Skip to content

Conversation

@MahatiC
Copy link
Member

@MahatiC MahatiC commented Nov 10, 2025

Prior to this change, if you had two containers with the same image layers, the second container would not get captured in the SecurityPolicy metadata and hence would not enforce the policy. SecurityPolicy pkg captures container image layer hashes and associates them with the ContainerID during CIM mount operation. But because the CIMs are already mounted (for the previous container), this process would not occur for the second container with the same layers.

This change caches the image layer hashes for each container and SecurityPolicy instance will capture it in the metadata later on (during layer combining) if it wasn't already captured previously for this ContainerID and enforces policy.

@MahatiC MahatiC marked this pull request as ready for review November 11, 2025 11:21
@MahatiC MahatiC requested a review from a team as a code owner November 11, 2025 11:21
@MahatiC MahatiC force-pushed the enforce-hashes branch 2 times, most recently from 0b676c7 to 3c87763 Compare January 16, 2026 16:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants