feat(policy): allow non-root sandbox identities - #2785
Conversation
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
|
Label |
1 similar comment
|
Label |
|
Label |
1 similar comment
|
Label |
|
🌿 Preview your docs: https://nvidia-preview-pr-2785.docs.buildwithfern.com/openshell |
Summary
Allow explicitly selected sandbox workload UID/GID values across the full usable non-root Linux range instead of imposing an arbitrary system-user cutoff. Root and the invalid identity sentinel remain rejected, while the egress-exempt Kubernetes proxy UID retains its stricter infrastructure boundary.
This is a simpler alternative to #2737: it requires no new gateway configuration or min/max propagation.
Related Issue
Fixes #2707
Changes
1through42949672940) and the Linux invalid-ID sentinel (4294967295)1000Testing
mise run pre-commitpassestest:e2eandtest:e2e-kubernetes)mise run testpassesmise run cipasses in a clean system-gateway filesystem viewChecklist