- K8sDriver.with_localhost_seccomp(profile): sandbox pods run under the STRICT allowlist instead of the runtime default. Proven live on kind: the harness installs the profile onto the node, a pod runs ordinary work as uid 10001, and unshare is kernel-denied inside the pod — the same probe the Docker suite uses, now passing on both targets - Helm: sandbox.seccomp=localhost renders a DaemonSet that installs the chart-shipped profile into /var/lib/kubelet/seccomp on every node (ConfigMap + hostPath); ci/check-helm.sh enforces the chart copy stays byte-identical to images/seccomp/agent-profile.json and asserts the hardened render (DaemonSet + profile + HPA) - server HPA (autoscaling/v2, CPU target) behind server.autoscaling.enabled - SandboxManager.warm(n): a background warmer keeps n pre-provisioned sandboxes ready so an agent's first exec skips container startup; unhealthy pool entries are discarded, reuse never drains the pool, shutdown destroys assigned AND pooled. [sandbox] warm_pool config (default 0). Real-Docker test: prefill -> assign -> refill -> reuse -> clean shutdown 160 Rust tests + 4 live kind tests. Co-Authored-By: Claude Fable 5 <[email protected]>
62 lines
1.9 KiB
Bash
Executable File
62 lines
1.9 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Lints the chart and asserts the load-bearing rendered properties: the
|
|
# broker rides as a server sidecar sharing the socket volume, SSE is
|
|
# unbuffered at the ingress, and pods run hardened.
|
|
set -euo pipefail
|
|
|
|
ROOT="$(cd "$(dirname "$0")/.." && pwd)"
|
|
CHART="$ROOT/deploy/helm/teamclaw"
|
|
|
|
helm lint "$CHART" \
|
|
--set auth.issuerUrl=https://idp.example.com \
|
|
--set oauth.redirectBase=https://teamclaw.example.com
|
|
|
|
RENDERED=$(helm template teamclaw "$CHART" \
|
|
--set auth.issuerUrl=https://idp.example.com \
|
|
--set oauth.redirectBase=https://teamclaw.example.com)
|
|
|
|
require() {
|
|
if ! grep -qF -- "$1" <<<"$RENDERED"; then
|
|
echo "FAIL: rendered chart is missing: $1"
|
|
exit 1
|
|
fi
|
|
}
|
|
|
|
# Broker sidecar shares the unix-socket emptyDir with the server.
|
|
require 'name: broker'
|
|
require 'value: /run/teamclaw/broker.sock'
|
|
require 'mountPath: /run/teamclaw'
|
|
# SSE must not buffer at the ingress.
|
|
require 'nginx.ingress.kubernetes.io/proxy-buffering: "off"'
|
|
# Hardened pods.
|
|
require 'runAsNonRoot: true'
|
|
require 'drop: ["ALL"]'
|
|
require 'readOnlyRootFilesystem: true'
|
|
# Config wired through the ConfigMap.
|
|
require 'socket_path = "/run/teamclaw/broker.sock"'
|
|
|
|
# The chart-shipped seccomp profile must BE the Docker driver's profile.
|
|
if ! diff -q "$ROOT/images/seccomp/agent-profile.json" \
|
|
"$CHART/files/agent-profile.json" >/dev/null; then
|
|
echo "FAIL: chart seccomp profile diverged from images/seccomp"
|
|
exit 1
|
|
fi
|
|
|
|
HARDENED=$(helm template teamclaw "$CHART" \
|
|
--set auth.issuerUrl=https://idp.example.com \
|
|
--set oauth.redirectBase=https://teamclaw.example.com \
|
|
--set sandbox.seccomp=localhost \
|
|
--set server.autoscaling.enabled=true)
|
|
for needle in \
|
|
'kind: DaemonSet' \
|
|
'teamclaw-agent-profile.json' \
|
|
'kind: HorizontalPodAutoscaler' \
|
|
'averageUtilization: 70'; do
|
|
if ! grep -qF -- "$needle" <<<"$HARDENED"; then
|
|
echo "FAIL: hardened render is missing: $needle"
|
|
exit 1
|
|
fi
|
|
done
|
|
|
|
echo "helm chart OK"
|