Skip to content

Security

Nobody knows what will run inside. Assume it is hostile.

Barrier How
Daemon off the network Unix socket only; remotely, only over SSH
Unprivileged VMM CapEff 0, no_new_privs, only the kvm group
No LAN access egress none by default; with internet, private networks are blocked
Neighbors that do not choke 128 MiB/s of disk and 16 MiB/s of network per machine; CPU cgroup
Keys that never repeat virtio-rng + VMGENID: the guest reseeds on restore
Secrets kept out of snapshots MMDS only on the live machine; a machine with secrets is not frozen
RESULT 192.168.2.100: BLOCKED (Proxmox host)
RESULT 192.168.2.1: BLOCKED (home router)
RESULT 169.254.169.254: BLOCKED (cloud metadata)
RESULT 1.1.1.1: REACHABLE

With a policy, every daemon route is authorized by the caller: admin or tenant:<name>.

Terminal window
kling ps

Output, with no role

error: uid 1003 has no role in the daemon's authz policy (/etc/kling/authz.json)
  • No encryption at rest; soft disk quotas.
  • KLING_JAILER=0 turns the jailer off.
  • The guest can use a proxied key against its domain: restrict it at the provider.