namespace isolation practices for multi-tenant runtimes

Designs, implements, and evaluates practices and mechanisms that create and enforce namespace boundaries in multi-tenant runtime environments to prevent cross-tenant access, resource leakage, and interference. This work includes specifying isolation policies, configuring and integrating isolation primitives (process, network, filesystem namespaces and resource controls), implementing enforcement and access controls, and testing and auditing runtime behavior to verify isolation.

namespaceisolationpracticesfor

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
0.73
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$200K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

Breaking the Bulkhead: Demystifying Cross-Namespace Reference Vulnerabilities in Kubernetes Operators

Jul 04, 2025
AC
Andong Chen
🏛️ Zhejiang University | Northwestern University

This paper presents the first systematic study revealing isolation failures in Kubernetes Operators caused by cross-namespace resource references: attackers with limited permissions in a single namespace can exploit Operator logic to escalate privileges and access or manipulate resources in other namespaces. To address this, we propose a static-analysis-driven inconsistency detection method and develop OpGuard, an automated tool that precisely identifies semantic mismatches between Operator code logic and the declared scopes in RBAC policies and CRD definitions. Empirical evaluation across 2,147 widely used Operators uncovers 312 (14.5%) vulnerable instances. Our findings have driven community remediation efforts, resulting in 7 confirmed fixes and 6 assigned CVEs. The OpGuard tool is open-sourced and has received acknowledgments and responses from major vendors including Red Hat and Rancher, significantly enhancing the security posture of the Kubernetes Operator ecosystem.

Exposes privilege escalation risks due to namespace isolation bypassIdentifies Cross-Namespace Reference Vulnerabilities in Kubernetes OperatorsReveals 14% of Operators are vulnerable with real-world impacts

Current research on the security of LLM-agent systems remains fragmented, lacking a unified framework to explain the common root causes and propagation mechanisms underlying failures such as prompt injection and tool misuse. This work establishes *isolation* as a first-class principle for system security and introduces a boundary-centric taxonomy comprising five boundary types: user–agent, agent–tool, agent–execution, agent–agent, and system–environment. By systematically modeling failure pathways and defense strategies through structured review and cross-domain analysis, the study reveals that security failures predominantly originate from insufficient isolation and follow distinct cross-boundary attack propagation patterns. The paper thus provides a cohesive theoretical foundation and a construction-oriented research agenda centered on isolation for designing highly secure agent systems.

boundary failureisolationLLM-agent system safety

This work addresses the absence of a unified, verifiable runtime safety mechanism in existing MCP-style agents, where security decisions are fragmented across multiple components. To bridge this gap, the paper introduces HCP (Handle-Capability Protocol), a runtime framework that, while fully compatible with MCP workflows, formally defines eight execution-layer safety invariants for the first time. HCP enforces these invariants through a fine-grained access control model grounded in subjects, resources, capabilities, handles, and policies, explicitly ensuring critical properties such as subject binding, capability scoping, and data-flow authorization. Empirical evaluation demonstrates that HCP successfully blocks all attacks across ten benchmark scenarios while preserving auditable evidence, substantially outperforming baseline approaches. Microbenchmark results further indicate that policy operations incur an average latency of less than one millisecond.

capability-based securityexecution controlMCP-style agent

This work addresses the challenge of formally comparing the semantic differences among transaction isolation levels. To this end, it introduces Isolde, a tool that, for the first time, automatically constructs counterexamples demonstrating behavioral discrepancies between isolation levels. By modeling transaction executions through formal specifications, Isolde generates execution traces that are permitted under one isolation level but prohibited under another. This approach enables automated verification of isolation-level equivalence and falsification of claimed semantic properties. The method not only reproduces established theoretical results but also uncovers long-standing errors in the literature and previously unknown flaws in the specifications of widely used isolation checkers, thereby significantly advancing the automation and reliability of reasoning about transaction isolation semantics.

concurrent accessisolation levelssemantic differences

Latest Papers

What's happening recently
View more

This work addresses the programming challenges and error-proneness introduced by Arm’s POE2 architecture, which employs a complex spatiotemporal permission mechanism yet lacks a unified security model. We propose the first general-purpose secure programming model tailored for POE2, abstracting away the intricacies of its spatial and temporal indexing and encapsulating hardware features such as memory protection keys, dedicated registers, and table structures. By doing so, our model significantly simplifies permission management while preserving POE2’s strong security guarantees. It naturally supports common intra-process isolation patterns used in software partitioning, enabling developers to construct secure isolated systems more efficiently and with fewer errors.

architectural complexityintra-process isolationmemory protection keys

Modern database systems lack effective mechanisms to verify whether concurrent control protocols correctly implement their intended isolation semantics under mixed isolation levels. This work proposes, for the first time, a formal semantic framework for rigorously validating the semantic consistency of concurrency control protocols operating across multiple isolation levels. By integrating formal methods with semantic modeling techniques, the framework enables systematic analysis of protocol behavior. As demonstrations of its applicability, the framework successfully verifies two representative protocols—one supporting two isolation levels and another supporting three—thereby addressing a critical gap in theoretical validation within this domain. This contribution provides a foundational tool for ensuring correctness in mixed-isolation database systems.

concurrency controldatabase consistencyisolation levels

Hot Scholars

AC

Asaf Cidon

Columbia University
Operating SystemsDistributed SystemsDatabasesStorage
HZ

Hefan Zhang

PhD student of Dartmouth College
Natural Language ProcessingMachine LearningInterpretabilityLLM Generation