On Mon, Apr 19, 2010 at 06:05:28PM +0100, Guido Trotter wrote: > Signed-off-by: Guido Trotter <[email protected]> > --- > doc/security.rst | 39 +++++++++++++++++++++++++++++++++++++++ > 1 files changed, 39 insertions(+), 0 deletions(-) > > diff --git a/doc/security.rst b/doc/security.rst > index e816ed3..7904290 100644 > --- a/doc/security.rst > +++ b/doc/security.rst > @@ -99,6 +99,45 @@ Paths for certificate, private key and CA files required > for SSL/TLS > will be set at source configure time. Symlinks or command line > parameters may be used to use different files. > > +KVM Security > +------------ > + > +When running KVM instances under Ganeti three security models ara > +available: 'none', 'user' and 'pool'. > + > +Under security model 'none' instances run by default as root. This means > +that, if an instance gets jail broken, it will be able to own the host > +node, and thus the ganeti cluster. This is the default model, and the > +only one available before Ganeti 2.1.2. > + > +Under security model 'user' an instance is run as the user specified by > +the hypervisor parameter 'security_domain'. This makes it easy to run > +all instances as non privileged users, and allows to manually allocate > +specific users to specific instances or sets of instances. If the > +specified user doesn't have permissions a jail broken instance will need > +some local privilege escalation before being able to take over the node > +and the cluster. It's possible though for a jail broken instance to > +affect other ones running under the same user. > + > +Under security model 'pool' a global cluster-level uid pool is used to > +start each instance on the same node under a different user. The uids in > +the cluster pool can be set with gnt-cluster init and modify, and must
Mark gnt-cluster init/modify in a different typeface (:command: or so). > +correspond to existing users on all nodes. Ganeti will then allocate one > +to each instance, as needed. Note that this is randomized, so no guarantees about the mapping. > This way a jail broken instance won't be > +able to affect any other. > + > +In addition to these precautions, if you want to avoid instances sending > +traffic on your node network, you can use an iptables rule such as:: > + > + iptables -A OUTPUT -m owner --uid-owner <uid>[-<uid>] -j LOG \ > + --log-prefix "ganeti uid pool user network traffic" > + iptables -A OUTPUT -m owner --uid-owner <uid>[-<uid>] -j DROP > + > +This won't affect regular instance traffic (that comes out of the tapX > +allocated to the instance, and can be filtered or subject to appropriate > +policy routes) but will stop any user generated traffic that might come > +from a jailbroken instance. LGTM. iustin -- Subscription settings: http://groups.google.com/group/ganeti-devel/subscribe?hl=en
