v0.4: implement node-owned eBPF link lifecycle and capability status
- Lenguaje dominante
- Go
- Estrellas
- 1
- Forks
- 0
- Merge medio
- 18 min
- PR fusionados (30 d)
- 19
Descripción
Parent epic: #6
Depends on the CNI handoff proof.
Implement the prepared-node agent ownership core:
- executable capability probe and stable node observation;
- UID/generation-owned cgroup programs, maps, links, and pins;
- adoption after loader/agent restart;
- atomic deny-to-deny update and failed-update retention;
- severed-link detection, Pod deletion/quarantine checks, and bounded GC;
- node reboot recovery before preview workloads resume;
- least-privilege amd64/arm64 security profiles, including a narrow Raspberry Pi AppArmor profile.
No prefix/glob cleanup, alphabetical identity, silent detach, or backend fallback. Acceptance is packet/lifecycle evidence, not feature presence.
Guía de contribución
Línea de trabajo
Start by reading parent epic #6 and the CNI handoff proof this depends on; the issue does not name files or tests. The work centers on the prepared-node agent ownership core for eBPF/cgroup program, map, link, and pin lifecycle. Done means packet and lifecycle evidence for adoption, updates, GC, reboot recovery, and least-privilege profiles, with no forbidden cleanup or fallback behavior.
Escrito por el modelo de indexación a partir del texto del issue.
Evaluación
- Stack tecnológico
- go, kubernetes, linux, raspberry-pi
- Área
- infrastructure, networking, security
- Tipo de issue
- Nueva funcionalidad
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Estado de actividad
- Tranquilo
- Claridad
- Necesita aclaración
- Aptitud para principiantes
- 18/100