agent-substrate / agent-substrate/substrate

Investigate replacing credential broker mTLS with per-worker UDS isolation

Aperta
#778 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
area/network area/node area/security kind/design kind/feature
Lingua principale
Go
Stelle
1.8k
Fork
316
Merge medio
2g 43m
PR unite (30g)
287

Descrizione

## Context

PR #708 authenticates atunnel to the node-local atelet credential broker with mTLS over a Unix domain socket. This is necessary in the current layout because every root-running ateom shares the hostPath containing the broker socket; permissions on one shared socket do not distinguish workers.

Review discussion: https://github.com/agent-substrate/substrate/pull/708#discussion_r3717247245

Investigate whether filesystem isolation can provide the same worker-to-atelet binding with less protocol machinery.

## Questions

- Can atelet create a separate socket directory and listener for each worker?
- Can each worker Pod mount only its own socket directory?
- What ownership and mode should protect the directory and socket when ateom runs as root?
- How are sockets created, removed, and recovered across worker replacement, Pod UID reuse, atelet restart, and failed activation?
- How do we prevent path traversal, symlink, stale-socket, and cross-worker access attacks?
- Can atelet securely derive the worker identity from the selected listener without trusting request metadata?
- If filesystem isolation is sufficient, can TLS be removed, or should it remain as defense in depth?

## Acceptance criteria

- Document the trust boundary and attacker model, including a compromised actor and a compromised sibling worker on the same node.
- Compare the current shared-socket mTLS design with per-worker filesystem-isolated sockets.
- Specify socket naming, mounts, permissions, identity binding, lifecycle, and cleanup.
- Confirm the proposed design fails closed during stale assignment and restart races.
- Recommend whether to keep mTLS, replace it, or combine both.
- Do not remove mTLS until equivalent worker isolation is demonstrated by tests.

Guida per i contributori

Apri la guida per i contributori

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.