Amoenus / Amoenus/waycloak

v0.4: prove containerd CNI identity and deny-before-start handoff

Aperta
#108 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
enhancement
Lingua principale
Go
Stelle
1
Fork
0
Merge medio
18m
PR unite (30g)
19

Descrizione

Parent epic: #6
Depends on the contract issue and research #65.

Build a disposable chained-CNI probe for the exact k3s/containerd target. Prove that one invocation receives matching `K8S_POD_UID`, sandbox container ID, `CNI_NETNS`, `prevResult`, and `runtimeConfig.cgroupPath`; installs Pod-parent deny before returning; and returns an error without opening traffic when intent or capability is missing.

Cover amd64 and arm64, duplicate ADD, CHECK, DEL with missing netns, GC, rapid Pod replacement, user init/native-sidecar/app first-packet capture, and composition after Flannel/portmap/bandwidth. Do not modify production workloads. Restore the exact prior conflist and remove every probe resource.

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

No file, test, or entry point is named; begin by reading contract issue #6 and research #65, then locate the CNI and k3s/containerd integration points for a disposable chained-CNI probe. Done means the probe verifies the listed identity and lifecycle cases on amd64 and arm64, fails closed when required intent or capability is absent, and restores the exact conflist while removing all probe resources.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
go, kubernetes
Ambito
networking, security
Tipo di issue
Funzionalità
Difficoltà
5/5
Tempo stimato
Più di una settimana
Stato di attività
Tranquilla
Chiarezza
Abbastanza chiara
Idoneità per principianti
35/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.