Skip to content

feat(runner): render the Runner DaemonSet and KVM device request - #1773

Draft
rigel-mintaka wants to merge 1 commit into
mainfrom
compass-managed/rig-3724-runner-manifests
Draft

rigel-mintaka wants to merge 1 commit into
mainfrom
compass-managed/rig-3724-runner-manifests

Conversation

@rigel-mintaka

@rigel-mintaka rigel-mintaka commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Adds tools/runner-manifests. It renders the Runner's ServiceAccount, PriorityClass and DaemonSet from an operator values file, following the containerization record's privilege shape and object contract. It covers R3 (manifests) and R4 (the KVM device request).

  • Pod security: user-namespaced pod (hostUsers: false); unmasked /proc; AppArmor unconfined; Localhost seccomp; drop: ["ALL"]; non-root uid 65532, the same uid as the image. No privileged, no supplementalGroups.
  • R4: /dev/kvm comes through the operator-named device-plugin extended resource. No /dev hostPath is mounted.
  • Mounts and sizing: exactly two hostPath trees. Memory request equals the limit, sized as sessions × guest RAM + overhead. Termination grace is sized to the reap budget, and maxUnavailable is 1.
  • Image and API access: the image must be a digest reference. The ServiceAccount does not mount an API token.
  • Seccomp profile: checked in as an OCI profile. Not yet minimized.
  • Record fix: the record now says the Runner pushes metrics over OTLP, so there is no scrape annotation.

Draft. Two things gate this PR:

  • the R7 real-node rerun;
  • per-node token delivery. A shared Secret enrolls one node only; the README states this.

Verification

  • bun test passes: 11 tests, 265 assertions. Each security field is checked by mutation, plus the sizing boundaries, digest-only images, the seccomp shape and uid parity.
  • tsc and biome are clean.
  • The rendered YAML parses back to 3 objects.

Risks

None at runtime. Nothing applies these manifests yet.

Compatibility

New tool, plus one comment in the Dockerfile.

Documentation

The README lists the node prerequisites.

Refs RIG-3724, RIG-3725

@linear-code

linear-code Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

RIG-3725

RIG-3724

@rigel-mintaka rigel-mintaka changed the title feat(runner): render the Runner DaemonSet and KVM device request (RIG-3724, RIG-3725) feat(runner): render the Runner DaemonSet and KVM device request Oct 6, 2026
@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Compass engineering docs preview: https://compass-managed-rig-3724-run.compass-eng-docs.pages.dev

Deployed from compass-managed/rig-3724-runner-manifests at 582f8b8.

Changed pages:

@mattwilkinsonn
mattwilkinsonn added this pull request to stack #1822 October 7, 2026 00:20
Base automatically changed from compass-managed/rig-4615-privilege-shape-a to main October 7, 2026 02:07
@trunk-io

trunk-io Bot commented Oct 7, 2026

Copy link
Copy Markdown

Merging to main in this repository is managed by Trunk.

  • To merge this pull request, check the box to the left or comment /trunk merge below.

After your PR is submitted to the merge queue, this comment will be automatically updated with its status. If the PR fails, failure details will also be posted here

…-3724, RIG-3725)

Add tools/runner-manifests: a values-driven renderer for the Runner's
ServiceAccount, PriorityClass and DaemonSet, encoding the privilege shape
from the containerization record. The pod is user-namespaced with
unmasked /proc, AppArmor unconfined, the Localhost seccomp profile (now
checked in), zero capabilities and no supplementalGroups. It requests
/dev/kvm through the operator-named device-plugin resource, mounts
exactly two host trees, and sizes memory to guest capacity. Render tests
check each security field by mutation, the sizing formula, digest-only
images and uid parity with the image.

Spec-impact: none
Refs RIG-3724, RIG-3725

Co-authored-by: Matt Wilkinson <matt@rigel.build>
@rigel-mintaka
rigel-mintaka force-pushed the compass-managed/rig-3724-runner-manifests branch from 9eb3787 to 582f8b8 Compare October 7, 2026 02:48

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant