Skip to content
@treetop-policy-engine

Treetop Policy Engine

Open-source Cedar authorization engine, server, clients, CLI, and browser workbench.

Treetop

Treetop Policy Engine

Treetop is an open-source authorization stack built on Cedar. It provides tools for building, validating, serving, and operating policy-based authorization.

Run Treetop as a REST service, integrate through an official client, compose deterministic policy bundles, or inspect the service from the command line and browser workbench. The Rust engine can also be embedded for specialized use cases.

Coordinated breaking release

The coordinated release adopts declared label ownership by exact Cedar resource type and attribute. Early Treetop releases prioritize correctness over compatibility; ambiguous ownership, deprecated aliases, and old-format defaults are removed. Bundle/module format 2 requires rebuilt and re-signed archives.

The September 6 release shipped Core, Bundle, REST, Rust/Python clients, CLI, and Workbench as 0.1.0; the Go client shipped as 0.3.0 and Bundle Action as v2. See the breaking migration and release set for the new syntax, required consumer updates, published artifacts, and upgrade order.

Current coordinated releases

Core and Bundle 0.3.0 are published with Cedar 4.13.0. REST, the Rust client, CLI, and Workbench are now 0.2.0; Python is 0.1.1, Go is 0.3.1, and Bundle Action is v3. The release set and migration notes link every artifact, review, and immutable server pin.

Rebuild and re-sign policy archives with Bundle CLI 0.3.0 before upgrading REST. Rust SDK/CLI builds require Rust 1.93.1 or newer. HTTP request and decision JSON are unchanged; the Utoipa 6 migration applies to Rust schema integrations.

Projects

These repositories are all maintained parts of Treetop, covering the runtime, policy delivery, client integrations, and operator tooling.

Project Purpose Distribution
treetop-rest REST API and standalone server server archives · container
treetop-client Typed asynchronous Rust client crate · docs
treetop-client-python Typed synchronous and asynchronous Python client PyPI
treetop-client-go Typed Go client Go package
treetop-cli Command-line client and interactive REPL native archives and checksums
treetop-frontend Browser workbench for policies, requests, and metrics static archive and checksum · container
treetop-bundle Deterministic, optionally signed Cedar policy bundles crate · docs · CLI archives
treetop-bundle-action Policy validation and bundle builds in GitHub Actions v3.0.0 · releases
treetop-core Rust engine underlying Treetop REST, also available for in-process deployments crate · docs

Release artifacts

Artifact Published formats
Treetop server Linux x86-64 and ARM64 musl archives; container image
Treetop CLI Linux x86-64 and ARM64 musl, Apple-silicon macOS, and Windows x86-64 archives with SHA-256 checksums
Bundle CLI Linux x86-64 and ARM64 musl, Apple-silicon macOS, and Windows x86-64 archives with SHA256SUMS
Workbench Versioned static-site archive with a SHA-256 checksum; Linux AMD64 and ARM64 container image
Libraries and clients Rust crates, Python on PyPI, and versioned Go modules
Bundle Action Versioned GitHub Action; v3.0.0 with the v3 major tag

Quick start

Run the server:

docker run --rm --publish 9999:9999 \
  --env TREETOP_LISTEN=0.0.0.0 \
  ghcr.io/treetop-policy-engine/treetop-rest:latest

Then check process liveness:

curl http://127.0.0.1:9999/livez

The Action v3 migration explains the required archive rebuild. Action v3 downloads published Bundle CLI 0.3.0 and verifies its checksum. Pin the reviewed immutable Action release commit 129eb4612dff4903e33cddb3cc9e0db131c3dfb6 in protected policy workflows. Existing v2 tags retain their original CLI 0.1.0 default.

Project-specific documentation, examples, current contracts, and release notes live in each repository.

Pinned Loading

  1. treetop-core treetop-core Public

    Embeddable Cedar policy engine for Rust

    Rust 1

  2. treetop-cli treetop-cli Public

    Command-line client and interactive REPL for Treetop authorization servers

    Rust

  3. treetop-client treetop-client Public

    Typed asynchronous Rust client for Treetop authorization servers

    Rust

  4. treetop-client-python treetop-client-python Public

    Typed synchronous and asynchronous Python client for Treetop

    Python

  5. treetop-frontend treetop-frontend Public

    Browser workbench for Treetop policies, authorization requests, and metrics

    TypeScript

  6. treetop-rest treetop-rest Public

    REST API and standalone server for the Treetop policy engine

    Rust

Repositories

Showing 10 of 10 repositories

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…