You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Exec is hard-coded as denied in all three implementations: POST /containers/<name>/exec and POST /exec/<id>/start. No policy or configuration can enable it. Some deployments may legitimately want callers of one socket to run a limited set of commands in their containers, for example a health or debug command, while other sockets stay locked down.
Policies are per service and are selected by image name only on POST /containers/create. Exec requests carry no image, so a policy cannot be selected for them.
So "per socket" means per proxy instance.
Describe the solution (for future consideration; not designed yet)
An instance-level setting, as a flag or a config file next to the policies, that allows exec under explicit limits. Open questions:
Command allowlist, matched on Cmd in the exec-create body, using the same flag/value-pattern machinery as CmdGate. Is a plain on/off switch ever acceptable?
Container scope: restrict to containers created from images matching a policy's allowed_image_prefixes, or to named containers. This needs the daemon's container-to-image mapping at exec time.
Fields to force or deny: Privileged: true (always deny?), User (force it?), Env, Tty/AttachStdin.
POST /exec/<id>/start, /resize, and GET /exec/<id>/json: start can only be allowed for exec instances this proxy created and approved, which means tracking exec IDs. Inspect leaks other users' exec command lines (verified in Routing parity: TS path-wide exec deny; Go matchEndpoint accepts endpoint subpaths #49: ExecIDs from container inspect, then GET /exec/<id>/json, shows the full arguments including inline secrets).
Spec: a new invariant in spec/docker_socket_policy.qnt, replacing "execContainer unconditionally returns false", such as "every executed command matches the instance allowlist".
Audit: log every exec create and start, with the command.
Describe alternatives
Keep exec denied everywhere (status quo). Simplest and safest. Users who need exec use the daemon socket directly, outside the proxy's guarantees.
Per-policy setting. Not workable: exec requests carry no image, so there is no policy to select (see above).
Is your feature request related to a problem?
Exec is hard-coded as denied in all three implementations:
POST /containers/<name>/execandPOST /exec/<id>/start. No policy or configuration can enable it. Some deployments may legitimately want callers of one socket to run a limited set of commands in their containers, for example a health or debug command, while other sockets stay locked down.Today's model:
POST /containers/create. Exec requests carry no image, so a policy cannot be selected for them.So "per socket" means per proxy instance.
Describe the solution (for future consideration; not designed yet)
An instance-level setting, as a flag or a config file next to the policies, that allows exec under explicit limits. Open questions:
Cmdin the exec-create body, using the same flag/value-pattern machinery as CmdGate. Is a plain on/off switch ever acceptable?allowed_image_prefixes, or to named containers. This needs the daemon's container-to-image mapping at exec time.Privileged: true(always deny?),User(force it?),Env,Tty/AttachStdin.POST /exec/<id>/start,/resize, andGET /exec/<id>/json: start can only be allowed for exec instances this proxy created and approved, which means tracking exec IDs. Inspect leaks other users' exec command lines (verified in Routing parity: TS path-wide exec deny; Go matchEndpoint accepts endpoint subpaths #49:ExecIDsfrom container inspect, thenGET /exec/<id>/json, shows the full arguments including inline secrets).spec/docker_socket_policy.qnt, replacing "execContainerunconditionally returns false", such as "every executed command matches the instance allowlist".Describe alternatives
Which implementation(s) would this affect?
Additional context
Raised while converging the exec deny rules in #49. #49 keeps exec denied and only fixes the cross-language differences.