- images/seccomp/agent-profile.json is now a TRUE ALLOWLIST: Docker's default profile (vendored from moby v27.5.1, defaultAction ERRNO) with 18 syscalls an agent never needs stripped from the allow groups (unshare, ptrace, bpf, mount family, setns, module loading, perf_event_open, process_vm_*, reboot, quotactl, ...); arch map trimmed to x86_64 + aarch64. All 6 Docker kernel assertions still green. - K8sDriver (tc-sandbox feature 'k8s', kube-rs): one hardened pod per sandbox — runAsUser 10001, cap-drop ALL, no-new-privs via allowPrivilegeEscalation=false, RuntimeDefault seccomp, read-only rootfs with emptyDir /tmp + /home/agent, resource limits, no service account token — in a PSS-restricted namespace carrying a default-deny NetworkPolicy (applied server-side apply, idempotent). Exec via the API server attach channel with exit codes parsed from v1.Status. - Live suite (feature 'k8s-tests') against a REAL kind cluster: uid / CapEff==0 / NoNewPrivs / rootfs probes from inside pods, PSS label + deny-all policy asserted via the API, lifecycle. Honest limits in the rustdoc: Localhost seccomp profile and CNI-enforced egress are per-cluster provisioning (kindnet does not enforce NetworkPolicy). - rustls 0.23 process provider pinned to ring at driver connect. - CI: dedicated sandbox-k8s job (helm/kind-action) running the suite. 149 Rust tests + 3 live kind tests; clippy clean including the k8s feature. Co-Authored-By: Claude Fable 5 <[email protected]>
32 lines
948 B
TOML
32 lines
948 B
TOML
[package]
|
|
name = "tc-sandbox"
|
|
version = "0.1.0"
|
|
edition.workspace = true
|
|
rust-version.workspace = true
|
|
license.workspace = true
|
|
publish.workspace = true
|
|
|
|
[dependencies]
|
|
async-trait = "0.1"
|
|
bollard = "0.19"
|
|
futures = "0.3"
|
|
k8s-openapi = { version = "0.25", features = ["latest"], optional = true }
|
|
kube = { version = "1", features = ["client", "rustls-tls", "ws"], default-features = false, optional = true }
|
|
rustls = { version = "0.23", features = ["ring"], default-features = false, optional = true }
|
|
serde = { workspace = true }
|
|
serde_json = { workspace = true }
|
|
thiserror = { workspace = true }
|
|
tokio = { workspace = true }
|
|
|
|
[features]
|
|
# The Kubernetes driver (kube-rs is a heavy dependency tree; the Docker
|
|
# driver alone serves dev and the air-gapped target).
|
|
k8s = ["dep:kube", "dep:k8s-openapi", "dep:rustls"]
|
|
# Live kind-cluster tests for the K8s driver (dedicated CI job).
|
|
k8s-tests = ["k8s"]
|
|
|
|
[dev-dependencies]
|
|
|
|
[lints]
|
|
workspace = true
|