Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Block new incoming connections to seed cluster from vpn tunnel #874

Merged
merged 1 commit into from Mar 28, 2019

Conversation

@DockToFuture
Copy link
Member

commented Mar 27, 2019

What this PR does / why we need it:
Set iptable rule to block new incoming connections from shoot cluster but allow icmp connections.

Which issue(s) this PR fixes:
Fixes: gardener/vpn#40

Special notes for your reviewer:
The important traffic is going through the public endpoint, so not affected by this PR.

Release note:

Traffic from shoot to seed via the VPN endpoint is now blocked.

@DockToFuture DockToFuture requested a review from gardener/gardener-maintainers as a code owner Mar 27, 2019

@DockToFuture DockToFuture force-pushed the DockToFuture:feature/block-new-traffic branch from 4f58f12 to 2044d50 Mar 27, 2019

@rfranzke

This comment has been minimized.

Copy link
Member

commented Mar 27, 2019

Can you elaborate what exactly happens here? What is blocked, etc.?

@zanetworker

This comment has been minimized.

Copy link
Contributor

commented Mar 27, 2019

Do we really want to block all traffic to the API server? There are things that needs to talk to the API server still e.g., Kube-proxy, kubelet, ...etc

@rfranzke
Copy link
Member

left a comment

You have to add alpine to list of injected images during deployment, e.g. https://github.com/gardener/gardener/blob/master/pkg/operation/hybridbotanist/controlplane.go#L379 for kube-apiserver (similar for prometheus).

@DockToFuture DockToFuture force-pushed the DockToFuture:feature/block-new-traffic branch from f2e3ebb to 97896f4 Mar 28, 2019

@rfranzke
Copy link
Member

left a comment

/lgtm

@zanetworker
Copy link
Contributor

left a comment

/lgtm

@rfranzke rfranzke merged commit 1cdd5aa into gardener:master Mar 28, 2019

4 checks passed

concourse-ci/check Concourse CI build success
Details
concourse-ci/publish Concourse CI build success
Details
concourse-ci/test Concourse CI build success
Details
license/cla Contributor License Agreement is signed.
Details
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
You can’t perform that action at this time.