v0.4: prove containerd CNI identity and deny-before-start handoff
- 主要言語
- Go
- スター
- 1
- フォーク
- 0
- 平均マージ
- 18分
- マージ済み PR(30日)
- 19
説明
Parent epic: #6
Depends on the contract issue and research #65.
Build a disposable chained-CNI probe for the exact k3s/containerd target. Prove that one invocation receives matching `K8S_POD_UID`, sandbox container ID, `CNI_NETNS`, `prevResult`, and `runtimeConfig.cgroupPath`; installs Pod-parent deny before returning; and returns an error without opening traffic when intent or capability is missing.
Cover amd64 and arm64, duplicate ADD, CHECK, DEL with missing netns, GC, rapid Pod replacement, user init/native-sidecar/app first-packet capture, and composition after Flannel/portmap/bandwidth. Do not modify production workloads. Restore the exact prior conflist and remove every probe resource.
コントリビューションガイド
調査の方向性
No file, test, or entry point is named; begin by reading contract issue #6 and research #65, then locate the CNI and k3s/containerd integration points for a disposable chained-CNI probe. Done means the probe verifies the listed identity and lifecycle cases on amd64 and arm64, fails closed when required intent or capability is absent, and restores the exact conflist while removing all probe resources.
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- go, kubernetes
- 領域
- networking, security
- issue の種類
- 機能追加
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 活発さ
- 静か
- 明瞭さ
- おおむね明確
- 初心者へのやさしさ
- 35/100