envoyproxy / envoyproxy/envoy

Admin endpoint security

オープン
#2,763 コメント 38 件 リアクション 39 件 担当者 0 名 GitHub で見る
area/admin area/security help wanted tech debt
主要言語
C++
スター
28.9k
フォーク
5.6k
平均マージ
1日 22時間
マージ済み PR(30日)
430

説明

The admin endpoint today is unsecured (no authentication or TLS), with the assumption that it is only available to localhost or accessible on a trusted network. Ideally:

* We want to be able to restrict access to only trusted IPs, client certificates and ensure we have transport security.
* We want to have some ability to distinguish roles and access to the admin console, i.e. distinct identities might be allowed to operate `/quitquitquit` vs. stats monitoring.

Beyond just security, there's also the question of what the admin console is. Is it just a `curl`able utility, an interactive web console or is it a first-class API intended for programatic use? Should it offer gRPC endpoints (in particular as we are moving towards a proto definition of its contents in places such as https://github.com/envoyproxy/envoy/issues/2172). Answers to this affect the framing of security considerations.

Opening this issue to start the design discussion here.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。