Post-1.0: Localhost seccomp on K8s, warm sandbox pool, server HPA
- K8sDriver.with_localhost_seccomp(profile): sandbox pods run under the STRICT allowlist instead of the runtime default. Proven live on kind: the harness installs the profile onto the node, a pod runs ordinary work as uid 10001, and unshare is kernel-denied inside the pod — the same probe the Docker suite uses, now passing on both targets - Helm: sandbox.seccomp=localhost renders a DaemonSet that installs the chart-shipped profile into /var/lib/kubelet/seccomp on every node (ConfigMap + hostPath); ci/check-helm.sh enforces the chart copy stays byte-identical to images/seccomp/agent-profile.json and asserts the hardened render (DaemonSet + profile + HPA) - server HPA (autoscaling/v2, CPU target) behind server.autoscaling.enabled - SandboxManager.warm(n): a background warmer keeps n pre-provisioned sandboxes ready so an agent's first exec skips container startup; unhealthy pool entries are discarded, reuse never drains the pool, shutdown destroys assigned AND pooled. [sandbox] warm_pool config (default 0). Real-Docker test: prefill -> assign -> refill -> reuse -> clean shutdown 160 Rust tests + 4 live kind tests. Co-Authored-By: Claude Fable 5 <[email protected]>
This commit is contained in:
co-authored by
Claude Fable 5
parent
a26939d7bc
commit
05e9612688
@@ -7,6 +7,11 @@ image:
|
||||
|
||||
server:
|
||||
replicas: 1
|
||||
autoscaling:
|
||||
enabled: false
|
||||
min: 1
|
||||
max: 5
|
||||
targetCPU: 70
|
||||
resources:
|
||||
requests: { cpu: 250m, memory: 256Mi }
|
||||
limits: { cpu: "1", memory: 512Mi }
|
||||
@@ -62,6 +67,11 @@ oauth:
|
||||
clientSecretName: teamclaw-oauth
|
||||
redirectBase: ""
|
||||
|
||||
sandbox:
|
||||
# runtimeDefault | localhost (localhost installs the strict allowlist
|
||||
# profile onto every node via a DaemonSet and runs sandbox pods under it)
|
||||
seccomp: runtimeDefault
|
||||
|
||||
ingress:
|
||||
enabled: true
|
||||
className: nginx
|
||||
|
||||
Reference in New Issue
Block a user