Skip to content

v0.4.0

Choose a tag to compare

@max3584 max3584 released this 07 Oct 17:17
ce742f3

rproxy-api v0.3.5 以上で動きます。v0.4 の項目を使うには rproxy-api v0.4.0 が要ります(使えない項目は画面で知らせます)。

追加

  • rproxy-api v0.4 のルールの項目をフォームと詳細画面で扱えます(#127・#131):送信元ごとの制限(limits)、帯域の上限(bandwidth)、GeoIP、受け身のヘルスチェック、ラベル、状態(conditions)、Gateway API 向けの L7・TLS の項目(headers の add、CORS、ミラー、HTTP/2 の転送先、サービスごとの TLS など)。
  • 変更前の差分(#127):保存の前に、rproxy で何が変わるか(作る・変える・作り直す・消す)を確かめられます。
  • 制御 API の mTLS(#127):RPROXY_API_TLS_* でクライアント証明書を使って rproxy-api に接続できます。
  • rproxy の API で作ったルールを見て変える(#128):rproxy の rproxy_rules(origin: "api")とルールの組のルールを一覧に出し、管理者は rproxy の API を通して変えられます。
  • 利用量の集計(#129・#130):ルールごとの通信量を時間・日・月で集計し、所有者・ラベルごとのグラフと CSV で見られます。

修正

  • rproxy の API やルールの組で作ったルールと同じキーの UI のルールを変えると、そのルールを上書きしていたのを直しました(409 shadowed。削除・停止は UI の DB の行だけを変えます)。
  • 利用者に、設定ファイルのパス・内部のエラーの文・バイナリのハッシュ・トークンの名前を見せないようにしました。
  • ほかのサイトからの書き込みの要求を断るようにしました(CSRF)。
  • 所有者やラベルが変わったとき、前の利用量の記録を書き換えていたのを直しました。
  • RPROXY_API_URL が http:// のときに、mTLS の設定とトークンを平文で送っていたのを、起動時に止めるようにしました。
  • CSV の書き出しで、表計算ソフトの数式として読まれる値をすべて無害化するようにしました。

変更

  • 利用量の集計を使っている環境では、UI を上げる前に db/migrations/011_usage_attr.sql を当ててください。 006〜010(v0.4 の項目、rproxy_rules、利用量の表)もまだなら一緒に当ててください。
  • rproxy-ui ユーザーを rproxy グループに入れ、ユニットに SupplementaryGroups=rproxy を足しました。同じ機械の rproxy-api のトークンは、写さずに RPROXY_API_TOKEN_FILE=/etc/rproxy/tokens をグループの権限で読みます(前の版の設定もそのまま動きます)。
  • UI を別のリバースプロキシの後ろに置いているときは、前のプロキシが Host か X-Forwarded-Host を渡すか、NEXTAUTH_URL を利用者が開く URL にしてください(CSRF の確認のため)。
  • rproxy-api v0.4.0 は、持ち主が rproxy-api でない証明書・鍵のファイルを断ります。画面には直し方(chown rproxy-api:rproxy、0640)を出します。

rproxy-api: v0.4.0


Works with rproxy-api v0.3.5 or later. The v0.4 items need rproxy-api v0.4.0 (the UI says when an item is not available).

Added

  • Forms and detail pages for the rproxy-api v0.4 rule items (#127, #131): per-source limits, bandwidth caps, GeoIP, passive health checks, labels, conditions, and the L7/TLS items for the Gateway API (headers add, CORS, mirror, HTTP/2 upstreams, per-service TLS and more).
  • Dry runs (#127): see what rproxy would create, change, recreate or remove before saving.
  • mTLS to the control API (#127): RPROXY_API_TLS_* connects to rproxy-api with a client certificate.
  • Rules made through rproxy's API (#128): rules from rproxy_rules (origin: "api") and from rule sets are listed, and admins can change them through rproxy's API.
  • Usage accounting (#129, #130): traffic per rule by hour, day and month, with charts and CSV by owner and label.

Fixed

  • Changing a UI rule with the same key as a rule made through rproxy's API or a rule set overwrote that rule; it is now refused (409 shadowed; delete and pause change only the UI's own row).
  • Users no longer see settings file paths, internal error texts, binary hashes or token names.
  • Write requests from other sites are refused (CSRF).
  • A change of owner or labels rewrote earlier usage records.
  • With an http:// RPROXY_API_URL, the mTLS settings and the token were sent in the clear; this is now refused at startup.
  • CSV exports neutralise every value a spreadsheet would read as a formula.

Changed

  • If you use usage accounting, apply db/migrations/011_usage_attr.sql before upgrading the UI. Apply 006 to 010 (v0.4 items, rproxy_rules, usage tables) too if you have not yet.
  • The rproxy-ui user joins the rproxy group, and the unit gets SupplementaryGroups=rproxy. The token of rproxy-api on the same machine is read in place through the group (RPROXY_API_TOKEN_FILE=/etc/rproxy/tokens) instead of being copied; older env files keep working.
  • Behind another reverse proxy, have it pass Host or X-Forwarded-Host, or set NEXTAUTH_URL to the URL users open (for the CSRF check).
  • rproxy-api v0.4.0 refuses certificate and key files not owned by rproxy-api; the UI shows how to fix them (chown rproxy-api:rproxy, 0640).

rproxy-api: v0.4.0