Skip to content

Add garden.no_new_privileges BOSH property#393

Open
plamen-bardarov wants to merge 1 commit into
cloudfoundry:developfrom
plamen-bardarov:enable-no-new-privileges
Open

Add garden.no_new_privileges BOSH property#393
plamen-bardarov wants to merge 1 commit into
cloudfoundry:developfrom
plamen-bardarov:enable-no-new-privileges

Conversation

@plamen-bardarov
Copy link
Copy Markdown

Summary

Adds garden.no_new_privileges BOSH property (default false) wired to Guardian's new --no-new-privileges flag. Operators can opt in to block setuid-based privilege escalation in application containers.

Backward Compatibility

Breaking Change? No

Wire new BOSH property to Guardian's --no-new-privileges flag via
config.ini. Defaults to false. Bump guardian submodule.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Development

Successfully merging this pull request may close these issues.

1 participant