@@ -25,3 +25,44 @@ kbs_cert = """
2525{ { trustee_cert } }
2626"""
2727'''
28+
29+ "policy.rego" = '''
30+ package agent_policy
31+
32+ default AddARPNeighborsRequest := true
33+ default AddSwapRequest := true
34+ default CloseStdinRequest := true
35+ default CopyFileRequest := true
36+ default CreateContainerRequest := true
37+ default CreateSandboxRequest := true
38+ default DestroySandboxRequest := true
39+ default ExecProcessRequest := false
40+ default GetMetricsRequest := true
41+ default GetOOMEventRequest := true
42+ default GuestDetailsRequest := true
43+ default ListInterfacesRequest := true
44+ default ListRoutesRequest := true
45+ default MemHotplugByProbeRequest := true
46+ default OnlineCPUMemRequest := true
47+ default PauseContainerRequest := true
48+ default PullImageRequest := true
49+ default ReadStreamRequest := false
50+ default RemoveContainerRequest := true
51+ default RemoveStaleVirtiofsShareMountsRequest := true
52+ default ReseedRandomDevRequest := true
53+ default ResumeContainerRequest := true
54+ default SetGuestDateTimeRequest := true
55+ default SetPolicyRequest := true
56+ default SignalProcessRequest := true
57+ default StartContainerRequest := true
58+ default StartTracingRequest := true
59+ default StatsContainerRequest := true
60+ default StopTracingRequest := true
61+ default TtyWinResizeRequest := true
62+ default UpdateContainerRequest := true
63+ default UpdateEphemeralMountsRequest := true
64+ default UpdateInterfaceRequest := true
65+ default UpdateRoutesRequest := true
66+ default WaitProcessRequest := true
67+ default WriteStreamRequest := true
68+ '''
0 commit comments