On Mon, Apr 19, 2010 at 06:05:28PM +0100, Guido Trotter wrote:
> Signed-off-by: Guido Trotter <[email protected]>
> ---
>  doc/security.rst |   39 +++++++++++++++++++++++++++++++++++++++
>  1 files changed, 39 insertions(+), 0 deletions(-)
> 
> diff --git a/doc/security.rst b/doc/security.rst
> index e816ed3..7904290 100644
> --- a/doc/security.rst
> +++ b/doc/security.rst
> @@ -99,6 +99,45 @@ Paths for certificate, private key and CA files required 
> for SSL/TLS
>  will be set at source configure time. Symlinks or command line
>  parameters may be used to use different files.
>  
> +KVM Security
> +------------
> +
> +When running KVM instances under Ganeti three security models ara
> +available: 'none', 'user' and 'pool'.
> +
> +Under security model 'none' instances run by default as root. This means
> +that, if an instance gets jail broken, it will be able to own the host
> +node, and thus the ganeti cluster. This is the default model, and the
> +only one available before Ganeti 2.1.2.
> +
> +Under security model 'user' an instance is run as the user specified by
> +the hypervisor parameter 'security_domain'. This makes it easy to run
> +all instances as non privileged users, and allows to manually allocate
> +specific users to specific instances or sets of instances. If the
> +specified user doesn't have permissions a jail broken instance will need
> +some local privilege escalation before being able to take over the node
> +and the cluster. It's possible though for a jail broken instance to
> +affect other ones running under the same user.
> +
> +Under security model 'pool' a global cluster-level uid pool is used to
> +start each instance on the same node under a different user. The uids in
> +the cluster pool can be set with gnt-cluster init and modify, and must

Mark gnt-cluster init/modify in a different typeface (:command: or so).

> +correspond to existing users on all nodes. Ganeti will then allocate one
> +to each instance, as needed.

Note that this is randomized, so no guarantees about the mapping.

> This way a jail broken instance won't be
> +able to affect any other.
> +
> +In addition to these precautions, if you want to avoid instances sending
> +traffic on your node network, you can use an iptables rule such as::
> +
> +  iptables -A OUTPUT -m owner --uid-owner <uid>[-<uid>] -j LOG \
> +    --log-prefix "ganeti uid pool user network traffic"
> +  iptables -A OUTPUT -m owner --uid-owner <uid>[-<uid>] -j DROP
> +
> +This won't affect regular instance traffic (that comes out of the tapX
> +allocated to the instance, and can be filtered or subject to appropriate
> +policy routes) but will stop any user generated traffic that might come
> +from a jailbroken instance.

LGTM.

iustin


-- 
Subscription settings: 
http://groups.google.com/group/ganeti-devel/subscribe?hl=en

Reply via email to