mirror of
https://github.com/windmill-labs/windmill.git
synced 2026-08-20 16:02:19 +00:00
f8467f38c8
* fix: bind /etc resolver files read-only in nsjail sandboxes * docs(nsjail): explain why per-file /etc resolver binds are load-bearing The explicit /etc/hosts, /etc/resolv.conf and /etc/hostname binds look like removable duplication of the read-only /etc bind above them. They are not: on Kubernetes those files are separate kubelet bind-mounts on top of /etc and nsjail's read-only remount is non-recursive, so without these shadow binds they stay writable and a job can persist cross-tenant DNS poisoning for the pod lifetime. Comment guards against a future "dedup cleanup" silently reintroducing the vulnerability. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(nsjail): shorten the load-bearing-bind comment to 3 lines Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude <noreply@anthropic.com>
Windmill Worker
The worker. Used to process and execute flows & jobs.
This crate exposes both a library as well as a binary target.