aboutsummaryrefslogtreecommitdiffhomepage
path: root/internal/workflows/doc.go
diff options
context:
space:
mode:
Diffstat (limited to 'internal/workflows/doc.go')
-rw-r--r--internal/workflows/doc.go15
1 files changed, 13 insertions, 2 deletions
diff --git a/internal/workflows/doc.go b/internal/workflows/doc.go
index e34c59c8..b0dab000 100644
--- a/internal/workflows/doc.go
+++ b/internal/workflows/doc.go
@@ -67,6 +67,7 @@ Before starting the container, configure act_runner via config.yaml:
-v /var/lib/rosa:/rosa
--security-opt='unmask=/proc/*'
--cap-add=SYS_ADMIN
+ --cap-add=SYS_PTRACE
--device=/dev/kvm
--device=/dev/fuse
valid_volumes:
@@ -76,8 +77,9 @@ where /var/lib/rosa is the absolute pathname of the cache directory in the init
namespace. Setting MBF_POISON_OPEN enables cmd/mbf to run as root. It is also
a good idea here to set runner.capacity to reflect the capacity of the guest, so
jobs can be consumed quicker. Removing mount points covering /proc enables
-testing of cmd/hakurei. Exposing the fuse device and adding capability SYS_ADMIN
-enables testing of cmd/sharefs.
+testing of cmd/hakurei. Exposing the fuse device and adding capability
+CAP_SYS_ADMIN enables testing of cmd/sharefs. Adding capability CAP_SYS_PTRACE
+enables dumping seccomp filters via ptrace on the patched kernel.
Build a statically-linked cmd/mbf:
@@ -120,6 +122,15 @@ this can be achieved by the init script:
It is often a good idea to populate the cache from a mirror service before the
first workflow job is started and re-populate it after every cmd/mbf update.
+# Configuring the kernel
+
+In order to attach to the container process, the sysctl kernel.yama.ptrace_scope
+must be set to 0. After which, apply the patch test/sandbox/seccomp.patch to
+your kernel sources, compile and install the new kernel. Refer to
+https://wiki.alpinelinux.org/wiki/Custom_Kernel if the guest runs Alpine Linux.
+If running podman or docker as root, the patch is not required. Do not apply
+this patch on a system meant to be secure.
+
# Security
The design of Microsoft Github workflows is inherently insecure: it requires