fetch_ml/tests/integration/security
Jeremie Fraeys 651318bc93
test(security): Integration tests for sandbox escape and secrets handling
Add sandbox escape integration tests:
- Container breakout attempts via privileged mode
- Host path mounting restrictions
- Network namespace isolation verification
- Capability dropping validation
- Seccomp profile enforcement

Add secrets integration tests:
- End-to-end credential expansion testing
- PHI denylist enforcement in real configs
- Environment variable reference resolution
- Plaintext secret detection across config boundaries
- Secret rotation workflow validation

Tests run with real container runtime (Podman/Docker) when available.
Provides defense-in-depth beyond unit tests.

Part of: security integration testing from security plan
2026-02-23 19:44:07 -05:00
..
sandbox_escape_test.go test(security): Integration tests for sandbox escape and secrets handling 2026-02-23 19:44:07 -05:00
secrets_integration_test.go test(security): Integration tests for sandbox escape and secrets handling 2026-02-23 19:44:07 -05:00