v0.4: implement node-owned eBPF link lifecycle and capability status
- Lingua principale
- Go
- Stelle
- 1
- Fork
- 0
- Merge medio
- 18m
- PR unite (30g)
- 19
Descrizione
Parent epic: #6
Depends on the CNI handoff proof.
Implement the prepared-node agent ownership core:
- executable capability probe and stable node observation;
- UID/generation-owned cgroup programs, maps, links, and pins;
- adoption after loader/agent restart;
- atomic deny-to-deny update and failed-update retention;
- severed-link detection, Pod deletion/quarantine checks, and bounded GC;
- node reboot recovery before preview workloads resume;
- least-privilege amd64/arm64 security profiles, including a narrow Raspberry Pi AppArmor profile.
No prefix/glob cleanup, alphabetical identity, silent detach, or backend fallback. Acceptance is packet/lifecycle evidence, not feature presence.
Guida per i contributori
Apri la guida per i contributori
Direzione di ricerca
Start by reading parent epic #6 and the CNI handoff proof this depends on; the issue does not name files or tests. The work centers on the prepared-node agent ownership core for eBPF/cgroup program, map, link, and pin lifecycle. Done means packet and lifecycle evidence for adoption, updates, GC, reboot recovery, and least-privilege profiles, with no forbidden cleanup or fallback behavior.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- go, kubernetes, linux, raspberry-pi
- Ambito
- infrastructure, networking, security
- Tipo di issue
- Funzionalità
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Stato di attività
- Tranquilla
- Chiarezza
- Da chiarire
- Idoneità per principianti
- 18/100