dynamicEntities
Governance for runtime, user-defined entities (the dynamic schema-registry driver).
Guide: Dynamic entities
dynamicEntities
Section titled “dynamicEntities”Governance for runtime, user-defined entities (the dynamic schema-registry driver). End-users create record types at runtime via the Management API into metadata tables — they are NOT declared under entities. This block is how the host expresses the security policy and limits over that whole class. The store itself is planned and not in this build.
- Type:
object - Required: no
dynamicEntities.enabled
Section titled “dynamicEntities.enabled”Allow end-users to define entities at runtime.
- Type:
boolean - Required: no
- Default:
false
dynamicEntities.namePrefix
Section titled “dynamicEntities.namePrefix”Reserved name prefix for runtime-created entities, so they can never collide with descriptor-defined entity names.
- Type:
string - Required: no
- Pattern:
^[a-z][a-z0-9_]{0,15}_$
dynamicEntities.defaultRules
Section titled “dynamicEntities.defaultRules”Authorization rules applied to EVERY runtime-created entity. A virtual entity must carry policy exactly as a physical one carries rules; without this, default-deny makes user entities unreachable (or, if defaulted open, insecure). Missing operation = deny.
- Type:
object - Required: no
dynamicEntities.defaultRules.list
Section titled “dynamicEntities.defaultRules.list”Condition in the CEL subset. Context: @user, @tenant; hooks/events additionally expose old, new, changed(field). Compiled fail-fast at apply time.
- Type:
string - Required: no
dynamicEntities.defaultRules.get
Section titled “dynamicEntities.defaultRules.get”Condition in the CEL subset. Context: @user, @tenant; hooks/events additionally expose old, new, changed(field). Compiled fail-fast at apply time.
- Type:
string - Required: no
dynamicEntities.defaultRules.create
Section titled “dynamicEntities.defaultRules.create”Condition in the CEL subset. Context: @user, @tenant; hooks/events additionally expose old, new, changed(field). Compiled fail-fast at apply time.
- Type:
string - Required: no
dynamicEntities.defaultRules.update
Section titled “dynamicEntities.defaultRules.update”Condition in the CEL subset. Context: @user, @tenant; hooks/events additionally expose old, new, changed(field). Compiled fail-fast at apply time.
- Type:
string - Required: no
dynamicEntities.defaultRules.delete
Section titled “dynamicEntities.defaultRules.delete”Condition in the CEL subset. Context: @user, @tenant; hooks/events additionally expose old, new, changed(field). Compiled fail-fast at apply time.
- Type:
string - Required: no
dynamicEntities.allowedFieldTypes
Section titled “dynamicEntities.allowedFieldTypes”The subset of field types end-users may use on runtime entities.
- Type:
array of string - Required: no
dynamicEntities.maxFieldsPerEntity
Section titled “dynamicEntities.maxFieldsPerEntity”Per-entity field quota for runtime entities.
- Type:
integer - Required: no
dynamicEntities.maxRecordsPerEntity
Section titled “dynamicEntities.maxRecordsPerEntity”Per-entity record quota for runtime entities (per tenant).
- Type:
integer - Required: no
dynamicEntities.maxEntitiesPerTenant
Section titled “dynamicEntities.maxEntitiesPerTenant”How many runtime entities a single tenant may create.
- Type:
integer - Required: no
dynamicEntities.defaultTenancy
Section titled “dynamicEntities.defaultTenancy”Default tenancy for runtime-created entities.
- Type:
string - Required: no
- Values:
"scoped","global" - Default:
"scoped"