{% extends "base.html" %} {% block title %}LASSO — System Check{% endblock %} {% block breadcrumb %} {% endblock %} {% block content %}

Platform Information

Operating System
{{ capabilities.platform }}
Python Version
{{ capabilities.python }}
LASSO Version
{{ version }}

Container Runtimes

Docker {% if capabilities.docker %} Available {% else %} Not Found {% endif %}

Primary container backend for full OS-level isolation

Podman {% if capabilities.podman %} Available {% else %} Not Found {% endif %}

Rootless alternative to Docker, DORA-compliant

Linux Kernel Capabilities

User Namespaces {% if capabilities.user_ns %} Available {% else %} Unavailable {% endif %}

Required for unprivileged sandbox creation

Mount Namespaces {% if capabilities.mount_ns %} Available {% else %} Unavailable {% endif %}

Filesystem isolation with read-only mounts and hidden paths

PID Namespaces {% if capabilities.pid_ns %} Available {% else %} Unavailable {% endif %}

Process isolation prevents agents from seeing host processes

Network Namespaces {% if capabilities.net_ns %} Available {% else %} Unavailable {% endif %}

Network isolation with iptables-based controls

Cgroups v2 {% if capabilities.cgroups_v2 %} Available {% else %} Unavailable {% endif %}

Resource limits for memory, CPU, and process counts

{% set all_ns = capabilities.user_ns and capabilities.mount_ns and capabilities.pid_ns and capabilities.net_ns and capabilities.cgroups_v2 %} {% set has_runtime = capabilities.docker or capabilities.podman %} {% if has_runtime and all_ns %}
Full Isolation Available

All kernel capabilities and at least one container runtime detected. LASSO can provide maximum sandbox isolation.

{% elif has_runtime %}
Container Backend Available

Some kernel capabilities missing for native isolation fallback. Container mode will provide full isolation.

{% elif all_ns %}
Kernel Capabilities Available

No container runtime detected. Install Docker or Podman for full container-based sandbox isolation.

{% else %}
Limited Isolation

LASSO will fall back to software-level enforcement (command gate + environment sanitization). For production use, install Docker/Podman and ensure kernel namespace support.

{% endif %} {% endblock %}