Hold enrolled workloads until Phantom Engine is enforce-ready - #151
Conversation
|
FOUNDER_OVERRIDE_MERGE deferred — merge conflicts Exact tip Rebase onto |
After reboot an enrolled workload can run while the loader and BPF pins are still down. This adds an enrolled-only early hold and a start gate, and leaves the reboot row NOT_PROVED until a host reproof.
…eck. Ordinary apply now enables the hold. A running loader that is not attached keeps enrolled workloads held. Break-glass clears the packet hold and the start gate in one root action.
89a02ae to
a492097
Compare
|
FOUNDER_OVERRIDE_MERGE by Founder bypass (zacharybalicki, pull-request bypass on ruleset 24281604). This is not a Kate review. It is not a kvantio approval. It is not Squash merge SHA: Council on
The reboot exposure row stays NOT_PROVED. A clean-host reproof is still required. This merge does not mark |
Summary
After a reboot, an enrolled workload can run while the Phantom Engine loader is down and the BPF pins are empty. This change closes that gap in open-core with an enrolled-only early hold plus a start gate. The hold is on by default. It does not drop the host default route, so SSH, DHCP, DNS, and unenrolled processes keep working.
vantio-install applyinstalls and enables the hold before the observe container starts. A trusted root opt-out file is left alone, so apply does not turn the hold back on. The opt-out is logged and shown onvantio-boot-hold statusand in installerHEALTH.json.vantio-boot-hold.serviceruns before Docker and containerd. It drops egress only forvantio-enrolled.sliceand for the enrolled subnet10.250.250.0/24. Release waits for more than a running loader: pins present, policy loaded,cgroup_skb_egress_enforceattached to the enrolled slice, loader health OK, and a live deny check (enrolled connect fails, the same connect outside the slice succeeds). A loader that is running but not attached keeps the hold. If that check fails, enrolled workloads stay held and status showsHELD/DEGRADED.Break-glass is one root command,
vantio-boot-hold release --break-glass --i-am-root-operator. It removes the packet hold, clears the file hold, and drops the systemdRequires=start gates for enrolled units. The audit log lists what was released. An enrolled workload cannot run it.Plain Docker, Compose, and systemd each have a start unit that requires enforce-ready when ordering is on. Enroll refuses a Docker restart policy other than
no. A workload missing from the registry isUNPROTECTEDin status.The reboot row stays NOT_PROVED. This PR does not mark
B1-REBOOT-EXPOSUREas passed, does not retro-claim seale0b19d55…, and does not invent a new seal. GAP-BH-002 and GAP-BH-005 through GAP-BH-009 stay open. The companion note isdocs/planning/boot-hold/PE-COMPANION.md. The Free-plan lab procedure isdocs/planning/boot-hold/FD-REBOOT-1-LAB-PROCEDURE.md(account960577828987, expected out-of-pocket $0). That procedure is not run from this PR.Test plan
python3 -m unittest discover -s tests -t .inpackages/vantio-install(172 tests, OK)vantio-install applywrites and enablesvantio-boot-hold.serviceand recordsHELDonHEALTH.jsonwithout turning enforcement onOPTED_OUTin healthRequires=and the audit lists the released gatesvantio-enrolled.sliceNo EC2, no publish, no Paid, no soak, fleet, or k3s.