Security evaluation of Nono as alternative to SRT
Overview
As part of &22766 and the evaluation in #605838 (closed), Nono is being proposed as a replacement for Anthropic Sandbox Runtime (SRT) for Duo Agent Platform runner sandboxing.
This issue tracks the security evaluation and review of Nono to validate it as a robust security boundary.
Background & Context
The current runner sandbox uses SRT (Anthropic Sandbox Runtime via bubblewrap and Linux mount namespaces), which has significant limitations in non-root or hardened environments (such as FedRAMP images) and requires root or unprivileged user namespaces.
Nono is an alternative sandbox runtime utilizing Linux Landlock for filesystem isolation and a local proxy for network domain filtering, operating without requiring root or namespace capabilities.
Scope of Security Evaluation
- AppSec Boundary Review:
- Evaluate Nono's Landlock-based filesystem isolation (read/write restrictions, protection of sensitive directories such as
~/.sshand credential stores). - Review network egress filtering and ensure proxy enforcement cannot be bypassed by child processes or unsetting environment variables.
- Verify fail-closed behavior across all failure scenarios (ensuring tasks fail rather than execute unsandboxed).
- Evaluate Nono's Landlock-based filesystem isolation (read/write restrictions, protection of sensitive directories such as
- Attack Surface & Sandbox Escape Analysis:
- Assess potential bypass mechanisms, kernel version dependencies, and Landlock ABI compatibility across supported runner host kernels.
- Evaluate interaction with container runtimes and seccomp profiles.
- Supply Chain & OSS Review:
- Review third-party dependency posture, Apache-2.0 license compliance, provenance, and binary verification/pinning for packaging into GitLab runner images.
- Compliance & Hardened Environments:
- Review compatibility and security posture for FedRAMP and enterprise hardened runner environments.
Related Items
- Parent Epic: &22766
- Research & Plan Issue: #605838 (closed)
- Feature Flag Rollout Issue: #624259
- Open MR: !252331 (merged)
Edited by 🤖 GitLab Bot 🤖