Skip to content

Improve container debug privilege gates#1944

Open
DENGXUELIN wants to merge 1 commit into
UnitOneAI:mainfrom
DENGXUELIN:improve/container-debug-ephemeral-privilege-1574
Open

Improve container debug privilege gates#1944
DENGXUELIN wants to merge 1 commit into
UnitOneAI:mainfrom
DENGXUELIN:improve/container-debug-ephemeral-privilege-1574

Conversation

@DENGXUELIN
Copy link
Copy Markdown

Summary

  • add an additive debug container and ephemeral privilege evidence gate inside the existing container-security workflow
  • require workload persistence, TTL/expiry, namespace and target scope, RBAC/admission control, audit trail, and runtime-constraint evidence before downgrading privileged debug access
  • add vulnerable and benign fixtures for a persistent privileged debug DaemonSet versus a scoped audited ephemeral debug container

Validation

  • git diff --check origin/main...HEAD
  • Markdown fence balance check
  • Added-line ASCII check
  • Content marker check for debug container, ephemeral privilege, TTL, audit evidence, RBAC gate, host namespace, privileged, and break-glass evidence
  • git merge-tree --write-tree origin/main HEAD

Closes #1574

Bounty request: Improver Moderate / USD 100 if accepted.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[REVIEW] container-security: add debug container and ephemeral privilege evidence gates

1 participant