Document ARC and sandbox runtime architecture - #50667
Conversation
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Pull request overview
Expands security architecture documentation for ARC/DinD and alternative agent runtimes.
Changes:
- Extends the substrate trust model across runner topologies.
- Documents Docker, gVisor, and Docker sbx isolation boundaries.
- Adds runtime compatibility guidance and related links.
Show a summary per file
| File | Description |
|---|---|
docs/src/content/docs/introduction/architecture.mdx |
Updates architecture, topology, runtime, and security-layer documentation. |
Review details
Tip
Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
- Files reviewed: 1/1 changed files
- Comments generated: 1
- Review effort level: Balanced
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
|
@copilot please refresh this branch if it is behind
|
Branch was already up to date with
The one review thread (compile-time vs runtime validation at line 194) is already resolved. No further code changes required. |
|
@copilot please review the latest PR feedback, refresh this branch if it is behind Run: https://github.com/github/gh-aw/actions/runs/31050365846
|
Branch is not behind
The PR Sous Chef run (31050365846) concluded |
Caution
agentic threat detected
Threat detection flagged this output in warn mode. Manual review is REQUIRED before any follow-up automation.
Details
Potential security threats were detected in the agent output.
Review the workflow run logs for details.
Overview
Updates the Security Architecture documentation to reflect the currently supported runner topologies and agent isolation runtimes: GitHub-hosted/self-hosted Linux runners, Actions Runner Controller (ARC) with a Docker-in-Docker (DinD) sidecar, gVisor (
runsc), and Docker sbx (KVM microVM). No code changes — documentation only.Key Changes
docs/src/content/docs/introduction/architecture.mdx(modified, ~82 diff lines)sandbox.agent.runtime: gvisor) and Docker sbx (sandbox.agent.runtime: docker-sbx) as alternative isolation boundaries on compatible runners.descriptionupdated to mention ARC/DinD, gVisor, and Docker sbx explicitly.Impact
Commits
f85f9f294docs: document runner and sandbox architecturef528bce63Potential fix for pull request findingb24ee134b,fa7401424Merge branch 'main' (sync commits)> Generated by PR Description Updater for Document ARC and sandbox runtime architecture #50667 · auto · 31.1 AIC · ⌖ 17.4 AIC · ⊞ 6.9K · ◷