feat(safe-exec): template safe-exec postures and wire ROE hosts - #26
Open
pshickeydev wants to merge 1 commit into
Open
pshickeydev wants to merge 1 commit into
pshickeydev wants to merge 1 commit into
Conversation
Contributor
|
@pshickeydev please see my comments on openshift/traust-engine#8 |
pshickeydev
force-pushed
the
config/safe-exec-curl-host-policy
branch
from
September 14, 2026 21:59
386cc72 to
a8e54ab
Compare
Make restricted validation usable for approved cluster endpoints with scoped discovery, managed tunnels, and explicit session handling while keeping execution state isolated and authorization failures closed.
pshickeydev
force-pushed
the
config/safe-exec-curl-host-policy
branch
from
September 15, 2026 00:24
a8e54ab to
f33b98f
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Included changes
--allowed-hostto the utility CLI and display posture in profile listings.http_targetsand per-clusterhttp_discoverypolicy. Route namespaces, resource names, approved domains, node networks, and credential permissions remain engagement data rather than permissions inferred from findings.Boundaries
The engine host gate is not port/path isolation or a DNS-rebinding defense. Resource-specific grants are enforced by structured resolution, not by the raw command-text host list. Operator-approved discovery boundaries remain necessary. Interactive console OAuth login is not implemented; unsatisfied authenticated-session preconditions remain inconclusive.
Verification
git diff --checkpassed.Merge prerequisites
Description prepared with AI assistance.