Skip to content

release: native CLI must select a matching manager image #84

Description

@sixtoad

Defect

The #82 source fix is merged and included in native-v0.3.3, but the released container-runtime stack never executes that fixed manager code. The tagged host CLI still defaults to an old upstream manager image. This is distinct from #82 path canonicalization: #82 works when the fixed manager binary is used.

Exact evidence

Credential-free reproduction on 2026-08-29:

The v0.3.3 help contract says its default is:

public.ecr.aws/s5i7k8t3/strongdm/leash:latest

That local image is digest sha256:2c08690eddda5bffe819bd43163fa5ace3c0b00cb87f4a2357ab9e504b9c0b6f, created 2026-03-11. Its embedded binary reports commit 5bf1c64, build 2026-03-11—months before #82 commit e13e588.

The exact combined-policy run exits in 6.9s before BME:

OCI runtime exec failed: ... proc/self/setgroups: ... permission denied
Interactive docker exec precheck failed; stopping containers.
docker exec precheck failed: exit status 126

The same non-root flow passes when the manager image is locally layered with the #82 binary. Therefore the released default manager selection, not #82 implementation, is the remaining defect.

Expected

A tagged native CLI and its manager must be one coherent release unit. Container-runtime execution must not silently pair new host orchestration with a stale upstream manager.

Acceptance

  • publish a versioned manager image containing the same release commit/eBPF sources as each native tag
  • make a tagged CLI select that matching tag or immutable digest by default
  • fail clearly before target bootstrap if CLI/manager contract versions are incompatible
  • preserve explicit --leash-image / LEASH_IMAGE overrides
  • release verification runs the exact combined file/exec/network policy with a named non-root target and fail-closed LSM; the command reaches the workload as that user
  • release notes identify the manager image tag/digest paired with the CLI

Related: #82 (source fix), #78 (blocked dogfood).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions