From 5c0daf1298b6ddfe7d7d9758c698ea69145ea2bc Mon Sep 17 00:00:00 2001 From: Google Team Member Date: Mon, 28 Sep 2026 21:26:21 -0700 Subject: [PATCH] feat: Support `"allowlist": "disabled"` in environment network config. Adds a short form for `network.allowlist` so terminal egress can be blocked from inside the `network` object. `network: "disabled"` keeps working unchanged. FUTURE_COPYBARA_INTEGRATE_REVIEW=https://github.com/googleapis/python-genai/pull/3002 from googleapis:release-please--branches--main f509ec224023fe807c4ccc226174e3dd47348279 PiperOrigin-RevId: 990032241 --- .../_gaos/types/interactions/__init__.py | 3 +++ .../types/interactions/allowlistentry.py | 22 +++++++++++++++++-- 2 files changed, 23 insertions(+), 2 deletions(-) diff --git a/google/genai/_gaos/types/interactions/__init__.py b/google/genai/_gaos/types/interactions/__init__.py index 4ea484662..3b5edc616 100644 --- a/google/genai/_gaos/types/interactions/__init__.py +++ b/google/genai/_gaos/types/interactions/__init__.py @@ -26,6 +26,7 @@ from .allowedtools import AllowedTools, AllowedToolsParam from .allowlistentry import ( AllowlistEntry, + AllowlistEntryMode, AllowlistEntryParam, Transform, TransformParam, @@ -451,6 +452,7 @@ "AllowedToolsParam", "Allowlist", "AllowlistEntry", + "AllowlistEntryMode", "AllowlistEntryParam", "AllowlistParam", "Annotation", @@ -859,6 +861,7 @@ "AllowedTools": ".allowedtools", "AllowedToolsParam": ".allowedtools", "AllowlistEntry": ".allowlistentry", + "AllowlistEntryMode": ".allowlistentry", "AllowlistEntryParam": ".allowlistentry", "Transform": ".allowlistentry", "TransformParam": ".allowlistentry", diff --git a/google/genai/_gaos/types/interactions/allowlistentry.py b/google/genai/_gaos/types/interactions/allowlistentry.py index 324c8b4ec..eb54ca40b 100644 --- a/google/genai/_gaos/types/interactions/allowlistentry.py +++ b/google/genai/_gaos/types/interactions/allowlistentry.py @@ -20,10 +20,17 @@ from __future__ import annotations from .. import BaseModel, UNSET_SENTINEL from pydantic import model_serializer -from typing import Dict, List, Optional, Union +from typing import Dict, List, Literal, Optional, Union from typing_extensions import NotRequired, TypeAliasType, TypedDict +AllowlistEntryMode = Literal["disabled",] +r"""Network egress mode. Set via the `\"allowlist\": \"disabled\"` short form; +must be the only rule in the allowlist and cannot be combined with +`domain`, `transform` or `credential`. +""" + + TransformParam = TypeAliasType( "TransformParam", Union[List[Dict[str, str]], Dict[str, str]] ) @@ -43,6 +50,11 @@ class AllowlistEntryParam(TypedDict): """ credential: NotRequired[str] r"""Optional. Reference to a server-managed Credential resource by ID.""" + mode: NotRequired[AllowlistEntryMode] + r"""Network egress mode. Set via the `\"allowlist\": \"disabled\"` short form; + must be the only rule in the allowlist and cannot be combined with + `domain`, `transform` or `credential`. + """ transform: NotRequired[TransformParam] r"""Headers to inject on all outbound requests matching this domain. Accepts a single dict or a list of dicts. The egress proxy injects these automatically.""" @@ -58,12 +70,18 @@ class AllowlistEntry(BaseModel): credential: Optional[str] = None r"""Optional. Reference to a server-managed Credential resource by ID.""" + mode: Optional[AllowlistEntryMode] = None + r"""Network egress mode. Set via the `\"allowlist\": \"disabled\"` short form; + must be the only rule in the allowlist and cannot be combined with + `domain`, `transform` or `credential`. + """ + transform: Optional[Transform] = None r"""Headers to inject on all outbound requests matching this domain. Accepts a single dict or a list of dicts. The egress proxy injects these automatically.""" @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["credential", "transform"]) + optional_fields = set(["credential", "mode", "transform"]) serialized = handler(self) m = {}