Skip to content

Feature: per-socket (per-instance) exec allowlist #65

Description

@abienkowski

Is your feature request related to a problem?

Exec is hard-coded as denied in all three implementations: POST /containers/<name>/exec and POST /exec/<id>/start. No policy or configuration can enable it. Some deployments may legitimately want callers of one socket to run a limited set of commands in their containers, for example a health or debug command, while other sockets stay locked down.

Today's model:

So "per socket" means per proxy instance.

Describe the solution (for future consideration; not designed yet)

An instance-level setting, as a flag or a config file next to the policies, that allows exec under explicit limits. Open questions:

  • Command allowlist, matched on Cmd in the exec-create body, using the same flag/value-pattern machinery as CmdGate. Is a plain on/off switch ever acceptable?
  • Container scope: restrict to containers created from images matching a policy's allowed_image_prefixes, or to named containers. This needs the daemon's container-to-image mapping at exec time.
  • Fields to force or deny: Privileged: true (always deny?), User (force it?), Env, Tty/AttachStdin.
  • POST /exec/<id>/start, /resize, and GET /exec/<id>/json: start can only be allowed for exec instances this proxy created and approved, which means tracking exec IDs. Inspect leaks other users' exec command lines (verified in Routing parity: TS path-wide exec deny; Go matchEndpoint accepts endpoint subpaths #49: ExecIDs from container inspect, then GET /exec/<id>/json, shows the full arguments including inline secrets).
  • Spec: a new invariant in spec/docker_socket_policy.qnt, replacing "execContainer unconditionally returns false", such as "every executed command matches the instance allowlist".
  • Audit: log every exec create and start, with the command.

Describe alternatives

Which implementation(s) would this affect?

  • All (Go, Rust, TypeScript, Quint specification)

Additional context

Raised while converging the exec deny rules in #49. #49 keeps exec denied and only fixes the cross-language differences.

Activity

  1. added
    Type: FeatureAdded to issues and PRs to identify that the change is a new feature.
    on Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type: FeatureAdded to issues and PRs to identify that the change is a new feature.

    Type

    No type

    Fields

    Priority

    None yet

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions