security: CI egress filter — jobs reach the internet, never Veron/LAN
Measured: an unprivileged job container inside the CI dind could open SSH, Ollama and dev servers on Veron (192.168.1.73) and the rest of the LAN, WireGuard and Tailscale — lateral movement for any malicious dependency, no escape needed. egress.sh (idempotent; windygit-ci-egress.service at boot) hooks the jobs bridge: runner<->dind, replies, DNS and public egress allowed; RFC1918, CGNAT, link-local and the host itself dropped. Verified from a job container: 6/6 private targets blocked, DNS, internet and the public forge OK. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
13
deploy/runner/windygit-ci-egress.service
Normal file
13
deploy/runner/windygit-ci-egress.service
Normal file
@@ -0,0 +1,13 @@
|
||||
[Unit]
|
||||
Description=Windy Git - CI egress filter (jobs reach the internet, never the LAN/host)
|
||||
After=docker.service
|
||||
Requires=docker.service
|
||||
|
||||
[Service]
|
||||
Type=oneshot
|
||||
RemainAfterExit=yes
|
||||
# The jobs network exists once the runner compose project is up; retry until it does.
|
||||
ExecStart=/bin/bash -c 'for i in $(seq 1 60); do /srv/windygit/src/deploy/runner/egress.sh && exit 0; sleep 5; done; exit 1'
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
Reference in New Issue
Block a user