From 4a34b354410842c1b18eec64c08db71d2d29db33 Mon Sep 17 00:00:00 2001 From: Grant Whitmer Date: Wed, 23 Sep 2026 03:20:45 -0400 Subject: [PATCH] =?UTF-8?q?security:=20CI=20egress=20filter=20=E2=80=94=20?= =?UTF-8?q?jobs=20reach=20the=20internet,=20never=20Veron/LAN?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Measured: an unprivileged job container inside the CI dind could open SSH, Ollama and dev servers on Veron (192.168.1.73) and the rest of the LAN, WireGuard and Tailscale — lateral movement for any malicious dependency, no escape needed. egress.sh (idempotent; windygit-ci-egress.service at boot) hooks the jobs bridge: runner<->dind, replies, DNS and public egress allowed; RFC1918, CGNAT, link-local and the host itself dropped. Verified from a job container: 6/6 private targets blocked, DNS, internet and the public forge OK. Co-Authored-By: Claude Opus 5.5 --- deploy/runner/egress.sh | 51 ++++++++++++++++++++++++ deploy/runner/windygit-ci-egress.service | 13 ++++++ 2 files changed, 64 insertions(+) create mode 100755 deploy/runner/egress.sh create mode 100644 deploy/runner/windygit-ci-egress.service diff --git a/deploy/runner/egress.sh b/deploy/runner/egress.sh new file mode 100755 index 0000000..823f976 --- /dev/null +++ b/deploy/runner/egress.sh @@ -0,0 +1,51 @@ +#!/usr/bin/env bash +# CI egress filter (2026-09-23) — jobs reach the internet, never Grant's network. +# +# Measured before this existed: an ordinary (unprivileged) job container inside +# the CI dind could open SSH, Ollama, and every dev server on Veron +# (192.168.1.73:22/3000/3300/8080/11434) and anything else on the LAN, WireGuard +# or Tailscale. No container escape needed — a malicious npm/pip dependency in +# any first-party repo's CI could walk straight onto the fleet. +# +# All CI traffic leaves through the `windy-git-runner_jobs` bridge (dind NATs +# its job containers onto it). This script, run at boot and after any runner +# compose change, allows on that bridge: +# * traffic between the runners and dind (same bridge) +# * replies (ESTABLISHED/RELATED) +# * DNS (53) — Docker's embedded resolver forwards to the LAN router +# * everything public +# and drops: RFC1918, CGNAT/Tailscale (100.64/10), link-local, and ANY packet +# addressed to the host itself (INPUT), whatever interface IP it targets. +# Idempotent: owned chains are flushed and rebuilt; hooks are added once. +set -euo pipefail + +NET=windy-git-runner_jobs +id=$(docker network inspect "$NET" --format '{{.Id}}') +BR="br-${id:0:12}" +ip link show "$BR" >/dev/null + +iptables -N WG-CI-EGRESS 2>/dev/null || iptables -F WG-CI-EGRESS +iptables -A WG-CI-EGRESS -o "$BR" -j RETURN +iptables -A WG-CI-EGRESS -m conntrack --ctstate ESTABLISHED,RELATED -j RETURN +iptables -A WG-CI-EGRESS -p udp --dport 53 -j RETURN +iptables -A WG-CI-EGRESS -p tcp --dport 53 -j RETURN +for cidr in 10.0.0.0/8 172.16.0.0/12 192.168.0.0/16 100.64.0.0/10 169.254.0.0/16; do + iptables -A WG-CI-EGRESS -d "$cidr" -j DROP +done +iptables -A WG-CI-EGRESS -j RETURN + +iptables -N WG-CI-INPUT 2>/dev/null || iptables -F WG-CI-INPUT +iptables -A WG-CI-INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j RETURN +iptables -A WG-CI-INPUT -j DROP + +# Hooks: remove any stale ones (the bridge name changes if the network is +# recreated), then add exactly one of each at the top. +for chain in DOCKER-USER INPUT; do + target=$([ "$chain" = INPUT ] && echo WG-CI-INPUT || echo WG-CI-EGRESS) + while read -r rule; do + iptables -D $chain ${rule#-A $chain } + done < <(iptables -S "$chain" | grep -- "-j $target" || true) + iptables -I "$chain" 1 -i "$BR" -j "$target" +done + +echo "ci egress filter active on $BR ($NET)" diff --git a/deploy/runner/windygit-ci-egress.service b/deploy/runner/windygit-ci-egress.service new file mode 100644 index 0000000..d59b473 --- /dev/null +++ b/deploy/runner/windygit-ci-egress.service @@ -0,0 +1,13 @@ +[Unit] +Description=Windy Git - CI egress filter (jobs reach the internet, never the LAN/host) +After=docker.service +Requires=docker.service + +[Service] +Type=oneshot +RemainAfterExit=yes +# The jobs network exists once the runner compose project is up; retry until it does. +ExecStart=/bin/bash -c 'for i in $(seq 1 60); do /srv/windygit/src/deploy/runner/egress.sh && exit 0; sleep 5; done; exit 1' + +[Install] +WantedBy=multi-user.target