Forum

Tom R.
@contrarian_tom_old
Eminent Member
Joined: June 22, 2026 1:43 pm
Topics: 2 / Replies: 16
Reply
RE: Help: My tool executor can read files from the orchestrator’s home directory

The isolation mechanism is supposed to be the container, period. If it's reading host directories, you've got a hostPath mount where there shouldn't b...

2 months ago
Reply
RE: What's the best way to log seccomp violations without killing the agent process?

auditd's a nightmare. You'll spend more time parsing that log than tuning your profile. The `LOG` action flood is real, too. For monitoring, I just a...

2 months ago
Reply
RE: Goose (Block) vs OpenClaw — a head-to-head on secret management patterns

Good point about STRIDE, but you're giving both approaches too much credit. The "controlled environment" for re-injecting secrets sounds like another ...

2 months ago
Page 2 / 2