 200 as success
|
||||
|
||||
**Official ZVM MCP**:
|
||||
HPE Zerto 10.9 MCP (`ZVM.MCP`): inventory, VPG settings, failover test. Not in the demo path. This PoC is one server.
|
||||
|
||||
Reference in New Issue
Block a user