Conversation
…ilable Some environments (notably Docker Desktop with Kubernetes) run the agent container in a private cgroup namespace where /proc/self/cgroup reports "0::/". leash-entry then cannot emit a scopable /leash/cgroup-path, and leashd previously FATALed at startup with "cgroup path required (set --cgroup)" before any enforcement could start. Mirror the cgroup-unavailable network fallback (#66): degrade gracefully instead of failing. - cmd/leash-entry/main.go: when no scopable cgroup is found, log a WARNING and continue (do not abort the container) so leashd can start. - internal/leashd/runtime.go: preFlight allows an empty cgroup path (warns, proxy-only); a non-empty path is still validated. - internal/lsm/manager.go: UpdateRuntimeRules no-ops without a cgroup, so no cgroup-scoped BPF-LSM programs are attached (kernel layer disabled). - internal/assets/apply-{iptables,ip6tables,nftables}.sh: with no target cgroup, still isolate the control plane via a namespace-wide block (same boundary as the cgroup fallback), so degraded mode stays safe. The L7 MITM proxy (hostname/header/MCP) is unaffected and keeps enforcing, preserving defense-in-depth minus the kernel layer. Closes #67
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
On Docker Desktop with Kubernetes the agent container runs in a private cgroup namespace where
/proc/self/cgroupreports0::/.leash-entry'semitCgroupPath()skips/as invalid, so/leash/cgroup-pathis never written, andleashdthen FATALs at startup withcgroup path required (set --cgroup)— before any enforcement starts.This is separate from #66 (which fixed the
xt_cgroupnetwork path): even with that fix, leashd can't start on Docker Desktop K8s because cgroup-path discovery fails first.This change makes leash degrade gracefully instead of failing, following the same philosophy as #66 (cgroup unavailable → fall back + WARNING, never FATAL, preserve the boundary):
cmd/leash-entry/main.go— when no scopable cgroup is found, log aWARNINGand continue (don't abort the container) so leashd can start.internal/leashd/runtime.go—preFlightallows an empty cgroup path (proxy-only, warns); a non-empty path is still validated as before.internal/lsm/manager.go—UpdateRuntimeRulesno-ops when there is no cgroup, so no cgroup-scoped BPF-LSM programs are attached (they'd have nothing valid to scope to).internal/assets/apply-{iptables,ip6tables,nftables}.sh— when there is no target cgroup, still isolate the control plane with a namespace-wide block (the same boundary as the existing network: fall back to blanket port block when cgroup isolation unavailable #66 cgroup fallback), so degraded mode stays safe.Net: the kernel LSM layer (file/exec/connect) is disabled when the cgroup is undiscoverable, but the L7 MITM proxy (hostname/header/MCP) keeps enforcing and the control plane stays isolated — defense-in-depth minus the kernel layer, with a clear warning, rather than a hard failure.
Design note
This follows #66's pattern: automatic fallback +
WARNING, no new flag. Since degraded mode is a reduction in enforcement, I'm happy to instead gate it behind an explicit opt-in flag (e.g.--allow-no-cgroup) if you'd prefer that posture.Validation
go build+go vetclean forinternal/lsm,internal/leashd,cmd/leash-entry.preFlightallows a missing cgroup. All 14 existingpreFlighttests still pass (non-empty invalid cgroup is still rejected).sh -nclean on all three netfilter scripts.Closes #67