Skip to content

feat(runner): carry no egress policy on a backend that cannot enforce one - #1145

Merged
trunk-io[bot] merged 3 commits into
compass-service-owner/rig-3512-egress-unenforcedfrom
compass-service-owner/rig-3512-egress-runner-profile
Sep 13, 2026
Merged

feat(runner): carry no egress policy on a backend that cannot enforce one#1145
trunk-io[bot] merged 3 commits into
compass-service-owner/rig-3512-egress-unenforcedfrom
compass-service-owner/rig-3512-egress-runner-profile

Conversation

@rigel-mintaka

@rigel-mintaka rigel-mintaka commented Sep 12, 2026

Copy link
Copy Markdown
Contributor

This PR is part of a stack containing 10 PRs:

  1. main
  2. feat(runtime): add the host-process WorkloadRuntime backend (RIG-3512) #1120
  3. feat(runner): derive the agent uid from the Runner's euid on the host backend (RIG-3512) #1125
  4. feat(runner): deliver the agent socket and config by path on the host backend (RIG-3512) #1135
  5. feat(runtime): distinguish a configured egress policy from an unset one #1142
  6. feat(runtime): refuse an egress policy the host tier cannot enforce #1143
  7. "feat(runner): carry no egress policy on a backend that cannot enforce one" (this PR)
  8. feat(runner): report the runtime tier and egress posture per session #1148
  9. feat(cli): show the runtime tier and egress posture per session #1153
  10. feat(ui): mark each agent's runtime tier and egress posture #1154
  11. feat(runner): declare the runtime tier and egress posture at enrollment #1156

The operator's allowlist flag parses into a real policy even when empty, so a
host-tier Runner would have handed provision a configured policy and failed
every launch. Resolution now sits beside the uid probe, keyed off the same
capability seam: an unenforceable backend carries the zero-value policy.

An explicit allowlist is treated differently. It is operator intent to confine
egress, and this tier cannot, so startup fails and names the remedy rather than
discarding the request silently.

@linear-code

linear-code Bot commented Sep 12, 2026

Copy link
Copy Markdown

RIG-3512

@rigel-mintaka
rigel-mintaka added this pull request to stack #1126 September 12, 2026 13:25
@github-actions

github-actions Bot commented Sep 12, 2026

Copy link
Copy Markdown

Compass engineering docs preview: https://compass-service-owner-rig-35-x6nu.compass-eng-docs.pages.dev

Deployed from compass-service-owner/rig-3512-egress-runner-profile at 7caeb60.

… one

The operator's allowlist flag parses into a real policy even when empty, so a
host-tier Runner would have handed provision a configured policy and failed
every launch. Resolution now sits beside the uid probe, keyed off the same
capability seam: an unenforceable backend carries the zero-value policy.

An explicit allowlist is treated differently. It is operator intent to confine
egress, and this tier cannot, so startup fails and names the remedy rather than
discarding the request silently.
The pair read EgressArmed and EgressUnenforcedPosture — one carrying the type
suffix, the other not — in a value set the design expects to grow. The suffix
was avoiding visual overlap with the EgressUnenforced marker method, which Go
namespacing never required. Both are now prefixed; the rendered strings are
unchanged.

Also records why the unenforced case is tested first (a both-marker backend must
refuse, not silently skip), marks the deliberately empty self-arming arm, warns
that a decorator must re-expose the marker, and closes two test gaps: credentials
on the unenforced path, and a marker answering false reading as armed.
The comment claimed the order prevents reporting armed, but EgressPosture asks
the marker directly and is independent of it. What the order governs is refusing
a policy instead of silently dropping it on the self-arm branch.

The test fake is renamed to match what it became when its answer turned into a
field: it parametrizes the marker rather than always being unenforced.
@rigel-mintaka
rigel-mintaka force-pushed the compass-service-owner/rig-3512-egress-runner-profile branch from 386afb9 to 7caeb60 Compare September 12, 2026 19:37
@trunk-io
trunk-io Bot merged commit 332c075 into main Sep 13, 2026
16 of 26 checks passed
@trunk-io
trunk-io Bot deleted the compass-service-owner/rig-3512-egress-runner-profile branch September 13, 2026 00:29
@trunk-io

trunk-io Bot commented Sep 13, 2026

Copy link
Copy Markdown

This pull request was merged into main as part of stacked PR 1156.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants