tofu: runner and drill security groups keep Neutron's default allow-all egress #471
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra#471
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "%!s()"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
opentofu/ephemeral-runners.tofuandopentofu/backup-drill.tofudeclare egress rules for 443 and 53 only and describe the groups that way. Neither setsdelete_default_rules = true, so Neutron's default allow-all IPv4 and IPv6 egress rules stay attached and the explicit rules restrict nothing. CI runner VMs run job code with unrestricted outbound.Deleting the defaults is a two-line change but not a no-op:
169.254.169.254:80at boot; without an explicit rule the runner never registers.apt-get installreach Debian mirrors over port 80.Plan: add explicit rules for metadata (80/tcp to
169.254.169.254/32) and NTP, decide whether port 80 to the world is allowed for jobs or whether the runner image bakes what jobs need, then setdelete_default_rules = trueon both groups and boot one runner and one drill VM to prove it. Verify the live rule set first withopenstack security group show.Applied and verified on 2026-09-19 (PR #483).
Live rule set after the apply, both groups, with Neutron's default allow-all IPv4 and IPv6 egress gone:
Runner proof: the CI run for PR #485 booted
ephemeral-runner-0a06c154against the new group and completed green, so cloud-init, runner registration and the job itself all work without the default egress. The drill group's proof folds into the next scheduled drill.One side effect worth recording.
delete_default_rulesforces replacement of the group, and the old drill group also carried ingress on 22 and 2222 from155.4.69.98/32. Those rules were never in the tofu state (tofu state listshows nine rules plus the group, none of them a 155 prefix) andlocal.backup_drill_ssh_cidrfalls back tovar.subnet_cidr, so they were added out-of-band at some point and the replacement swept them. Drill VMs get no floating IP, so a public-source ingress rule had nothing to match; the deletion looks like cleanup rather than a regression. If direct admin SSH to a drill VM is ever wanted, declare it in tofu rather than adding it by hand.Drill-side proof, 2026-09-20. A manual
bitborg-backup-drill.servicerun booted a VM under the replacedgitborg-prod-backup-drill-sgand passed:So the VM reached the metadata service at boot, resolved DNS, and pulled images over 443 with the default allow-all egress gone. No VM or boot volume leaked.
Both groups are now proven under a real workload: the runner group by the CI run for PR #485, the drill group by this.