Skip to content

Restrict network access of the executed tool #1049

@petertrr

Description

@petertrr

(https://gvisor.dev/docs/architecture_guide/security/)

A sandbox is not a substitute for a secure architecture.

save-cloud services should either be able to authorize against each other (including agent), or the tested tool should have restricted network access (i.e. being able to communicate only with targets outside of cluster IP range)

Plan:

Metadata

Metadata

Assignees

Labels

authIssues related to authentication, authorization and overall service security

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions