Skip to content

feat(runtime): distinguish a configured egress policy from an unset one - #1142

Merged
trunk-io[bot] merged 1 commit into
compass-service-owner/rig-3512-host-transportfrom
compass-service-owner/rig-3512-egress-configured
Sep 13, 2026
Merged

feat(runtime): distinguish a configured egress policy from an unset one#1142
trunk-io[bot] merged 1 commit into
compass-service-owner/rig-3512-host-transportfrom
compass-service-owner/rig-3512-egress-configured

Conversation

@rigel-mintaka

@rigel-mintaka rigel-mintaka commented Sep 12, 2026

Copy link
Copy Markdown
Contributor

This PR is part of a stack containing 10 PRs:

  1. main
  2. feat(runtime): add the host-process WorkloadRuntime backend (RIG-3512) #1120
  3. feat(runner): derive the agent uid from the Runner's euid on the host backend (RIG-3512) #1125
  4. feat(runner): deliver the agent socket and config by path on the host backend (RIG-3512) #1135
  5. "feat(runtime): distinguish a configured egress policy from an unset one" (this PR)
  6. feat(runtime): refuse an egress policy the host tier cannot enforce #1143
  7. feat(runner): carry no egress policy on a backend that cannot enforce one #1145
  8. feat(runner): report the runtime tier and egress posture per session #1148
  9. feat(cli): show the runtime tier and egress posture per session #1153
  10. feat(ui): mark each agent's runtime tier and egress posture #1154
  11. feat(runner): declare the runtime tier and egress posture at enrollment #1156

An empty allowlist is the strictest posture — pure default-deny — while a
zero-value policy means egress was never configured. The two were
indistinguishable, so a tier that cannot enforce egress had no way to refuse a
policy without also rejecting the tightest one.

AllowEgress now marks the policy configured, and Configured() exposes it.
Hosts() and NftScript() are untouched, so container arming is unchanged.

@linear-code

linear-code Bot commented Sep 12, 2026

Copy link
Copy Markdown

RIG-3512

@github-actions

github-actions Bot commented Sep 12, 2026

Copy link
Copy Markdown

Compass engineering docs preview: https://compass-service-owner-rig-35-elxl.compass-eng-docs.pages.dev

Deployed from compass-service-owner/rig-3512-egress-configured at ab53b80.

An empty allowlist is the strictest posture — pure default-deny — while a
zero-value policy means egress was never configured. The two were
indistinguishable, so a tier that cannot enforce egress had no way to refuse a
policy without also rejecting the tightest one.

AllowEgress now marks the policy configured, and Configured() exposes it.
Hosts() and NftScript() are untouched, so container arming is unchanged.
@rigel-mintaka
rigel-mintaka force-pushed the compass-service-owner/rig-3512-egress-configured branch from 13a2767 to ab53b80 Compare September 12, 2026 19:37
@trunk-io
trunk-io Bot merged commit 2108d46 into main Sep 13, 2026
16 of 26 checks passed
@trunk-io
trunk-io Bot deleted the compass-service-owner/rig-3512-egress-configured branch September 13, 2026 00:29
@trunk-io

trunk-io Bot commented Sep 13, 2026

Copy link
Copy Markdown

This pull request was merged into main as part of stacked PR 1156.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants