v0.4: prove containerd CNI identity and deny-before-start handoff
- Lingua principale
- Go
- Stelle
- 1
- Fork
- 0
- Merge medio
- 18m
- PR unite (30g)
- 19
Descrizione
Parent epic: #6
Depends on the contract issue and research #65.
Build a disposable chained-CNI probe for the exact k3s/containerd target. Prove that one invocation receives matching `K8S_POD_UID`, sandbox container ID, `CNI_NETNS`, `prevResult`, and `runtimeConfig.cgroupPath`; installs Pod-parent deny before returning; and returns an error without opening traffic when intent or capability is missing.
Cover amd64 and arm64, duplicate ADD, CHECK, DEL with missing netns, GC, rapid Pod replacement, user init/native-sidecar/app first-packet capture, and composition after Flannel/portmap/bandwidth. Do not modify production workloads. Restore the exact prior conflist and remove every probe resource.
Guida per i contributori
Apri la guida per i contributori
Direzione di ricerca
No file, test, or entry point is named; begin by reading contract issue #6 and research #65, then locate the CNI and k3s/containerd integration points for a disposable chained-CNI probe. Done means the probe verifies the listed identity and lifecycle cases on amd64 and arm64, fails closed when required intent or capability is absent, and restores the exact conflist while removing all probe resources.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- go, kubernetes
- Ambito
- networking, security
- Tipo di issue
- Funzionalità
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Stato di attività
- Tranquilla
- Chiarezza
- Abbastanza chiara
- Idoneità per principianti
- 35/100