Skip to content

docs(external-database-exposure): make the plaintext-exposure rule per engine - #91

Open
Aleksei Sviridkin (lexfrei) wants to merge 1 commit into
mainfrom
docs/edx-redis-plaintext-rule
Open

Aleksei Sviridkin (lexfrei) wants to merge 1 commit into
mainfrom
docs/edx-redis-plaintext-rule

Conversation

@lexfrei

Copy link
Copy Markdown
Contributor

The admission rule in the Security section of external-database-exposure does not hold for the engines it was written for, so this changes it to a per-engine rule and records why in decision 0002.

The old rule refused an explicit tls.enabled: false with external: true for every engine. It was written before redis had TLS and only fits postgres's tri-state. For postgres it closes nothing: CloudNativePG keeps TLS offered and accepts plaintext from a client that asks, whatever tls.enabled says (cozystack/cozystack#4619). Redis TLS, added in cozystack/cozystack#2729, is opt-in and fixed at creation, and the API accepts a change the operator refuses. So the rule implemented in cozystack/cozystack#4639 covers redis only: exposing it needs TLS at creation, an update cannot turn external on, and tls.enabled is frozen while external stays on.

The record keeps the alternatives that lost, with the test case in #4639 that pins each bypass. The same change corrects the Postgres SNI edge cases. A client without direct TLS negotiation does not lack SNI, it sends a plaintext protocol message first, which a passthrough listener never reads.

This should merge after cozystack/cozystack#4639, since the record states what that PR implements.

Before review

  • If this revises a merged design proposal: it adds a decision record under that proposal's decisions/ directory, or says below why none is needed.

DCO

  • Commits are signed off (git commit --signoff).

…r engine

The Security section had one admission rule for every engine, written
before redis had TLS, and it only fits the postgres chart's tri-state.
For postgres it closes nothing: CloudNativePG keeps ssl on and its
default pg_hba accepts plaintext whatever tls.enabled says. Redis TLS
is opt-in and fixed at creation, so the implemented rule requires TLS
when an instance is created external, refuses exposure after creation,
and refuses TLS changes while exposed. Record 0002 keeps the
alternatives that lost.

Also correct the Postgres SNI mechanism. A client is unroutable when it
sends a plaintext SSLRequest before the handshake, which a passthrough
listener never reads; the server version does not decide that. A
direct-negotiation client against a pre-17 server does not fall back:
it is routed and the server closes the connection. The certificate
hooks section now names the redis and mariadb SAN hooks that arrived
with their TLS support instead of calling them open pull requests.

Assisted-by: LLM
Signed-off-by: Aleksei Sviridkin <f@lex.la>
@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 9af3edaf-26bd-483f-9ec5-ae332eea57b4

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant