agent-substrate / agent-substrate/substrate

[Feature] Equivalent of "Node Isolation" in K8s

オープン
#125 コメント 4 件 リアクション 0 件 担当者 1 名 @ahmedtd が担当を希望しています GitHub で見る
area/node area/security kind/feature prio/P1
主要言語
Go
スター
1.8k
フォーク
316
平均マージ
2日 43分
マージ済み PR(30日)
287

説明

We need to make sure that atelet and ateom only have privileges to act on behalf of actors that are actually assigned to them.

* If you break out of an actor to compromise an atelet / node, then you can modify the snapshots that atelet writes. This gives you RCE on the next node that actor is restored onto.
* My suspicion is that the churn in actors will mean that a compromise of one node will quickly be able to pivot to many more nodes, as compromised actors get restored on different nodes.
* Traditional node isolation (in the k8s sense) will not be a sufficient defense against this.
* We may need to consider a strategy where we divide the fleet of actors into N bins, and ensure that actors from different bins are never co-scheduled.
* The larger N gets, the more efficiency we are giving up for small deployments. So N will need to be somewhat dynamic.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。