4 ms·
For those more familiar with Kubernetes and gVisor, would this allow me to build a CI/CD service that runs untrusted user code?
by conroy 7y ago
For those more familiar with Kubernetes and gVisor, would this allow me to build a CI/CD service that runs untrusted user code?
- snug 7y ago> gVisor provides a virtualized environment in order to sandbox untrusted containers. So yes
- raesene9 7y agoWell like all things in security, that kind of depends :) What gVisor does is provide a smaller attack surface to a containerized process, when compared with a "traditional" Docker container using standard Docker setup (you can, of course harden Docker containers considerably from base, if you are so inclined). However it doesn't affect anything outside of that interface so, for example, if your CI/CD process is running on a network that has other insecure services on them, then gVisor alone won't really help you if malicious code is executed inside a container allowing an attacker to start probing the environment from the perspective of that container.