chore(security): document Kubernetes runtime RBAC (#3328)

Signed-off-by: Drew Newberry <anewberry@nvidia.com>
This commit is contained in:
Drew Newberry
2026-09-14 22:11:42 +00:00
committed by GitHub
parent 42e9bcf2b0
commit 2d5db4c5bd
+10
View File
@@ -32,3 +32,13 @@ misconfigurations:
- "**/deployment.yaml"
statement: >-
Images come from ghcr.io/nvidia/openshell, this project's own registry.
# The Kubernetes compute driver creates its runtime infrastructure and the
# per-sandbox outer egress fence in the configured sandbox namespace.
- id: KSV-0056
paths:
- "**/role.yaml"
statement: >-
The namespace-scoped gateway role can create Services and NetworkPolicy
resources so the compute driver can connect each sandbox runtime to its
supervisor while denying direct workload egress.