Amoenus / Amoenus/waycloak

v0.4: prove containerd CNI identity and deny-before-start handoff

オープン
#108 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
enhancement
主要言語
Go
スター
1
フォーク
0
平均マージ
18分
マージ済み PR(30日)
19

説明

Parent epic: #6
Depends on the contract issue and research #65.

Build a disposable chained-CNI probe for the exact k3s/containerd target. Prove that one invocation receives matching `K8S_POD_UID`, sandbox container ID, `CNI_NETNS`, `prevResult`, and `runtimeConfig.cgroupPath`; installs Pod-parent deny before returning; and returns an error without opening traffic when intent or capability is missing.

Cover amd64 and arm64, duplicate ADD, CHECK, DEL with missing netns, GC, rapid Pod replacement, user init/native-sidecar/app first-packet capture, and composition after Flannel/portmap/bandwidth. Do not modify production workloads. Restore the exact prior conflist and remove every probe resource.

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

No file, test, or entry point is named; begin by reading contract issue #6 and research #65, then locate the CNI and k3s/containerd integration points for a disposable chained-CNI probe. Done means the probe verifies the listed identity and lifecycle cases on amd64 and arm64, fails closed when required intent or capability is absent, and restores the exact conflist while removing all probe resources.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
go, kubernetes
領域
networking, security
issue の種類
機能追加
難易度
5/5
見積もり時間
1週間以上
活発さ
静か
明瞭さ
おおむね明確
初心者へのやさしさ
35/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。