Seccomp restricted
Subprocess with seccomp filter — only whitelisted syscalls allowed. No network; scoped filesystem.
id policy/seccomp-restrictedv1.0.0by convergent-systems-key
Rule
Subprocess with seccomp filter — only whitelisted syscalls allowed. No network; scoped filesystem.
- Process
subprocess- Network
none- Filesystem
scoped- Paths
${WORKSPACE_ROOT}
Author convergent-systems-key. Source convergent-systems-co/agent-atoms (original ↗). License Apache-2.0. Re-typed from isolation-constraint by scripts/migrate-policy-tool.py.