-
Notifications
You must be signed in to change notification settings - Fork 59
feat(security): provide shared runsc provisioning for Bluefin-family hosts #1038
Copy link
Copy link
Open
Labels
area/securityAuthentication, image trust, signing policy, and sandbox isolation.Authentication, image trust, signing policy, and sandbox isolation.area/system-servicesHost setup hooks, system services, OS updates, and power management.Host setup hooks, system services, OS updates, and power management.blockedWork is blocked on human input or an external dependency.Work is blocked on human input or an external dependency.kind/featureA requested capability or enhancement.A requested capability or enhancement.needs-humanHuman input is required before Hive may start new implementation work.Human input is required before Hive may start new implementation work.needs-triageAwaiting a maintainer assessment; not implementation approval.Awaiting a maintainer assessment; not implementation approval.
Description
Activity
Metadata
Metadata
Assignees
Labels
area/securityAuthentication, image trust, signing policy, and sandbox isolation.Authentication, image trust, signing policy, and sandbox isolation.area/system-servicesHost setup hooks, system services, OS updates, and power management.Host setup hooks, system services, OS updates, and power management.blockedWork is blocked on human input or an external dependency.Work is blocked on human input or an external dependency.kind/featureA requested capability or enhancement.A requested capability or enhancement.needs-humanHuman input is required before Hive may start new implementation work.Human input is required before Hive may start new implementation work.needs-triageAwaiting a maintainer assessment; not implementation approval.Awaiting a maintainer assessment; not implementation approval.
Outcome
Provide one shared, trusted Bluefin-family host provisioning path for gVisor's
runscOCI runtime so Review and other isolated workloads can select--runtime=runscwithout each image repository maintaining its own installer.Ownership
Common's
system_files/shared/is distributed to the Bluefin family and ownsreusable host infrastructure. The initial implementation was developed in
projectbluefin/bluefin#1142; this issue re-homes that work rather than creating
a second implementation.
Required behavior
Preserve the #1142 contract: a pinned upstream release; exact x86_64 and
aarch64 identities; unsupported-architecture rejection before download;
HTTPS-only acquisition; digest verification before archive inspection or
extraction; expected-member allowlisting; the required
gvisor-binpayload;safe install/update/remove ownership and symlink protection; atomic
publication; idempotency;
/usr/local/bin/runscdiscovery; unchanged Podmandefault runtime; no Review packaging; no
ignore-cgroups=true; and nohost-network workaround.
Consumers and acceptance
Common provisioning alone does not prove native acceptance. After a Bluefin
Testing image consumes this change, prove
ujust runsc install, versionreporting, rootless
podman --runtime=runsc,OCIRuntime=runsc, ordinarynetworking, lifecycle behavior, no cgroup or host-network workaround, the
Review fail-closed path, and separate arm64 acceptance.