Replies: 1 comment
-
Good idea, Let us look into it, and see if the current eBPF helper supports digest list. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
There are two proposals for IMA-based container-level measurement:
We are currently using the
cgpath
template and applying two kernel patches. However, the kernel patches RFC has been archived, and the author no longer updated it. eBPF is a revolutionary technology that can run sandboxed programs in the Linux kernel without changing kernel source code or loading a kernel module, maybe we can use eBPF to replace the kernel patches.Here is an example of extending the IMA to container measurement without changes to the kernel: https://github.com/avery-blanchard/container-ima
Beta Was this translation helpful? Give feedback.
All reactions