grantseltzer/karn
Simplifying Seccomp enforcement in containerized or non-containerized apps
GoMPL-2.0
Issues
- 0
Add subcommand for listing system calls a specific entitlement corresponds to
#37 opened by grantseltzer - 0
Add chmod entitlement
#36 opened by grantseltzer - 0
Proposal: A command like sudo which would run a program using specified entitlements (or linux capabilities?)
#35 opened by grantseltzer - 0
Update man page
#29 opened by grantseltzer - 1
Library package for taking a Karn declarations to run processes with the outputted seccomp/apparmor configurations
#6 opened by grantseltzer - 0
- 0
Docs with full examples
#9 opened by grantseltzer - 0
- 0
- 0
Set up build bot
#12 opened by grantseltzer - 0
Output options for installing apparmor/seccomp profiles for use in various container runtimes
#5 opened by grantseltzer - 0
Cut 0.1 release semver
#19 opened by grantseltzer - 4
Need validation for spec fields
#1 opened by grantseltzer - 1
- 0
- 0
Add example CLI commands to README
#34 opened by grantseltzer - 5
Install make step
#16 opened by grantseltzer - 0
Add documentation for individual entitlements and introduce command for printing it
#32 opened by grantseltzer - 3
- 0
fix lint and gofmt issues
#24 opened by grantseltzer - 0
- 1
When a syscall is specified, if there's a corresponding CAP it should add that to the apparmor prof
#4 opened by grantseltzer - 1
- 1
- 1
If nothing is specified, generate produces error for missing default action
#17 opened by grantseltzer - 0
Reverse default seccomp/apparmor profiles into declarations, have them auto included
#15 opened by grantseltzer - 1
Create defaults for unspecified fields
#14 opened by grantseltzer - 0
- 0
- 0
- 0
Check syscall duplicates on add
#7 opened by grantseltzer - 0
Unit tests
#3 opened by grantseltzer