From 39d9c047e86aabf9f2830a4f5b33961bad457009 Mon Sep 17 00:00:00 2001 From: Drew Newberry Date: Mon, 14 Sep 2026 14:19:43 -0700 Subject: [PATCH] chore(security): document Kubernetes runtime RBAC Signed-off-by: Drew Newberry --- .trivyignore.yaml | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/.trivyignore.yaml b/.trivyignore.yaml index 5e6afc010e..4cc4e32ffe 100644 --- a/.trivyignore.yaml +++ b/.trivyignore.yaml @@ -32,3 +32,13 @@ misconfigurations: - "**/deployment.yaml" statement: >- Images come from ghcr.io/nvidia/openshell, this project's own registry. + + # The Kubernetes compute driver creates its runtime infrastructure and the + # per-sandbox outer egress fence in the configured sandbox namespace. + - id: KSV-0056 + paths: + - "**/role.yaml" + statement: >- + The namespace-scoped gateway role can create Services and NetworkPolicy + resources so the compute driver can connect each sandbox runtime to its + supervisor while denying direct workload egress.