Skip to content

docs(security-validation): cross-platform validation report — AKS, local-k8s, docker - #368

Merged
Pal Lakatos-Toth (pallakatos) merged 2 commits into
mainfrom
docs/security-validation-2026-05-30
May 31, 2026
Merged

Pal Lakatos-Toth (pallakatos) merged 2 commits into
mainfrom
docs/security-validation-2026-05-30

Conversation

@pallakatos

Copy link
Copy Markdown
Collaborator

Summary

Comprehensive cross-platform security & runtime validation report, mapped to the 9-layer model in docs/security.md.

User asked for: "detailed analysis, error log checks everywhere, all 3 different envs are up — ensure nothing is broken, the outputs are not hallucinated, real foundry calls used, in case of AKS proper entra agent id and rbac used, CRD apply, attestation, sign logs etc."

Headline results

Property AKS local-k8s docker
9/9 verify checks ✅ ✅ ✅
Real Foundry calls (HTTP 200 sample) ✅ ✅ ✅
Per-sandbox Entra Agent ID ✅ (4 unique appIds) n/a (anonymous tier) n/a (anonymous tier)
CRDs applied + content-digest signed ✅ sha256:e8b22768… ✅ same n/a (no controller)
Container hardening per layer 3 ✅ ✅ ⚠️ NET_ADMIN on parent (Finding #3)
seccomp kars-strict ✅ ✅ ✅
Agent does not see Azure creds ✅ ✅ ⚠️ macOS Docker Desktop only (Finding #1)

Findings (no fixes applied, plan in §10 of the report)

None of these block the AKS verified-tier security story documented in docs/security.md.

File added

docs/internal/security-validations/2026-05-30-all-platforms-validation.md (212 lines, 11 evidence tables)

…cal-k8s, docker

Comprehensive security & runtime validation across all three deploy
modes, mapped to the 9-layer model in docs/security.md.

Per-platform live evidence collected:
- CRD presence + InferencePolicyCompiled/ToolPolicyCompiled/EgressAllowlistCompiled digests
- Pod securityContext (UID, readOnlyRootFilesystem, capabilities, seccomp)
- Workload Identity / Entra Agent ID federated token plumbing (AKS only)
- entra-auth-sidecar token issuance + per-sandbox pinned_agent_id
- Output authenticity (real Foundry calls, real URLs verified via HTTP 200)
- AGT mesh KNOCK + E2E channel establishment per agent
- Native AGT governance modules (PolicyEngine, AuditLogger, etc.)
- NetworkPolicy enforcement + egress-guard caps
- 9-check verify run on every platform

Verified all three platforms 9/9 PASS with current main checks.py.

Findings (no fixes applied — tracked for separate PRs):
  #1 HIGH (docker macOS) — UID 1000 reads Foundry API key (Docker Desktop UID virtualization)
  #2 HIGH (local-k8s) — API key + GitHub token in plaintext pod env (should be secretKeyRef)
  #3 MEDIUM (docker) — NET_ADMIN on persistent parent container (vs init-only in K8s mode)
  #4 MEDIUM (AKS, local-k8s) — blocklist-refresh CronJob failing every 6h (VAP collision)
  #5 MEDIUM (all) — audit JSONL not persisted (RO root FS, no emptyDir mount)
  #6 LOW (AKS) — AllowlistVerified=False on execbrief (inline endpoints, no cosign attestation)
  #7 LOW (AKS) — TrustGraph router-side enforcement not active (documented roadmap)

All findings include a remediation plan in §10. None block the AKS
verified-tier security story documented in docs/security.md.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Pal Lakatos-Toth <pallakatos@github.com>
@github-actions

github-actions Bot commented May 30, 2026 •

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

…tainers

Adds detailed per-container env-var analysis answering the question:
'do AKS containers have more env variables than they should?'

Per-container inventories with full categorization:
- openclaw container: 42 vars in 8 categories
- inference-router container: 54 vars (router-only paths/toggles)

Three additional findings on env-var hygiene:
  #8 LOW — OPENCLAW_GATEWAY_TOKEN exposed via env (should be file mount)
  #9 LOW — enableServiceLinks=true leaks internal cluster IPs (16 env vars)
  #10 LOW — possibly-redundant Foundry/Mesh-auth env vars on openclaw

Headline confirmations:
  ✅ NO AZURE_OPENAI_API_KEY on either AKS container
  ✅ NO COPILOT_GITHUB_TOKEN on either AKS container
  ✅ Federated identity token mounted RO, never as env value
  ✅ Auth mode 'shared entra-auth-sidecar fail-closed, no WI/IMDS/API-key fallback'

Comparison table across all 3 platforms included.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Pal Lakatos-Toth <pallakatos@github.com>
@pallakatos
Pal Lakatos-Toth (pallakatos) merged commit b6b365f into main May 31, 2026
32 checks passed
@pallakatos
Pal Lakatos-Toth (pallakatos) deleted the docs/security-validation-2026-05-30 branch May 31, 2026 04:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant