Rename escalation mechanism labels - #21
Merged
Merged
Conversation
The mechanism shown for an escalation hop was "pods/exec" or "pods create". The first is also the literal Kubernetes subresource name, so a hop label could be mistaken for an RBAC resource. The second contains a space, which reads poorly in the comma-joined list (for example "pods/exec, token, pods create, impersonate") and is awkward to split or grep. Use "pod-exec" and "pod-create" instead. These appear in the text output of ::smt reaches and ::smt cluster-admin, and as the "mechanism" field in --format ndjson output, so consumers matching the old strings need to be updated. The Mangle rules and examples that refer to the real pods/exec resource are unchanged. Add a test that drives the real pipeline and asserts both labels. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Rename the escalation mechanism labels produced by
mechanism_forinsrc/smt/access.rs:pods/exec->pod-execpods create->pod-createtokenandimpersonateare unchanged. The Mangle rules and examples that refer to the real Kubernetespods/execsubresource are untouched.Behavior change
Both the displayed labels (
::smt reaches,::smt cluster-admintext output) and themechanismfield in--format ndjsonoutput change frompods/exec/pods createtopod-exec/pod-create. Anything matching the old strings needs updating.Why:
pods/execdoubles as the real RBAC resource name, so a hop label could be read as a permission.pods createcontains a space, which is awkward in the comma-joined list (pods/exec, token, pods create, impersonate) and harder to split or grep.Consistency caveat: this is a modest improvement, not full uniformity. The other labels are single words (
tokenis a noun,impersonatea bare verb), so the set is still mixed. The old labels were arguably fine as plain English; the gain here is mainly avoiding the clash with the RBAC resource name and having space-free labels. Also notepod-execcoverspods/attachgrants too (exec_reachable_sainrules/escalation.mg), aspods/execdid before.Before / after
::smt cluster-adminontestdata/alone does not show a pod-exec or pod-create hop for a user principal (onlykube-system:defaultandpallograph-test:admin-sachains). The output below usestestdata/plus a small extra fixture (SAdemo:targetwith cluster-admin and a pod running as it;exec-userwithpods/exec createindemo;create-userwithpods createindemo).Before (text):
After (text):
After (
--format ndjson,jq -c '[.principal, .paths[0].via]'):The "before" labels come from a prebuilt binary without this change (same fixture); the code path is the one-line strings in
mechanism_for.Testing
Added
pod_exec_and_pod_create_hops_use_hyphenated_mechanism_labelsinsrc/smt/access.rs. It loads the fixture above throughload_engine_with, callspaths_for_principal, and asserts the hop mechanism is exactlypod-exec/pod-create. No existing test asserted on these strings (tests/smt_ndjson.rsdoes not check mechanisms).All pass.
🤖 Generated with Claude Code