Skip to content

v0.4.0

Choose a tag to compare

@github-actions github-actions released this 07 Oct 17:08
· 75 commits to master since this release
d2df0d1

追加

  • Kubernetes のコントローラ向けの口(#220)。Kubernetes の Gateway API で rproxy を動かすコントローラ rproxy-gateway v0.4.0 と一緒に使えます。
    • ルールの組 PUT /rulesets/{name}:持っているルールの全体を 1 回で渡すと、rproxy が差分を当てます。generation・If-Match(etag)・?dry_run=true が使え、組のルールを個別に変えると 409 owned です。組は作ったトークンのもので、トークンファイルの allow_rulesets で扱える組の名前を絞れます。
    • ルールの labels(ログ・/metrics に出す印)、conditions(Gateway API の status の形)、GET /readyz。
  • Gateway API 向けの L7・TLS(#237・#239)
    • headers の add、リダイレクトのステータス、ルートごとのタイムアウト、replace_host、サーバごとのミドルウェア、retry のステータス、エラーのステータスのサーバ。
    • 新しいミドルウェア cors・mirror。
    • 転送先への HTTP/2(h2・h2c・auto、トレーラー)とサービスごとの TLS(CA・SNI・SAN の検証、BackendTLSPolicy)。
    • tls.routes の複数の宛先。
    • client_auth: optional_no_verify と X-Client-Verify・X-Forwarded-Client-Cert。
  • L4 の送信元ごとの制限と帯域の上限(#219):ルールの limits(同時接続・新しい接続の速さ)と bandwidth(上り・下り)。利用量の集計のための数(counters_since)。
  • 制御 API の守り(#218):クライアント証明書(mTLS)とトークンの結びつけ、トークンの期限の知らせ、認証の失敗が続く送信元の一時停止(429 locked_out)。
  • GeoIP の許可・拒否(#221):MaxMind 形式のデータベースで、国・AS ごとに許可・拒否できます。
  • 受け身のヘルスチェック(#221):転送の失敗が続いたサーバを一時的に外します(outlier_detection)。
  • 変更前の差分(#222):?dry_run=true、POST /config/plan、rproxy-api --check-config --diff。
  • API で作ったルールの保存(#222):トークンに persist: true を付けると、作ったルールを DB の rproxy_rules に保存し、再起動の後も戻します(origin: "api")。
  • 再起動なしの更新(#223):SIGUSR2 か POST /admin/upgrade で、接続を切らずに新しいバイナリへ引き継ぎます。同じマイナーの中のパッチは、.deb の更新でも引き継ぎます。
  • コンテナの自動更新(#223):入口を rproxy-api launch にして RPROXY_UPDATE=auto にすると、同じ X.Y の最新のパッチを取り、minisign の署名を確かめてから入れ替えます。落ちた版は自動で戻します。リリースの鍵は docs/UPGRADE.md。
  • performance の設定(#223):global.performance(workers・udp_shards・cpu_affinity・busy_poll_usecs・splice)。

修正

  • クライアントが送ってきた X-Client-Verify・X-Forwarded-Client-Cert を、どのルールでも消すようにしました。tls.client_auth のないルールで、偽のクライアント証明書の情報が転送先に届いていました。
  • mirror の写しにも、転送先に付けるヘッダ(X-Forwarded-*・証明書)を付けるようにしました。
  • 転送先が HTTP/2 のとき、ストリームの空きを待ち続けて詰まることがあったのを直しました。
  • 自動更新で試していた版を、止めただけで悪い版として扱っていたのを直しました。
  • そのほか、セキュリティレビューの指摘を直しました(docs/DESIGN-v0.4.md の 17 節)。

変更

  • サービスのユーザーが rproxy から rproxy-api(主グループ rproxy)に変わります。 .deb と install.sh が、uid を変えずに名前だけ変えるので、ファイルの持ち主はそのままです。UI(rproxy-ui)は rproxy グループに入り、グループで読めるファイルを共有できます。
  • ルールが指す証明書・鍵・秘密のファイルを確かめるようになりました(global.files.owner_check: strict、既定)。
    • 持ち主が rproxy-api のファイルだけを使います。グループや他人が書けるファイル、誰でも読める鍵は断ります。
    • おすすめは rproxy-api:rproxy の 0640 です。certbot の証明書は deploy hook で写してください。
    • root が持つファイルを使いたい場所は、global.files.trusted_dirs か RPROXY_FILES_TRUSTED_DIRS で指定できます(Kubernetes の Secret など)。確認を止めるには owner_check: off。
  • v0.3.x から v0.4.0 への更新は、引き継ぎではなく再起動になります(引き継ぎは同じマイナーの中だけ)。
  • 接続の失敗の target.down のログは、reason: connect から reason: outlier と cause: connect に変わりました。
  • v0.4 を入れたことのある機械に v0.3 の .deb を入れ直すと、残った rproxy グループのせいで失敗します。UI v0.4 と組み合わせるときは、rproxy-api も v0.4 にしてください。

UI: TCP-UDP-rproxy-ui v0.4.0 · Kubernetes: rproxy-gateway v0.4.0


Added

  • Hooks for a Kubernetes controller (#220), used by rproxy-gateway v0.4.0 to run rproxy behind the Kubernetes Gateway API.
    • Rule sets PUT /rulesets/{name}: send the whole set of rules at once and rproxy applies the difference. Supports generation, If-Match (etag) and ?dry_run=true; changing a rule of a set on its own gets 409 owned. A set belongs to the token that created it, and allow_rulesets in the token file limits which set names a token may use.
    • Rule labels (shown in logs and /metrics), conditions (in the shape of Gateway API status) and GET /readyz.
  • L7 and TLS for the Gateway API (#237, #239)
    • headers add, redirect status, per-route timeouts, replace_host, per-server middlewares, retry status, error-status servers.
    • New middlewares cors and mirror.
    • HTTP/2 to upstreams (h2, h2c, auto, with trailers) and per-service TLS (CA, SNI and SAN checks; BackendTLSPolicy).
    • Several targets in tls.routes.
    • client_auth: optional_no_verify with X-Client-Verify and X-Forwarded-Client-Cert.
  • Per-source L4 limits and bandwidth caps (#219): rule limits (concurrent connections, new-connection rate) and bandwidth (up and down); counters for usage accounting (counters_since).
  • Control API hardening (#218): tokens bound to client certificates (mTLS), token-expiry notices, and a lockout for sources with repeated auth failures (429 locked_out).
  • GeoIP allow and deny (#221) by country and AS, with MaxMind-format databases.
  • Passive health checks (#221): servers that keep failing are taken out for a while (outlier_detection).
  • Dry runs (#222): ?dry_run=true, POST /config/plan and rproxy-api --check-config --diff.
  • Persistence for API-made rules (#222): with persist: true on a token, the rules it creates are saved in the rproxy_rules table and restored after a restart (origin: "api").
  • Upgrades without a restart (#223): SIGUSR2 or POST /admin/upgrade hands the sockets over to a new binary without dropping connections. Patches within the same minor are handed over by the .deb upgrade too.
  • Self-update for containers (#223): with rproxy-api launch as the entrypoint and RPROXY_UPDATE=auto, rproxy fetches the newest patch of its X.Y, checks its minisign signature and swaps it in; a version that crashes is rolled back. The release key is in docs/en/UPGRADE.md.
  • Performance settings (#223): global.performance (workers, udp_shards, cpu_affinity, busy_poll_usecs, splice).

Fixed

  • X-Client-Verify and X-Forwarded-Client-Cert sent by clients are now removed on every rule; on rules without tls.client_auth, forged client-certificate details reached upstreams.
  • mirror copies now carry the same forwarding headers (X-Forwarded-*, certificate details) as the main request.
  • HTTP/2 upstreams could stall while waiting for a free stream.
  • The self-update no longer marks a version under trial as bad just because it was stopped.
  • Other findings of the security review (docs/en/DESIGN-v0.4.md, section 17).

Changed

  • The service user changes from rproxy to rproxy-api (primary group rproxy). The .deb and install.sh rename the user and keep its uid, so file ownership stays valid. The UI user (rproxy-ui) joins the rproxy group and can read group-readable files.
  • Files that rules point at are now checked (global.files.owner_check: strict, the default).
    • Only files owned by rproxy-api are used. Files writable by the group or others, and keys readable by anyone, are refused.
    • The recommended mode is rproxy-api:rproxy 0640. Copy certbot's certificates with a deploy hook.
    • Directories where root-owned files are acceptable (Kubernetes Secrets, for one) can be listed in global.files.trusted_dirs or RPROXY_FILES_TRUSTED_DIRS. owner_check: off turns the check off.
  • Upgrading from v0.3.x to v0.4.0 restarts the service (handover works only within the same minor).
  • target.down for connection failures now logs reason: outlier with cause: connect instead of reason: connect.
  • Installing a v0.3 .deb again on a machine that had v0.4 fails because of the leftover rproxy group. With UI v0.4, use rproxy-api v0.4 as well.

UI: TCP-UDP-rproxy-ui v0.4.0 · Kubernetes: rproxy-gateway v0.4.0