Sign inSign up

docker/sbx-kit-panw-endpoint-enforcement:latest

Multi-platform
Manifest digest

sha256:dea63efeac5c58a5357ed931e59f5d24ff26c1954687e50fc898d602373d4f24

Last pushed

8 days by cdupuis

Type

Sandbox Kit

Manifest digest

sha256:dea63efeac5c58a5357ed931e59f5d24ff26c1954687e50fc898d602373d4f24

yaml
schemaVersion: "3"
displayName: PANW Endpoint Enforcement Marker
description: Marks agent processes as running inside a sandbox so a host-side endpoint security policy engine can permit sandbox-wrapped agents while denying any agent process that spawns outside a sandbox.
sourceUrl: https://github.com/docker/sbx-kits-contrib/tree/main/panw-endpoint-enforcement
version: 1.0.0
licenses:
    - Apache-2.0
kind: mixin
capabilities:
    - type: com.docker.sandbox/lifecycle@1
      config:
        files:
            - content: |
                marker=${{ kit.args.markerId }}
                enforced=1
              description: Write the sandbox enforcement marker file
              mode: "0444"
              overwrite: false
              path: /home/agent/.sandbox-enforced
    - type: com.docker.sandbox/agent-context@1
      config:
        contentFile: /usr/share/sandbox/kit/panw-endpoint-enforcement/panw-endpoint-enforcement-context.md
args:
    markerId:
        default: sandbox-wrapped
        description: Identity string the host endpoint policy keys on to allow this process.
        pattern: ^[a-z0-9]([a-z0-9-]{0,62}[a-z0-9])?$
        env: SANDBOX_ENFORCEMENT_MARKER