shukitchan opened a new pull request, #382:
URL: https://github.com/apache/trafficserver-ingress-controller/pull/382

   This pull request introduces significant security improvements and 
configurability to the ATS Ingress Controller, particularly around the handling 
of ConfigMaps and Lua server snippets. The main focus is on hardening the 
dynamic configuration path to prevent privilege escalation and code injection, 
while providing operators a safe, auditable way to extend configuration as 
needed. Additionally, new tests and documentation have been added to support 
these changes.
   
   **ConfigMap RBAC and Allowlist Hardening:**
   
   * Added a strict allowlist (`builtinAllowedRecords`) of `records.config` 
keys that can be set via ConfigMaps, blocking all others by default. The 
allowlist can be extended by operators using the `CONFIGMAP_RECORD_ALLOWLIST` 
environment variable in the pod spec. Only keys starting with `proxy.config.` 
are accepted, and entries can be exact or prefix matches. 
[[1]](diffhunk://#diff-c70e431013afd3fe7a2b9134b8f0ccbe4bc4b50298a9cda70d065a5207c3b33eR34-R107)
 
[[2]](diffhunk://#diff-c70e431013afd3fe7a2b9134b8f0ccbe4bc4b50298a9cda70d065a5207c3b33eR130-R137)
   * Rejected config values containing whitespace or control characters to 
prevent injection or malformed configuration.
   * Updated RBAC: ClusterRole now only grants access to Endpoints (not 
ConfigMaps, Secrets, etc.), and a new namespaced Role/RoleBinding pair grants 
access to ConfigMaps only in the controller's namespace, following 
least-privilege principles. 
[[1]](diffhunk://#diff-f9c183049e35e9d73b80aaca71929a145e294c39c763de656187bfd091198b3fR31-R55)
 
[[2]](diffhunk://#diff-5263a7cb31176ec0085699537adeb2498b3ed023584cc600cbe4febfab9cfa76R1-R45)
 
[[3]](diffhunk://#diff-0bfe31f0defe643ca353dc70f7b33b544bca22f783ce88eccbef42c87a4eb577R1-R39)
   
   **Lua Server Snippet Sandboxing:**
   
   * Introduced a restricted execution environment for Lua server snippets, 
allowing only a safe subset of global functions and constants. Dangerous 
primitives (e.g., `os`, `io`, `require`, metatables, debug) are not accessible, 
and any attempt to use them results in a runtime error that is safely logged 
and contained. 
[[1]](diffhunk://#diff-073f9e0b4f40794597614c637578cda90068656aac5688ebbd54f6aac7e1a2a1R34-R64)
 
[[2]](diffhunk://#diff-073f9e0b4f40794597614c637578cda90068656aac5688ebbd54f6aac7e1a2a1L247-R287)
   
   **Testing and Documentation:**
   
   * Added comprehensive unit tests for both the ConfigMap allowlist logic and 
the Lua snippet sandbox, ensuring that only allowed keys/values are applied and 
that sandbox escapes are not possible. 
[[1]](diffhunk://#diff-93a225df7c7c71a793f0d8679bf3e52b3d1485695cdbf26615a9b66feab1757bR111-R211)
 
[[2]](diffhunk://#diff-bf5a570b0cb400b1bce17bbdcf466aa958fa4ca2d528760841a6711860cbe468R200-R277)
   * Updated documentation to explain the new allowlist mechanism, its security 
rationale, and how operators can safely extend it. 
[[1]](diffhunk://#diff-0feec4b5635887418b63788f156bd8d252d2fb2205415afc00b3ca03bbe2e4f6R41-R49)
 
[[2]](diffhunk://#diff-2515627113bc7b3cc4805c26401bd011e82d28306ac2d3413aa11e386f4ab6d5R75-R79)
   
   **Other Minor Improvements:**
   
   * Added missing imports and minor code cleanups to support new features. 
[[1]](diffhunk://#diff-c70e431013afd3fe7a2b9134b8f0ccbe4bc4b50298a9cda70d065a5207c3b33eR20-R21)
 
[[2]](diffhunk://#diff-3f7f01da5f23b1829a75c4f9257ad78429b20042cb9a8387fd2e8515363c447dR21)
   
   These changes collectively provide a much safer and more auditable 
configuration path for ATS Ingress, reducing the risk of privilege escalation 
or code execution via Kubernetes ConfigMaps or Ingress annotations.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to