agent-substrate / agent-substrate/substrate
Investigate replacing credential broker mTLS with per-worker UDS isolation
- 主要語言
- Go
- 星號
- 1.8k
- 分支
- 316
- 平均合併
- 2 天 43 分鐘
- 30 天內合併 PR
- 287
描述
## Context
PR #708 authenticates atunnel to the node-local atelet credential broker with mTLS over a Unix domain socket. This is necessary in the current layout because every root-running ateom shares the hostPath containing the broker socket; permissions on one shared socket do not distinguish workers.
Review discussion: https://github.com/agent-substrate/substrate/pull/708#discussion_r3717247245
Investigate whether filesystem isolation can provide the same worker-to-atelet binding with less protocol machinery.
## Questions
- Can atelet create a separate socket directory and listener for each worker?
- Can each worker Pod mount only its own socket directory?
- What ownership and mode should protect the directory and socket when ateom runs as root?
- How are sockets created, removed, and recovered across worker replacement, Pod UID reuse, atelet restart, and failed activation?
- How do we prevent path traversal, symlink, stale-socket, and cross-worker access attacks?
- Can atelet securely derive the worker identity from the selected listener without trusting request metadata?
- If filesystem isolation is sufficient, can TLS be removed, or should it remain as defense in depth?
## Acceptance criteria
- Document the trust boundary and attacker model, including a compromised actor and a compromised sibling worker on the same node.
- Compare the current shared-socket mTLS design with per-worker filesystem-isolated sockets.
- Specify socket naming, mounts, permissions, identity binding, lifecycle, and cleanup.
- Confirm the proposed design fails closed during stale assignment and restart races.
- Recommend whether to keep mTLS, replace it, or combine both.
- Do not remove mTLS until equivalent worker isolation is demonstrated by tests.
貢獻指南
評估
這個 Issue 還沒有評估資料。