Repository navigation
v0.4.0
追加
- Kubernetes のコントローラ向けの口(#220)。Kubernetes の Gateway API で rproxy を動かすコントローラ rproxy-gateway v0.4.0 と一緒に使えます。
- ルールの組
PUT /rulesets/{name}:持っているルールの全体を 1 回で渡すと、rproxy が差分を当てます。generation・If-Match(etag)・?dry_run=trueが使え、組のルールを個別に変えると409 ownedです。組は作ったトークンのもので、トークンファイルのallow_rulesetsで扱える組の名前を絞れます。 - ルールの
labels(ログ・/metricsに出す印)、conditions(Gateway API の status の形)、GET /readyz。
- ルールの組
- Gateway API 向けの L7・TLS(#237・#239)
headersのadd、リダイレクトのステータス、ルートごとのタイムアウト、replace_host、サーバごとのミドルウェア、retryのステータス、エラーのステータスのサーバ。- 新しいミドルウェア
cors・mirror。 - 転送先への HTTP/2(
h2・h2c・auto、トレーラー)とサービスごとの TLS(CA・SNI・SAN の検証、BackendTLSPolicy)。 tls.routesの複数の宛先。client_auth: optional_no_verifyとX-Client-Verify・X-Forwarded-Client-Cert。
- L4 の送信元ごとの制限と帯域の上限(#219):ルールの
limits(同時接続・新しい接続の速さ)とbandwidth(上り・下り)。利用量の集計のための数(counters_since)。 - 制御 API の守り(#218):クライアント証明書(mTLS)とトークンの結びつけ、トークンの期限の知らせ、認証の失敗が続く送信元の一時停止(
429 locked_out)。 - GeoIP の許可・拒否(#221):MaxMind 形式のデータベースで、国・AS ごとに許可・拒否できます。
- 受け身のヘルスチェック(#221):転送の失敗が続いたサーバを一時的に外します(
outlier_detection)。 - 変更前の差分(#222):
?dry_run=true、POST /config/plan、rproxy-api --check-config --diff。 - API で作ったルールの保存(#222):トークンに
persist: trueを付けると、作ったルールを DB のrproxy_rulesに保存し、再起動の後も戻します(origin: "api")。 - 再起動なしの更新(#223):SIGUSR2 か
POST /admin/upgradeで、接続を切らずに新しいバイナリへ引き継ぎます。同じマイナーの中のパッチは、.deb の更新でも引き継ぎます。 - コンテナの自動更新(#223):入口を
rproxy-api launchにしてRPROXY_UPDATE=autoにすると、同じ X.Y の最新のパッチを取り、minisign の署名を確かめてから入れ替えます。落ちた版は自動で戻します。リリースの鍵は docs/UPGRADE.md。 - performance の設定(#223):
global.performance(workers・udp_shards・cpu_affinity・busy_poll_usecs・splice)。
修正
- クライアントが送ってきた
X-Client-Verify・X-Forwarded-Client-Certを、どのルールでも消すようにしました。tls.client_authのないルールで、偽のクライアント証明書の情報が転送先に届いていました。 mirrorの写しにも、転送先に付けるヘッダ(X-Forwarded-*・証明書)を付けるようにしました。- 転送先が HTTP/2 のとき、ストリームの空きを待ち続けて詰まることがあったのを直しました。
- 自動更新で試していた版を、止めただけで悪い版として扱っていたのを直しました。
- そのほか、セキュリティレビューの指摘を直しました(docs/DESIGN-v0.4.md の 17 節)。
変更
- サービスのユーザーが
rproxyからrproxy-api(主グループrproxy)に変わります。 .deb と install.sh が、uid を変えずに名前だけ変えるので、ファイルの持ち主はそのままです。UI(rproxy-ui)はrproxyグループに入り、グループで読めるファイルを共有できます。 - ルールが指す証明書・鍵・秘密のファイルを確かめるようになりました(
global.files.owner_check: strict、既定)。- 持ち主が rproxy-api のファイルだけを使います。グループや他人が書けるファイル、誰でも読める鍵は断ります。
- おすすめは
rproxy-api:rproxyの 0640 です。certbot の証明書は deploy hook で写してください。 - root が持つファイルを使いたい場所は、
global.files.trusted_dirsかRPROXY_FILES_TRUSTED_DIRSで指定できます(Kubernetes の Secret など)。確認を止めるにはowner_check: off。
- v0.3.x から v0.4.0 への更新は、引き継ぎではなく再起動になります(引き継ぎは同じマイナーの中だけ)。
- 接続の失敗の
target.downのログは、reason: connectからreason: outlierとcause: connectに変わりました。 - v0.4 を入れたことのある機械に v0.3 の .deb を入れ直すと、残った
rproxyグループのせいで失敗します。UI v0.4 と組み合わせるときは、rproxy-api も v0.4 にしてください。
UI: TCP-UDP-rproxy-ui v0.4.0 · Kubernetes: rproxy-gateway v0.4.0
Added
- Hooks for a Kubernetes controller (#220), used by rproxy-gateway v0.4.0 to run rproxy behind the Kubernetes Gateway API.
- Rule sets
PUT /rulesets/{name}: send the whole set of rules at once and rproxy applies the difference. Supportsgeneration,If-Match(etag) and?dry_run=true; changing a rule of a set on its own gets409 owned. A set belongs to the token that created it, andallow_rulesetsin the token file limits which set names a token may use. - Rule
labels(shown in logs and/metrics),conditions(in the shape of Gateway API status) andGET /readyz.
- Rule sets
- L7 and TLS for the Gateway API (#237, #239)
headersadd, redirect status, per-route timeouts,replace_host, per-server middlewares,retrystatus, error-status servers.- New middlewares
corsandmirror. - HTTP/2 to upstreams (
h2,h2c,auto, with trailers) and per-service TLS (CA, SNI and SAN checks; BackendTLSPolicy). - Several targets in
tls.routes. client_auth: optional_no_verifywithX-Client-VerifyandX-Forwarded-Client-Cert.
- Per-source L4 limits and bandwidth caps (#219): rule
limits(concurrent connections, new-connection rate) andbandwidth(up and down); counters for usage accounting (counters_since). - Control API hardening (#218): tokens bound to client certificates (mTLS), token-expiry notices, and a lockout for sources with repeated auth failures (
429 locked_out). - GeoIP allow and deny (#221) by country and AS, with MaxMind-format databases.
- Passive health checks (#221): servers that keep failing are taken out for a while (
outlier_detection). - Dry runs (#222):
?dry_run=true,POST /config/planandrproxy-api --check-config --diff. - Persistence for API-made rules (#222): with
persist: trueon a token, the rules it creates are saved in therproxy_rulestable and restored after a restart (origin: "api"). - Upgrades without a restart (#223): SIGUSR2 or
POST /admin/upgradehands the sockets over to a new binary without dropping connections. Patches within the same minor are handed over by the .deb upgrade too. - Self-update for containers (#223): with
rproxy-api launchas the entrypoint andRPROXY_UPDATE=auto, rproxy fetches the newest patch of its X.Y, checks its minisign signature and swaps it in; a version that crashes is rolled back. The release key is in docs/en/UPGRADE.md. - Performance settings (#223):
global.performance(workers,udp_shards,cpu_affinity,busy_poll_usecs,splice).
Fixed
X-Client-VerifyandX-Forwarded-Client-Certsent by clients are now removed on every rule; on rules withouttls.client_auth, forged client-certificate details reached upstreams.mirrorcopies now carry the same forwarding headers (X-Forwarded-*, certificate details) as the main request.- HTTP/2 upstreams could stall while waiting for a free stream.
- The self-update no longer marks a version under trial as bad just because it was stopped.
- Other findings of the security review (docs/en/DESIGN-v0.4.md, section 17).
Changed
- The service user changes from
rproxytorproxy-api(primary grouprproxy). The .deb and install.sh rename the user and keep its uid, so file ownership stays valid. The UI user (rproxy-ui) joins therproxygroup and can read group-readable files. - Files that rules point at are now checked (
global.files.owner_check: strict, the default).- Only files owned by rproxy-api are used. Files writable by the group or others, and keys readable by anyone, are refused.
- The recommended mode is
rproxy-api:rproxy0640. Copy certbot's certificates with a deploy hook. - Directories where root-owned files are acceptable (Kubernetes Secrets, for one) can be listed in
global.files.trusted_dirsorRPROXY_FILES_TRUSTED_DIRS.owner_check: offturns the check off.
- Upgrading from v0.3.x to v0.4.0 restarts the service (handover works only within the same minor).
target.downfor connection failures now logsreason: outlierwithcause: connectinstead ofreason: connect.- Installing a v0.3 .deb again on a machine that had v0.4 fails because of the leftover
rproxygroup. With UI v0.4, use rproxy-api v0.4 as well.
UI: TCP-UDP-rproxy-ui v0.4.0 · Kubernetes: rproxy-gateway v0.4.0