Skip to content

Security Hardening and Docker Sandboxes - #12

Closed
joecklau wants to merge 11 commits into
mainfrom
feature/security_hardening
Closed

Security Hardening and Docker Sandboxes#12
joecklau wants to merge 11 commits into
mainfrom
feature/security_hardening

Conversation

@joecklau

Copy link
Copy Markdown
Contributor

Summary

  • Harden host-trust verification and runner lifecycle behavior across providers.
  • Add storage catalogs, preflight checks, external storage handling, and cleanup planning.
  • Improve image acquisition, artifact updates, Buildx progress, and runner-release workflows.
  • Refresh startup, configuration, provider, security, operations, and development documentation.
  • Add focused tests and a host-trust verification workflow.

Testing

  • Expanded unit and integration coverage across startup, configuration, storage, image, GitHub, and host-trust paths.
  • Added workflow-based host-trust verification.
  • Full validation status not provided in the supplied context.

joecklau and others added 11 commits July 22, 2026 11:24
- register Docker Sandboxes as the default provider with wizard, templates, policy, and validation
- separate provider integration, common pool lifecycle, image management, durable state, and storage responsibilities
- add capacity admission, owned-artifact inventory, status and prune previews, bounded retention, and exact cleanup
- preserve source and no-Go startup entry points with human-readable storage remediation
- align configuration, development guidance, provider documentation, wrappers, and contract tests
Share guided Catthehacker image onboarding and source-aware storage admission across Docker-capable providers.

Build and import verified Docker Sandboxes templates through an EPAR-owned Buildx builder with operational host trust, durable receipts, wrapper parity, tests, and updated documentation.
Add a host-wide exact resource catalog and reconcile owned provider artifacts during startup.

Stream verified Docker Sandboxes archives directly into the sandbox cache, track WSL and Tart activation, bound BuildKit and no-Go controller storage, and separate operational build trust from runner trust.

Improve long-running build progress, lifecycle diagnostics, and supervisor cleanup so temporary provider and GitHub failures do not retire healthy runners.
Persist per-config freshness checks with a weekly 07:00 local default and add an explicit image update command.

Resolve exact Actions runner assets, coordinate scheduled pool maintenance across providers, and update onboarding, status, tests, wrappers, examples, and documentation.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review this pull request because it exceeds the maximum number of lines (20,000). Try reducing the number of changed lines and requesting a review from Copilot again.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants