Repository navigation
docs(runner): adopt the user-namespaced pod shape from R7 - #1771
Merged
trunk-io[bot] merged 1 commit intoOct 7, 2026
Merged
trunk-io[bot] merged 1 commit into
trunk-io[bot] merged 1 commit into
Conversation
R7's VM run showed the privilege shape as written does not boot. Per the ruling, the pod now runs user-namespaced with unmasked /proc, AppArmor unconfined and the Localhost seccomp profile. Nodes provide user-namespace support, the userns sysctl where the image enables it, and /dev/kvm 0666. The kvm supplementalGroups grant is dropped because the user namespace makes it ineffective. OQ-2 resolves to shipping the profile; OQ-6 adds a custom AppArmor profile as an R3 follow-up. A real-node R7 rerun remains. Spec-impact: none Refs RIG-4615, RIG-3723 Co-authored-by: Matt Wilkinson <matt@rigel.build>
|
Compass engineering docs preview: https://compass-managed-rig-4615-pri.compass-eng-docs.pages.dev Deployed from Changed pages: |
rigel-mintaka
marked this pull request as ready for review
October 6, 2026 05:52
This was referenced Oct 6, 2026
mattwilkinsonn
added this pull request to stack #1822
October 7, 2026 00:20
mattwilkinsonn
approved these changes
Oct 7, 2026
Contributor
|
/trunk merge |
|
😎 Stack merged successfully - details. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR is part of a stack containing 3 PRs:
mainSummary
Amends the runner containerization record to adopt ruling A from the R7 spike.
hostUsers: falseandprocMount: Unmasked, so virtiofsd can mount/proc.appArmorProfile: Unconfined, so passt can remount. TheLocalhostseccomp profile is required. Still non-root,drop: ["ALL"], never privileged.0, where the image enables it./dev/kvmat mode0666.supplementalGroupskvm-gid grant. The user namespace maps the device to65534, so the grant can't apply.spike-findings.mdnow points at the adopted shape. Stacked on the findings PR.Verification
rumdl checkis clean.Risks
None. Docs only.
Compatibility
No runtime change. R3 and R4 encode this spec.
Documentation
This PR is the design record update.
Refs RIG-4615, RIG-3723