Skip to content

feat(security): provide shared runsc provisioning for Bluefin-family hosts #1038

Description

@joshyorko

Outcome

Provide one shared, trusted Bluefin-family host provisioning path for gVisor's
runsc OCI runtime so Review and other isolated workloads can select
--runtime=runsc without each image repository maintaining its own installer.

Ownership

Common's system_files/shared/ is distributed to the Bluefin family and owns
reusable host infrastructure. The initial implementation was developed in
projectbluefin/bluefin#1142; this issue re-homes that work rather than creating
a second implementation.

Required behavior

Preserve the #1142 contract: a pinned upstream release; exact x86_64 and
aarch64 identities; unsupported-architecture rejection before download;
HTTPS-only acquisition; digest verification before archive inspection or
extraction; expected-member allowlisting; the required gvisor-bin payload;
safe install/update/remove ownership and symlink protection; atomic
publication; idempotency; /usr/local/bin/runsc discovery; unchanged Podman
default runtime; no Review packaging; no ignore-cgroups=true; and no
host-network workaround.

Consumers and acceptance

Common provisioning alone does not prove native acceptance. After a Bluefin
Testing image consumes this change, prove ujust runsc install, version
reporting, rootless podman --runtime=runsc, OCIRuntime=runsc, ordinary
networking, lifecycle behavior, no cgroup or host-network workaround, the
Review fail-closed path, and separate arm64 acceptance.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/securityAuthentication, image trust, signing policy, and sandbox isolation.area/system-servicesHost setup hooks, system services, OS updates, and power management.blockedWork is blocked on human input or an external dependency.kind/featureA requested capability or enhancement.needs-humanHuman input is required before Hive may start new implementation work.needs-triageAwaiting a maintainer assessment; not implementation approval.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions