Repository navigation
Expand file tree
/
Copy pathdocker-compose.yml
More file actions
52 lines (51 loc) · 2.23 KB
/
Copy pathdocker-compose.yml
File metadata and controls
52 lines (51 loc) · 2.23 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
# pasu-egress guarding a separate workload container (sidecar-style, one host).
#
# docker compose -f deploy/docker-compose.yml up --build
#
# `agent` is placed in a dedicated slice; `pasu-egress` attaches the kernel
# guard to that slice (so it filters the agent's egress, not its own). Only
# 1.1.1.1 is allowed — the agent's calls to anything else are dropped by the
# kernel. Watch the agent log: 1.1.1.1 succeeds, 1.0.0.1 is BLOCKED.
#
# cgroup driver = systemd here; `cgroup_parent` must end in `.slice`, and a
# dash in a slice name means NESTING: `pasu-guarded.slice` lands on the host at
# /sys/fs/cgroup/pasu.slice/pasu-guarded.slice. On a cgroupfs host use a plain
# name and adjust the attach path accordingly.
services:
agent:
image: docker.io/curlimages/curl:latest
# a stand-in agent: keeps trying an allowed and a blocked destination
command:
- sh
- -c
- |
while true; do
A=$$(curl -s --max-time 5 -o /dev/null -w '%{http_code}' http://1.1.1.1 || echo DROPPED)
B=$$(curl -s --max-time 5 -o /dev/null -w '%{http_code}' http://1.0.0.1 || echo DROPPED)
echo "agent: allowed(1.1.1.1)=$$A blocked(1.0.0.1)=$$B"
sleep 4
done
cgroup_parent: pasu-guarded.slice
restart: unless-stopped
pasu-egress:
image: pasu-egress:latest # built + tagged by `up --build`; reuse with `up --no-build`
build:
context: ..
dockerfile: deploy/Dockerfile
# runs in its OWN cgroup, attaches the guard to the agent's slice
privileged: true # or: cap_add [BPF, NET_ADMIN, PERFMON]
pid: host
cgroup: host # host cgroup NAMESPACE — without this the
# container only sees its own cgroup subtree
volumes:
- /sys/fs/cgroup:/sys/fs/cgroup # see the host cgroup hierarchy
depends_on:
- agent
entrypoint: ["/bin/sh", "-c"]
command:
- |
SLICE=/sys/fs/cgroup/pasu.slice/pasu-guarded.slice # systemd nests on the dash
echo "waiting for the agent cgroup at $$SLICE ..."
until [ -d "$$SLICE" ]; do sleep 1; done
exec pasu-egress --cgroup-path "$$SLICE" --allow 1.1.1.1
restart: unless-stopped