Repository navigation
Add application-controlled security policies for kubeconfig exec plugins - #1930
brendandburns with Copilot wants to merge 3 commits into
Conversation
There was a problem hiding this comment.
Copilot wasn't able to review any files in this pull request. Check if the Files changed in this pull request are included in default exclusions.
|
Co-authored-by: brendandburns <5751682+brendandburns@users.noreply.github.com>
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: Copilot The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
| return commands.Any(entry => string.Equals( | ||
| entry, IsBasename(entry) ? Path.GetFileName(command) : command, CommandComparison)); |
There was a problem hiding this comment.
Addressed in the latest commit: Allowlist mode now rejects all kubeconfig-supplied environment overrides before process creation and again at the launch boundary; AllowAll retains existing behavior. Tests cover PATH, LD_PRELOAD, DYLD_INSERT_LIBRARIES, and ordinary overrides during configuration loading, direct execution, and refresh. Documentation explains trusted application-inherited environment settings, basename resolution limitations, and that approved plugin arguments/executable behavior are not sandboxed.
Co-authored-by: brendandburns <5751682+brendandburns@users.noreply.github.com>

Untrusted kubeconfigs can launch arbitrary local processes through exec credential plugins. This adds application-controlled authorization without requiring callers to parse and inspect kubeconfig themselves.
AllowAll(default),DenyAll, andAllowlistpolicies across configuration builders, including Classic and AOT. Existing API signatures remain available.ExecCredentialPluginDeniedException; kubeconfig cannot override the application policy.