Security
Nobody knows what will run inside. Assume it is hostile.
The barriers
Section titled “The barriers”| Barrier | How |
|---|---|
| Daemon off the network | Unix socket only; remotely, only over SSH |
| Unprivileged VMM | CapEff 0, no_new_privs, only the kvm group |
| No LAN access | egress none by default; with internet, private networks are blocked |
| Neighbors that do not choke | 128 MiB/s of disk and 16 MiB/s of network per machine; CPU cgroup |
| Keys that never repeat | virtio-rng + VMGENID: the guest reseeds on restore |
| Secrets kept out of snapshots | MMDS only on the live machine; a machine with secrets is not frozen |
Checked from the guest
Section titled “Checked from the guest”RESULT 192.168.2.100: BLOCKED (Proxmox host)RESULT 192.168.2.1: BLOCKED (home router)RESULT 169.254.169.254: BLOCKED (cloud metadata)RESULT 1.1.1.1: REACHABLEPer-user authorization
Section titled “Per-user authorization”With a policy, every daemon route is authorized by the caller: admin or tenant:<name>.
kling psOutput, with no role
error: uid 1003 has no role in the daemon's authz policy (/etc/kling/authz.json)What is NOT solved
Section titled “What is NOT solved”- No encryption at rest; soft disk quotas.
KLING_JAILER=0turns the jailer off.- The guest can use a proxied key against its domain: restrict it at the provider.
In the repo: SECURITY.md · docs/authz.md