Files
OpenShell/examples/multi-agent-notepad/policy.template.yaml
Matthew Grossman bc14018cad feat(sandbox): use policy-first OCI image identity (#2509)
* feat(sandbox): use policy-first OCI image identity

Closes #2331

Preserve per-field policy omission, derive Docker and Podman fallbacks from the inspected immutable image, and resolve the final numeric identity before starting agent children.

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

* fix(sandbox): preserve declared process identities

Keep explicit policy values and OCI-declared names intact, defer passwd lookup until a primary GID is required, and refresh stale policy examples.

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

* fix(supervisor): reuse resolved OCI identity

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

* fix(supervisor): allow Linux pre-exec arguments

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

* fix(kubernetes): protect resolved sandbox identity

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

* fix(sandbox): prepare workspace for OCI identity

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

* refactor(sandbox): own only workspace root

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

* fix(sandbox): harden partial identity drops

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

* test(sandbox): scope OCI image e2e to Docker

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

* fix(sandbox): narrow OCI identity fallback scope

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

* test(podman): cover OCI identity launch

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

* fix(podman): exercise OCI fallback in E2E

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

---------

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>
2026-07-29 05:27:21 +00:00

68 lines
2.1 KiB
YAML

# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
# SPDX-License-Identifier: Apache-2.0
version: 1
filesystem_policy:
include_workdir: true
read_only: [/usr, /lib, /proc, /dev/urandom, /app, /etc, /var/log]
read_write: [/sandbox, /tmp, /dev/null]
landlock:
compatibility: best_effort
network_policies:
codex:
name: codex
endpoints:
- { host: api.openai.com, port: 443, protocol: rest, enforcement: enforce, access: full }
- { host: auth.openai.com, port: 443, protocol: rest, enforcement: enforce, access: full }
- { host: chatgpt.com, port: 443, protocol: rest, enforcement: enforce, access: full }
- { host: ab.chatgpt.com, port: 443, protocol: rest, enforcement: enforce, access: full }
binaries:
- { path: /usr/bin/codex }
- { path: /usr/bin/node }
- { path: "/usr/lib/node_modules/@openai/**" }
codex_plugins:
name: codex-plugins
endpoints:
- host: github.com
port: 443
protocol: rest
enforcement: enforce
rules:
- allow:
method: GET
path: "/openai/plugins.git/info/refs*"
- allow:
method: POST
path: "/openai/plugins.git/git-upload-pack"
binaries:
- { path: /usr/bin/git }
- { path: /usr/lib/git-core/git-remote-http }
- { path: "/usr/lib/node_modules/@openai/**" }
github_memory:
name: github-memory
endpoints:
- host: api.github.com
port: 443
protocol: rest
enforcement: enforce
rules:
- allow:
method: GET
path: "/repos/__OWNER__/__REPO__"
- allow:
method: GET
path: "/repos/__OWNER__/__REPO__/contents/runs/__RUN_ID__"
- allow:
method: GET
path: "/repos/__OWNER__/__REPO__/contents/runs/__RUN_ID__/**"
- allow:
method: PUT
path: "/repos/__OWNER__/__REPO__/contents/runs/__RUN_ID__/**"
binaries:
- { path: /usr/bin/curl }