fix(tofu): drop Neutron's default allow-all egress on the runner and drill groups #483

Sammanfogat
supernaut sammanfogade 1 incheckning från fix/471-egress-default-rules in i main 2026-09-19 13:16:15 +00:00
Ägare

What

Set delete_default_rules = true on the ephemeral-runner and backup-drill security groups, and add the egress those VMs need before the defaults go away.

Neutron attaches allow-all IPv4 and IPv6 egress to every new group. Neither group deleted them, so the explicit 443/53 rules restricted nothing and CI runner VMs ran job code with unrestricted outbound. Confirmed live before the change:

$ openstack security group rule list gitborg-prod-ephemeral-runner-sg
None IPv6 ::/0       egress      <- default allow-all
None IPv4 0.0.0.0/0  egress      <- default allow-all
tcp  IPv4 0.0.0.0/0 443:443 egress
...

Both groups had the same pair.

New rules

  • TCP 80 to 169.254.169.254/32 — cloud-init metadata probe.
  • UDP 123 (v4 + v6) — NTP; a skewed clock breaks TLS and token validation.

Port 80 to the world is deliberately not allowed. The runner image is baked (no per-boot installs — see runner-userdata.yaml.tmpl) and no workflow in any repo installs packages at job time. The drill VM runs podman pulls over 443 only.

Both VMs boot with config_drive = true, so user-data comes off the config drive rather than the metadata service. The metadata rule covers cloud-init's datasource probe anyway; it is one rule to a link-local address.

Apply notes

delete_default_rules forces replacement of both groups. Plan is 20 to add, 14 to destroy, and both group IDs change.

Both consumers reference the group by name, not ID:

  • runner-controller/defaults/main.yml:88 → gitborg-prod-ephemeral-runner-sg
  • backup-drill/defaults/main.yml:68 → gitborg-prod-backup-drill-sg

So no Ansible re-apply is needed. The apply must happen while no runner or drill VM is attached, or Neutron refuses to delete the in-use group. The drill timer is Sat *-*-* 06:00:00.

Verification plan

After apply: confirm the two None-protocol rules are gone from both groups, then boot one runner (queue a CI job) and one drill VM and confirm both complete.

Closes #471

## What Set `delete_default_rules = true` on the ephemeral-runner and backup-drill security groups, and add the egress those VMs need before the defaults go away. Neutron attaches allow-all IPv4 and IPv6 egress to every new group. Neither group deleted them, so the explicit 443/53 rules restricted nothing and CI runner VMs ran job code with unrestricted outbound. Confirmed live before the change: ``` $ openstack security group rule list gitborg-prod-ephemeral-runner-sg None IPv6 ::/0 egress <- default allow-all None IPv4 0.0.0.0/0 egress <- default allow-all tcp IPv4 0.0.0.0/0 443:443 egress ... ``` Both groups had the same pair. ## New rules - TCP 80 to `169.254.169.254/32` — cloud-init metadata probe. - UDP 123 (v4 + v6) — NTP; a skewed clock breaks TLS and token validation. Port 80 to the world is deliberately **not** allowed. The runner image is baked (no per-boot installs — see `runner-userdata.yaml.tmpl`) and no workflow in any repo installs packages at job time. The drill VM runs podman pulls over 443 only. Both VMs boot with `config_drive = true`, so user-data comes off the config drive rather than the metadata service. The metadata rule covers cloud-init's datasource probe anyway; it is one rule to a link-local address. ## Apply notes `delete_default_rules` forces replacement of both groups. Plan is 20 to add, 14 to destroy, and both group IDs change. Both consumers reference the group by **name**, not ID: - `runner-controller/defaults/main.yml:88` → `gitborg-prod-ephemeral-runner-sg` - `backup-drill/defaults/main.yml:68` → `gitborg-prod-backup-drill-sg` So no Ansible re-apply is needed. The apply must happen while no runner or drill VM is attached, or Neutron refuses to delete the in-use group. The drill timer is `Sat *-*-* 06:00:00`. ## Verification plan After apply: confirm the two `None`-protocol rules are gone from both groups, then boot one runner (queue a CI job) and one drill VM and confirm both complete. Closes #471
supernaut lade till 1 incheckning 2026-09-19 12:58:29 +00:00
fix(tofu): drop Neutron's default allow-all egress on the runner and drill groups
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m53s
e453df7d22
Neither security group set delete_default_rules, so Neutron's allow-all IPv4
and IPv6 egress rules stayed attached and the explicit 443/53 rules restricted
nothing. CI runner VMs ran job code with unrestricted outbound.

Adds the egress the VMs actually need before removing the defaults: TCP 80 to
169.254.169.254/32 for cloud-init's metadata probe, and UDP 123 for NTP. Port
80 to the world is deliberately not allowed - the runner image is baked, and no
workflow in any repo installs packages at job time.

Setting delete_default_rules forces replacement of both groups. Both consumers
(runner-controller and the backup-drill orchestrator) reference the group by
name, not id, so no Ansible re-apply is needed; the apply must happen while no
runner or drill VM is attached.

Closes #471

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
supernaut sammanfogade incheckning e51097ee0e till main 2026-09-19 13:16:15 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!483
Ingen beskrivning angiven.