docs(external-database-exposure): make the plaintext-exposure rule per engine - #91
Open
Aleksei Sviridkin (lexfrei) wants to merge 1 commit into
Open
Aleksei Sviridkin (lexfrei) wants to merge 1 commit into
Aleksei Sviridkin (lexfrei) wants to merge 1 commit into
Conversation
…r engine The Security section had one admission rule for every engine, written before redis had TLS, and it only fits the postgres chart's tri-state. For postgres it closes nothing: CloudNativePG keeps ssl on and its default pg_hba accepts plaintext whatever tls.enabled says. Redis TLS is opt-in and fixed at creation, so the implemented rule requires TLS when an instance is created external, refuses exposure after creation, and refuses TLS changes while exposed. Record 0002 keeps the alternatives that lost. Also correct the Postgres SNI mechanism. A client is unroutable when it sends a plaintext SSLRequest before the handshake, which a passthrough listener never reads; the server version does not decide that. A direct-negotiation client against a pre-17 server does not fall back: it is routed and the server closes the connection. The certificate hooks section now names the redis and mariadb SAN hooks that arrived with their TLS support instead of calling them open pull requests. Assisted-by: LLM Signed-off-by: Aleksei Sviridkin <f@lex.la>
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The admission rule in the Security section of
external-database-exposuredoes not hold for the engines it was written for, so this changes it to a per-engine rule and records why in decision 0002.The old rule refused an explicit
tls.enabled: falsewithexternal: truefor every engine. It was written before redis had TLS and only fits postgres's tri-state. For postgres it closes nothing: CloudNativePG keeps TLS offered and accepts plaintext from a client that asks, whatevertls.enabledsays (cozystack/cozystack#4619). Redis TLS, added in cozystack/cozystack#2729, is opt-in and fixed at creation, and the API accepts a change the operator refuses. So the rule implemented in cozystack/cozystack#4639 covers redis only: exposing it needs TLS at creation, an update cannot turnexternalon, andtls.enabledis frozen whileexternalstays on.The record keeps the alternatives that lost, with the test case in #4639 that pins each bypass. The same change corrects the Postgres SNI edge cases. A client without direct TLS negotiation does not lack SNI, it sends a plaintext protocol message first, which a passthrough listener never reads.
This should merge after cozystack/cozystack#4639, since the record states what that PR implements.
Before review
decisions/directory, or says below why none is needed.DCO
git commit --signoff).