bottlerocket-os / bottlerocket-os/bottlerocket
clarify security guidance around user namespaces
Open
area/security
status/icebox
type/documentation
- Dominant language
- Rust
- Stars
- 9.7k
- Forks
- 586
- Avg merge
- 1d 11h
- Merged PRs (30d)
- 11
Description
As noted in #3318, the statement that "Bottlerocket does not currently support user namespaces" can reasonably be interpreted to mean that user namespaces aren't supported. 😀
Need to rewrite it to mention what's specifically not supported - running orchestrated containers in a new user namespace - or else just drop it altogether.
Contributor guide
Assessment
This issue has not been assessed yet.