shukitchan opened a new pull request, #382: URL: https://github.com/apache/trafficserver-ingress-controller/pull/382
This pull request introduces significant security improvements and configurability to the ATS Ingress Controller, particularly around the handling of ConfigMaps and Lua server snippets. The main focus is on hardening the dynamic configuration path to prevent privilege escalation and code injection, while providing operators a safe, auditable way to extend configuration as needed. Additionally, new tests and documentation have been added to support these changes. **ConfigMap RBAC and Allowlist Hardening:** * Added a strict allowlist (`builtinAllowedRecords`) of `records.config` keys that can be set via ConfigMaps, blocking all others by default. The allowlist can be extended by operators using the `CONFIGMAP_RECORD_ALLOWLIST` environment variable in the pod spec. Only keys starting with `proxy.config.` are accepted, and entries can be exact or prefix matches. [[1]](diffhunk://#diff-c70e431013afd3fe7a2b9134b8f0ccbe4bc4b50298a9cda70d065a5207c3b33eR34-R107) [[2]](diffhunk://#diff-c70e431013afd3fe7a2b9134b8f0ccbe4bc4b50298a9cda70d065a5207c3b33eR130-R137) * Rejected config values containing whitespace or control characters to prevent injection or malformed configuration. * Updated RBAC: ClusterRole now only grants access to Endpoints (not ConfigMaps, Secrets, etc.), and a new namespaced Role/RoleBinding pair grants access to ConfigMaps only in the controller's namespace, following least-privilege principles. [[1]](diffhunk://#diff-f9c183049e35e9d73b80aaca71929a145e294c39c763de656187bfd091198b3fR31-R55) [[2]](diffhunk://#diff-5263a7cb31176ec0085699537adeb2498b3ed023584cc600cbe4febfab9cfa76R1-R45) [[3]](diffhunk://#diff-0bfe31f0defe643ca353dc70f7b33b544bca22f783ce88eccbef42c87a4eb577R1-R39) **Lua Server Snippet Sandboxing:** * Introduced a restricted execution environment for Lua server snippets, allowing only a safe subset of global functions and constants. Dangerous primitives (e.g., `os`, `io`, `require`, metatables, debug) are not accessible, and any attempt to use them results in a runtime error that is safely logged and contained. [[1]](diffhunk://#diff-073f9e0b4f40794597614c637578cda90068656aac5688ebbd54f6aac7e1a2a1R34-R64) [[2]](diffhunk://#diff-073f9e0b4f40794597614c637578cda90068656aac5688ebbd54f6aac7e1a2a1L247-R287) **Testing and Documentation:** * Added comprehensive unit tests for both the ConfigMap allowlist logic and the Lua snippet sandbox, ensuring that only allowed keys/values are applied and that sandbox escapes are not possible. [[1]](diffhunk://#diff-93a225df7c7c71a793f0d8679bf3e52b3d1485695cdbf26615a9b66feab1757bR111-R211) [[2]](diffhunk://#diff-bf5a570b0cb400b1bce17bbdcf466aa958fa4ca2d528760841a6711860cbe468R200-R277) * Updated documentation to explain the new allowlist mechanism, its security rationale, and how operators can safely extend it. [[1]](diffhunk://#diff-0feec4b5635887418b63788f156bd8d252d2fb2205415afc00b3ca03bbe2e4f6R41-R49) [[2]](diffhunk://#diff-2515627113bc7b3cc4805c26401bd011e82d28306ac2d3413aa11e386f4ab6d5R75-R79) **Other Minor Improvements:** * Added missing imports and minor code cleanups to support new features. [[1]](diffhunk://#diff-c70e431013afd3fe7a2b9134b8f0ccbe4bc4b50298a9cda70d065a5207c3b33eR20-R21) [[2]](diffhunk://#diff-3f7f01da5f23b1829a75c4f9257ad78429b20042cb9a8387fd2e8515363c447dR21) These changes collectively provide a much safer and more auditable configuration path for ATS Ingress, reducing the risk of privilege escalation or code execution via Kubernetes ConfigMaps or Ingress annotations. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
