fix(tofu): drop Neutron's default allow-all egress on the runner and drill groups #483
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!483
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "fix/471-egress-default-rules"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
What
Set
delete_default_rules = trueon the ephemeral-runner and backup-drill security groups, and add the egress those VMs need before the defaults go away.Neutron attaches allow-all IPv4 and IPv6 egress to every new group. Neither group deleted them, so the explicit 443/53 rules restricted nothing and CI runner VMs ran job code with unrestricted outbound. Confirmed live before the change:
Both groups had the same pair.
New rules
169.254.169.254/32— cloud-init metadata probe.Port 80 to the world is deliberately not allowed. The runner image is baked (no per-boot installs — see
runner-userdata.yaml.tmpl) and no workflow in any repo installs packages at job time. The drill VM runs podman pulls over 443 only.Both VMs boot with
config_drive = true, so user-data comes off the config drive rather than the metadata service. The metadata rule covers cloud-init's datasource probe anyway; it is one rule to a link-local address.Apply notes
delete_default_rulesforces replacement of both groups. Plan is 20 to add, 14 to destroy, and both group IDs change.Both consumers reference the group by name, not ID:
runner-controller/defaults/main.yml:88→gitborg-prod-ephemeral-runner-sgbackup-drill/defaults/main.yml:68→gitborg-prod-backup-drill-sgSo no Ansible re-apply is needed. The apply must happen while no runner or drill VM is attached, or Neutron refuses to delete the in-use group. The drill timer is
Sat *-*-* 06:00:00.Verification plan
After apply: confirm the two
None-protocol rules are gone from both groups, then boot one runner (queue a CI job) and one drill VM and confirm both complete.Closes #471