Skip to content

Investigate replacing credential broker mTLS with per-worker UDS isolation #778

Description

@EItanya

Context

PR #708 authenticates atunnel to the node-local atelet credential broker with mTLS over a Unix domain socket. This is necessary in the current layout because every root-running ateom shares the hostPath containing the broker socket; permissions on one shared socket do not distinguish workers.

Review discussion: #708 (comment)

Investigate whether filesystem isolation can provide the same worker-to-atelet binding with less protocol machinery.

Questions

  • Can atelet create a separate socket directory and listener for each worker?
  • Can each worker Pod mount only its own socket directory?
  • What ownership and mode should protect the directory and socket when ateom runs as root?
  • How are sockets created, removed, and recovered across worker replacement, Pod UID reuse, atelet restart, and failed activation?
  • How do we prevent path traversal, symlink, stale-socket, and cross-worker access attacks?
  • Can atelet securely derive the worker identity from the selected listener without trusting request metadata?
  • If filesystem isolation is sufficient, can TLS be removed, or should it remain as defense in depth?

Acceptance criteria

  • Document the trust boundary and attacker model, including a compromised actor and a compromised sibling worker on the same node.
  • Compare the current shared-socket mTLS design with per-worker filesystem-isolated sockets.
  • Specify socket naming, mounts, permissions, identity binding, lifecycle, and cleanup.
  • Confirm the proposed design fails closed during stale assignment and restart races.
  • Recommend whether to keep mTLS, replace it, or combine both.
  • Do not remove mTLS until equivalent worker isolation is demonstrated by tests.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions