Repository navigation
docs(byoc): state standing EKS admin access and unsigned ECR image copies - #6483
Closed
ashwinamardeep-ashwin wants to merge 1 commit into
Closed
ashwinamardeep-ashwin wants to merge 1 commit into
ashwinamardeep-ashwin wants to merge 1 commit into
Conversation
…pies Posture statements for security reviewers, verified against code: - byoc-faq.mdx and byoc-architecture.mdx: the cross-account role is granted AmazonEKSClusterAdminPolicy at cluster scope through an EKS access entry, so operating the cluster requires standing administrative Kubernetes access. It is logged in EKS audit logs in the customer account and revocable by the customer. - byoc-architecture.mdx: the byoc-* ECR copies are produced with `docker buildx imagetools create` and carry no cosign signatures or SBOM attestations; point to the Docker Hub verification page. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Contributor
|
Mintlify preview branch generated: Site preview: https://langchain-5e9cc07a-preview-docsby-1791319236-3be7a15.mintlify.site Important Preview links may take a few minutes to start working while the deployment finishes. Changed documentation pages (preview deep links): |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Needs review: Arthur Stromquist, Romain Priour
Summary
Posture statements (class B): the existing text is technically true but omits a capability a security reviewer would consider material. Kept separate from the factual-corrections PR so it can be reviewed on its own. Verified against
langchain-ai/langchainplus @ 9ae4a56; evidence line numbers refer to the internal sweepbyoc-checkmarx-evidence.md(2026-10-05).src/langsmith/byoc-faq.mdxAmazonEKSClusterAdminPolicyon the EKS cluster through an EKS access entry. Every API call made with it is recorded in the EKS audit logs in your account, and you can revoke the access entry at any time."langsmith-aws-eks-composition.tpl:973-1037AccessEntry for$provisioningRoleArn(=crossplaneRoleArn) +AccessPolicyAssociationAmazonEKSClusterAdminPolicy,accessScope.type: cluster(116, 134-161, 193)src/langsmith/byoc-architecture.mdxsrc/langsmith/byoc-architecture.mdxcopy_byoc_ecr_images.yamlusesdocker buildx imagetools createfrom internallangsmith-prod/*repos; nocosign copy/crane/.sig/.att(366, 395-398, 401)Reviewer notes
AmazonEKSClusterAdminPolicy,pods/execandsecrets get/listare implied (evidence V1.b, line 189), so reviewers may want to soften that "No." This PR adds the sentence only and does not change the answer.Test plan
lint-prose); not run locally, Vale is not installed on this machine/langsmith/self-host-mirroring-images#verifying-image-signaturesresolves