Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

disabling stdio in pause container #10

Merged
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions src/confcom/azext_confcom/security_policy.py
Original file line number Diff line number Diff line change
Expand Up @@ -51,11 +51,13 @@ def __init__(
rego_fragments: Any = config.DEFAULT_REGO_FRAGMENTS,
existing_rego_fragments: Any = None,
debug_mode: bool = False,
disable_stdio: bool = False,
) -> None:
self._docker_client = None
self._rootfs_proxy = None
self._policy_str = None
self._policy_str_pp = None
self._disable_stdio = disable_stdio
self._fragments = rego_fragments
self._existing_fragments = existing_rego_fragments
if debug_mode:
Expand Down Expand Up @@ -374,6 +376,9 @@ def _policy_serialization(self, use_json, pretty_print=False) -> str:
if not is_sidecars:
# add in the default containers that have their hashes pre-computed
policy += config.DEFAULT_CONTAINERS
if self._disable_stdio:
for container in policy:
container[config.POLICY_FIELD_CONTAINERS_ALLOW_STDIO_ACCESS] = False

# default output is rego policy
if use_json:
Expand Down Expand Up @@ -632,6 +637,7 @@ def load_policy_from_arm_template_str(
config.ACI_FIELD_CONTAINERS: containers,
config.ACI_FIELD_TEMPLATE_CCE_POLICY: existing_containers,
},
disable_stdio=disable_stdio,
rego_fragments=rego_fragments,
# fallback to default fragments if the policy is not present
existing_rego_fragments=fragments,
Expand Down