Local filesystem integration. Watch directories for changes, read/write files, and list directories β all constrained to configured allow-list paths.
Local filesystem connector-filesystem Rule engine
β β β
β inotify / FSEvents β β
β (watch_paths) β β
βββββββββββββββββββββββββββββββΊβ β
β β debounce (debounce_ms) β
β β emit FileWatch trigger β
β ββββββββββββββββββββββββββββΊβ
β β β
β β execute(read_file, β¦) β
β βββββββββββββββββββββββββββββ€ path β read_paths? β
β β β
β β execute(write_file, β¦) β
β βββββββββββββββββββββββββββββ€ path β write_paths? β
Fig. 1. Filesystem data flow. Watched paths emit debounced triggers; read/write actions are capability-checked against the path allow-lists.
TABLE I. CONFIG FIELDS
| Field | Type | Default | Description |
|---|---|---|---|
watch_paths |
Vec<PathBuf> |
(required) | Directories to monitor for filesystem events |
read_paths |
Vec<PathBuf> |
(required) | Allow-list for read operations |
write_paths |
Vec<PathBuf> |
(required) | Allow-list for write operations |
debounce_ms |
u64 |
500 |
Debounce interval for file events (milliseconds) |
None. Access is controlled by the path allow-lists in configuration.
All paths are canonicalized before checking β symlink traversal attacks are prevented. A request to read /data/inbox/../../etc/passwd resolves to /etc/passwd, which won't match any configured read_paths.
TABLE II. TRIGGERS
| Name | Description | Payload fields |
|---|---|---|
file_created |
A file was created in a watched directory | path, event: "create", filename, extension |
file_modified |
A file was modified in a watched directory | path, event: "modify", filename, extension |
file_deleted |
A file was deleted in a watched directory | path, event: "delete", filename, extension |
Triggers use the notify crate with debouncing to coalesce rapid filesystem events. The debounce window is configurable (default 500ms).
TABLE III. ACTIONS
| Name | Input fields | Output fields |
|---|---|---|
read_file |
path: String |
content: String, size_bytes: u64 |
write_file |
path: String, content: String, append: bool (default: false) |
bytes_written: u64 |
list_dir |
path: String |
entries: [{name, path, is_dir, is_file, size_bytes}], count: u64 |
Capabilities are generated dynamically from configuration:
| Capability | Parameter |
|---|---|
FilesystemRead |
Each path in watch_paths and read_paths |
FilesystemWrite |
Each path in write_paths |
[rule]
name = "auto-archive"
[trigger]
type = "ConnectorEvent"
connector = "connector-filesystem"
event = "file_created"
[[conditions]]
type = "Regex"
field = "trigger.extension"
pattern = "\\.(csv|json|xml)$"
[[actions]]
type = "WriteFile"
destination = "/data/archive/${trigger.filename}"
content = ""
delete_source = true