gitlab_runner: try to protect the VM runner kernel from the root user
Enable kernel lockdown in confidentiality
mode to restrict how the root user can interact with the kernel.
See https://wiki.archlinux.org/title/Security#Kernel_lockdown_mode and https://man.archlinux.org/man/kernel_lockdown.7.
This may or may not improve ~security.
Merge request reports
Activity
- Resolved by nl6720
What is the threat model?
added 7 commits
-
50434793...30b0520e - 6 commits from branch
archlinux:master
- c7d2dfa6 - gitlab_runner: try to protect the VM runner kernel from the root user
-
50434793...30b0520e - 6 commits from branch
added 1 commit
- 737ee368 - gitlab_runner: try to protect the VM runner kernel from the root user
mentioned in commit klausenbusk/arch-boxes@4b41267a
- Resolved by nl6720
Deployed and seems to work: https://gitlab.archlinux.org/klausenbusk/arch-boxes/-/jobs/82888#L334. Can you rebase? :)
added 33 commits
-
737ee368...4d8dfb6a - 32 commits from branch
archlinux:master
- ab612463 - gitlab_runner: try to protect the VM runner kernel from the root user
-
737ee368...4d8dfb6a - 32 commits from branch
mentioned in commit 6d94e7b9