Skip to content

docs: expand GPU Operator security guidance - #508

Open
efegokdemir wants to merge 1 commit into
NVIDIA:mainfrom
efegokdemir:codex/issue-155-security-docs
Open

efegokdemir wants to merge 1 commit into
NVIDIA:mainfrom
efegokdemir:codex/issue-155-security-docs

Conversation

@efegokdemir

Copy link
Copy Markdown

Summary

Complete the remaining documentation work in #155 by incorporating the security guidance from closed PR #136 into the current GPU Operator Security Considerations page. The page now explains how administrators can prevent unprivileged workloads from selecting GPUs through NVIDIA_VISIBLE_DEVICES and clarifies the related security assumptions.

Changes

  • Add configuration guidance for restricting the NVIDIA Container Toolkit and device plugin to device-plugin-provided GPU lists.
  • Document the host-volume and privileged-container assumptions that remain important after enabling the restriction.
  • Correct the duplicated wording in the NVIDIA security bulletin link and normalize the GPU Operator security-policy link.

Testing

  • git diff --check — passed.
  • HTTP checks for the two referenced security links — passed with HTTP 200.
  • ./repo docs -p gpu-operator — blocked by the repository bootstrap tool on this Apple Silicon host: its bundled python 3.10.5-1-macos-x86_64 executable fails with Bad CPU type in executable.

Notes

Signed-off-by: Efe Gökdemir <efe@rexcode.co.uk>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant