Azure / Azure/azure-cli-extensions

[confcom] Ensure base64 encodings of functionally identical policies are the same

Open
#9,249 1 comment 0 reactions 0 assignees View on GitHub
Service Attention
Dominant language
Python
Stars
454
Forks
1.7k
Avg merge
2d 19h
Merged PRs (30d)
64

Description

Attestation reports present a SHA256 of the raw security policy that is being enforced. This means changes which are not functional (e.g. arrays being reordered) will result in a different hash and therefore a policy that fails to match, despite actually being a correct policy.

This is a source of instability and should therefore be fixed. Here are the current known possible sources of different hashes from functionally identical policies:

- [ ] Ordering of arrays
- [ ] Environment variables in container definitions
- [ ] Exec processes in container definitions
- [ ] Volume Mounts in container definitions
- [ ] Includes statements in fragments
- [ ] Container definitions
- [ ] Fragment definitions

The priority is to fix ones which we change in future work, but ultimately all of these should be addressed

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.