spire
spire copied to clipboard
Unix path selector can be relative to either the host or a container image
The path selector in the unix workload attestor is generated by reading the link from /proc/PID/exe
. The value of this link does not consider namespacing, and appears as being relative to the namespace in which the binary is executing.
We should choose one or the other, or deprecate the path selector altogether.
Please see https://github.com/spiffe/spire/issues/1403 for more information.
This issue is stale because it has been open for 365 days with no activity.
This issue was closed because it has been inactive for 30 days since being marked as stale.
Still relevant.