Skip to content
Snippets Groups Projects

gitlab_runner: try to protect the VM runner kernel from the root user

Merged nl6720 requested to merge nl6720/infrastructure:vm_runner-lockdown into master
All threads resolved!

Enable kernel lockdown in confidentiality mode to restrict how the root user can interact with the kernel.

See https://wiki.archlinux.org/title/Security#Kernel_lockdown_mode and https://man.archlinux.org/man/kernel_lockdown.7.

This may or may not improve ~security.

Merge request reports

Loading
Loading

Activity

Filter activity
  • Approvals
  • Assignees & reviewers
  • Comments (from bots)
  • Comments (from users)
  • Commits & branches
  • Edits
  • Labels
  • Lock status
  • Mentions
  • Merge request status
  • Tracking
Please register or sign in to reply
Loading