How policies can block unexpected shared_fs changes

by fidencio
GNU/Linux ◆ xterm-256color ◆ bash 161 views

This is a short demo on how policies can block changes done by a malicious infra owner, who could force containerd and Kata Containers to not use the nydus-snapshotter to pull the image inside the guest.