feat(netns): bwrap-contained chrome + proton wrapper

- netvm-chrome.sh --contained: bwrap fs jail inside netns (profile
  home only + vault ro at /tmp/vault, Chromium sandbox stays on)
- netvm-proton.sh: run proton-cli as the profile identity in netns
  + jail (config dir + static binary, PROTON_NO_INPUT=1)
This commit is contained in:
operator
2026-10-08 13:23:06 -04:00
parent ed33d66479
commit ef2a4c419a
3 changed files with 83 additions and 6 deletions
+2 -1
View File
@@ -119,7 +119,8 @@ veth IPs aren't routable off the host and Warp forwards no inbound traffic.
- `bin/netvm-fleet.sh` — operator fleet control over the tailnet (topology/up/down/ssh/exec/cdp per node).
- `bin/netvm-exec.sh <node> -- <cmd>` — run a command inside the node's netns as the invoking user (the agent-friendly primitive).
- `bin/netvm-enter.sh` — root worker behind netvm-exec/netvm-chrome (allowlisted; enters netns, fixes DNS, drops privs).
- `bin/netvm-chrome.sh <profile> [url]` — launch a chrome-box profile in its netns (CDP on by default; --headless for agents).
- `bin/netvm-chrome.sh <profile> [url]` — launch a chrome-box profile in its netns (CDP on by default; --headless for agents; --contained adds a bwrap fs jail inside the netns: profile home only + vault read-only at /tmp/vault, Chromium sandbox stays on).
- `bin/netvm-proton.sh <profile> -- <args>` — run proton-cli as the profile's Proton identity (1:1:1 profile = node = warp identity = proton-cli profile) inside the netns + bwrap jail (config dir + static binary only, PROTON_NO_INPUT=1). Human creates the session once: `proton-cli -p <profile> account login`.
- `bin/netvm-cdp.sh <profile>` — print the CDP endpoint + SSH forward.
- `bin/netvm-cdp-relay.py` — veth-IP→loopback TCP relay for CDP (pidfile-supervised).
- `bin/netvm-names.sh` — shared naming: netns, hashed iface tags, veth subnet, CDP port.