Skip to content
Talk to our solutions team

Namespace Reference

A script sees a set of namespaces. Each groups related functions, and a script reaches only what has been bound into it — the namespace set is the sandbox boundary. The security question is therefore what you bound, not whether the script is trustworthy.

GroupNamespaces
Executionshell, supershell, ssh, docker, podman, k8s, kubectl
Files & Transferfile, glob, archive, extract, rsync, scp, s3, azureblob
Networkhttp, dns, letsencrypt
Data & Templatingdb, jq, liquid, vars, compute, aggregate, csv, excel, parquet, entity, morph, stdout
Secrets & Securityvault, secret, crypt, hash, id
Coordinationlock, wait, cron, port, user
AIllm, intent, guard, embed, sofia, milvus, text, validate, scrape, pipeline

Namespaces are bound per execution context. Not every caller grants every namespace — a rule helper is given far less than a deployment script — so check what your invoking block binds rather than assuming the full set.

The same capabilities are available as YAML tasks in pipelines; see the Automate task reference for that form.