Repository navigation
feat(rootfs): isolate envd in a dedicated network namespace #2700
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Closed
Closed
Changes from all commits
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
37 changes: 37 additions & 0 deletions
37
packages/orchestrator/pkg/template/build/core/rootfs/files/e2b-netns.service.tpl
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,37 @@ | ||
| {{- /*gotype:github.com/e2b-dev/infra/packages/orchestrator/pkg/template/build/core/rootfs.templateModel*/ -}} | ||
| {{ .WriteFile "/etc/systemd/system/e2b-netns.service" 0o644 }} | ||
|
|
||
| [Unit] | ||
| Description=E2B envd network namespace setup | ||
| DefaultDependencies=no | ||
| After=systemd-networkd.service | ||
| Requires=systemd-networkd.service | ||
| Before=network.target sysinit.target | ||
|
|
||
| [Service] | ||
| Type=oneshot | ||
| RemainAfterExit=yes | ||
|
|
||
| # Create the namespace and move eth0 + the envd-side veth peer into it. | ||
| # `-` prefix ignores failure so re-runs across reboots are idempotent. | ||
| ExecStart=-/sbin/ip netns add envd-ns | ||
| ExecStart=-/sbin/ip link set eth0 netns envd-ns | ||
| ExecStart=-/sbin/ip link set veth-envd netns envd-ns | ||
|
|
||
| # Configure interfaces inside envd-ns (systemd-networkd doesn't run there). | ||
| ExecStart=-/sbin/ip -n envd-ns link set lo up | ||
| ExecStart=-/sbin/ip -n envd-ns addr add 169.254.0.21/30 dev eth0 | ||
| ExecStart=-/sbin/ip -n envd-ns link set eth0 up | ||
| ExecStart=-/sbin/ip -n envd-ns route add default via 169.254.0.22 | ||
| ExecStart=-/sbin/ip -n envd-ns addr add 192.168.250.2/30 dev veth-envd | ||
| ExecStart=-/sbin/ip -n envd-ns link set veth-envd up | ||
| ExecStart=/sbin/ip netns exec envd-ns sysctl -qw net.ipv4.ip_forward=1 | ||
|
|
||
| # Idempotent iptables: -C check before -A. Wrapped in sh because there is no | ||
| # declarative systemd directive for "add rule if not present". | ||
| ExecStart=/bin/sh -c 'ip netns exec envd-ns iptables -t nat -C POSTROUTING -o eth0 -j MASQUERADE 2>/dev/null || ip netns exec envd-ns iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE' | ||
| ExecStart=/bin/sh -c 'ip netns exec envd-ns iptables -t nat -C PREROUTING -i eth0 -p tcp --dport 49983 -j RETURN 2>/dev/null || ip netns exec envd-ns iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 49983 -j RETURN' | ||
| ExecStart=/bin/sh -c 'ip netns exec envd-ns iptables -t nat -C PREROUTING -i eth0 -p tcp -j DNAT --to-destination 192.168.250.1 2>/dev/null || ip netns exec envd-ns iptables -t nat -A PREROUTING -i eth0 -p tcp -j DNAT --to-destination 192.168.250.1' | ||
|
|
||
| [Install] | ||
| WantedBy=sysinit.target |
9 changes: 9 additions & 0 deletions
9
packages/orchestrator/pkg/template/build/core/rootfs/files/e2b-veth-customer.network.tpl
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,9 @@ | ||
| {{- /*gotype:github.com/e2b-dev/infra/packages/orchestrator/pkg/template/build/core/rootfs.templateModel*/ -}} | ||
| {{ .WriteFile "/etc/systemd/network/10-e2b-veth-customer.network" 0o644 }} | ||
|
|
||
| [Match] | ||
| Name=veth-customer | ||
|
|
||
| [Network] | ||
| Address=192.168.250.1/30 | ||
| Gateway=192.168.250.2 |
9 changes: 9 additions & 0 deletions
9
packages/orchestrator/pkg/template/build/core/rootfs/files/e2b-veth.netdev.tpl
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,9 @@ | ||
| {{- /*gotype:github.com/e2b-dev/infra/packages/orchestrator/pkg/template/build/core/rootfs.templateModel*/ -}} | ||
| {{ .WriteFile "/etc/systemd/network/10-e2b-veth.netdev" 0o644 }} | ||
|
|
||
| [NetDev] | ||
| Name=veth-customer | ||
| Kind=veth | ||
|
|
||
| [Peer] | ||
| Name=veth-envd |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Child processes spawned by envd inherit wrong network namespace
High Severity
NetworkNamespacePath=/run/netns/envd-nscauses all child processes forked by envd (socat port forwarders, user terminal sessions, command execution) to inheritenvd-ns. The existing socat port forwarder binds to169.254.0.21:portinenvd-nsand tries to connect tolocalhost:portinenvd-ns— but customer processes listen in the default namespace's loopback, which is unreachable fromenvd-ns. Additionally, any user-facing process spawning (terminals, exec) would place the user process in the wrong network namespace whereveth-customer(192.168.250.1) isn't visible.Reviewed by Cursor Bugbot for commit 91fea54. Configure here.