Repository navigation
feat(runner): render the Runner DaemonSet and KVM device request - #1773
Draft
rigel-mintaka wants to merge 1 commit into
Draft
rigel-mintaka wants to merge 1 commit into
rigel-mintaka wants to merge 1 commit into
Conversation
This was referenced Oct 6, 2026
|
Compass engineering docs preview: https://compass-managed-rig-3724-run.compass-eng-docs.pages.dev Deployed from Changed pages: |
mattwilkinsonn
added this pull request to stack #1822
October 7, 2026 00:20
Base automatically changed from
compass-managed/rig-4615-privilege-shape-a
to
main
October 7, 2026 02:07
|
Merging to
After your PR is submitted to the merge queue, this comment will be automatically updated with its status. If the PR fails, failure details will also be posted here |
…-3724, RIG-3725) Add tools/runner-manifests: a values-driven renderer for the Runner's ServiceAccount, PriorityClass and DaemonSet, encoding the privilege shape from the containerization record. The pod is user-namespaced with unmasked /proc, AppArmor unconfined, the Localhost seccomp profile (now checked in), zero capabilities and no supplementalGroups. It requests /dev/kvm through the operator-named device-plugin resource, mounts exactly two host trees, and sizes memory to guest capacity. Render tests check each security field by mutation, the sizing formula, digest-only images and uid parity with the image. Spec-impact: none Refs RIG-3724, RIG-3725 Co-authored-by: Matt Wilkinson <matt@rigel.build>
rigel-mintaka
force-pushed
the
compass-managed/rig-3724-runner-manifests
branch
from
October 7, 2026 02:48
9eb3787 to
582f8b8
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds
tools/runner-manifests. It renders the Runner's ServiceAccount, PriorityClass and DaemonSet from an operator values file, following the containerization record's privilege shape and object contract. It covers R3 (manifests) and R4 (the KVM device request).hostUsers: false); unmasked/proc; AppArmor unconfined;Localhostseccomp;drop: ["ALL"]; non-root uid 65532, the same uid as the image. Noprivileged, nosupplementalGroups./dev/kvmcomes through the operator-named device-plugin extended resource. No/devhostPath is mounted.maxUnavailableis 1.Draft. Two things gate this PR:
Verification
bun testpasses: 11 tests, 265 assertions. Each security field is checked by mutation, plus the sizing boundaries, digest-only images, the seccomp shape and uid parity.tscandbiomeare clean.Risks
None at runtime. Nothing applies these manifests yet.
Compatibility
New tool, plus one comment in the Dockerfile.
Documentation
The README lists the node prerequisites.
Refs RIG-3724, RIG-3725