Feature request: allow administrator to restrict host volume mappings
Open
ECS
Proposed
- Dominant language
- Shell
- Stars
- 5.4k
- Forks
- 334
- PR merge metrics
- No merged PRs in 30d
Description
As an administrator, I want to be able to whitelist -- or, alternatively blacklist -- host volumes that can be mounted into a task container. This would mitigate certain kinds of host data leakage vulnerabilities (e.g., mounting `/etc/shadow` into a container) that could be exploited by allowing tasks to run with arbitrary and unfiltered volume mount specifications.
Contributor guide
Research direction
No files, tests, or entry points are named. Start by locating the task-container volume-mount configuration and determine whether whitelist or blacklist semantics are intended; done means administrators can enforce the selected policy and blocked mappings cannot be used.
Written by the indexing model from the issue text.
Assessment
- Domain
- cloud, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100