Skip to content

docs(runner): adopt the user-namespaced pod shape from R7 - #1771

Merged
trunk-io[bot] merged 1 commit into
compass-managed/rig-3723-r7-findingsfrom
compass-managed/rig-4615-privilege-shape-a
Oct 7, 2026
Merged

trunk-io[bot] merged 1 commit into
compass-managed/rig-3723-r7-findingsfrom
compass-managed/rig-4615-privilege-shape-a

Conversation

@rigel-mintaka

@rigel-mintaka rigel-mintaka commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

This PR is part of a stack containing 3 PRs:

  1. main
  2. docs(runner): record R7 privilege-shape observations from a VM node #1763
  3. "docs(runner): adopt the user-namespaced pod shape from R7" (this PR)
  4. feat(runner): render the Runner DaemonSet and KVM device request #1773

Summary

Amends the runner containerization record to adopt ruling A from the R7 spike.

  • Pod: hostUsers: false and procMount: Unmasked, so virtiofsd can mount /proc. appArmorProfile: Unconfined, so passt can remount. The Localhost seccomp profile is required. Still non-root, drop: ["ALL"], never privileged.
  • Node: Kubernetes user-namespace support. The userns AppArmor sysctl at 0, where the image enables it. /dev/kvm at mode 0666.
  • Dropped: the supplementalGroups kvm-gid grant. The user namespace maps the device to 65534, so the grant can't apply.
  • Open questions: OQ-2 resolves to shipping the seccomp profile. OQ-6 adds a custom AppArmor profile as an optional R3 follow-up. OQ-3 notes a per-pod-mode device plugin as untested.
  • R7: stays open until a real-node rerun.

spike-findings.md now points at the adopted shape. Stacked on the findings PR.

Verification

  • Two review rounds. The second round's one finding is fixed.
  • rumdl check is clean.

Risks

None. Docs only.

Compatibility

No runtime change. R3 and R4 encode this spec.

Documentation

This PR is the design record update.

Refs RIG-4615, RIG-3723

R7's VM run showed the privilege shape as written does not boot. Per the
ruling, the pod now runs user-namespaced with unmasked /proc, AppArmor
unconfined and the Localhost seccomp profile. Nodes provide user-namespace
support, the userns sysctl where the image enables it, and /dev/kvm 0666.
The kvm supplementalGroups grant is dropped because the user namespace
makes it ineffective. OQ-2 resolves to shipping the profile; OQ-6 adds a
custom AppArmor profile as an R3 follow-up. A real-node R7 rerun remains.

Spec-impact: none
Refs RIG-4615, RIG-3723

Co-authored-by: Matt Wilkinson <matt@rigel.build>
@linear-code

linear-code Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

RIG-4615

RIG-3723

@rigel-mintaka rigel-mintaka changed the title docs(runner): adopt the user-namespaced pod shape from R7 (RIG-4615) docs(runner): adopt the user-namespaced pod shape from R7 Oct 6, 2026
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

Compass engineering docs preview: https://compass-managed-rig-4615-pri.compass-eng-docs.pages.dev

Deployed from compass-managed/rig-4615-privilege-shape-a at 061b4a2.

Changed pages:

@mattwilkinsonn

Copy link
Copy Markdown
Contributor

/trunk merge

@trunk-io

trunk-io Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

😎 Stack merged successfully - details.

@trunk-io
trunk-io Bot merged commit e65e932 into main Oct 7, 2026
18 checks passed
@trunk-io
trunk-io Bot deleted the compass-managed/rig-4615-privilege-shape-a branch October 7, 2026 02:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants