Summary
Several unbounded data structures and non-idempotent operations could lead to resource exhaustion:
-
Pending approvals queue unbounded (blocklist.rs:56) — pending_approvals: Vec has no size limit. A noisy agent spamming egress fetch with random URLs could exhaust router memory.
-
iptables rules not idempotent (entrypoint.sh:44-65, reconciler.rs:666-700) — rules are appended without checking for duplicates. Pod restarts accumulate duplicate rules, degrading network performance.
Proposed Fixes
Bounded queue:
const MAX_PENDING: usize = 1000;
if pending.len() >= MAX_PENDING {
return Err("Pending approval queue full");
}
Idempotent iptables:
# In egress-guard init container:
iptables -F OUTPUT 2>/dev/null || true # Flush existing rules
iptables -A OUTPUT ... # Apply fresh
AGT's resource quota policy engine can enforce configurable limits on all bounded resources.
References
- blocklist.rs line 56
- entrypoint.sh lines 44-65
- reconciler.rs lines 666-700
Summary
Several unbounded data structures and non-idempotent operations could lead to resource exhaustion:
Pending approvals queue unbounded (blocklist.rs:56) —
pending_approvals: Vechas no size limit. A noisy agent spamming egress fetch with random URLs could exhaust router memory.iptables rules not idempotent (entrypoint.sh:44-65, reconciler.rs:666-700) — rules are appended without checking for duplicates. Pod restarts accumulate duplicate rules, degrading network performance.
Proposed Fixes
Bounded queue:
Idempotent iptables:
AGT's resource quota policy engine can enforce configurable limits on all bounded resources.
References