Harden kea socket dir to 0750 in the rendered entrypoints
After v0.1.1 moved the socket dir to /var/run/kea, kea-dhcp4 and kea-ctrl-agent still crash-loop: DHCP4_PARSER_COMMIT_FAIL ... 'socket-name' is invalid: socket path:/var/run/kea does not exist or has more relaxed permissions than 750 Kea 2.6+ refuses a unix-socket directory whose mode is more relaxed than 0750. The shared emptyDir is mounted at /var/run/kea with the default 0777, so kea rejects it. The kea containers run as root, so the entrypoints can tighten it. - chmod 0750 the RunDir in both rendered entrypoints after mkdir. - Assert both entrypoints chmod the socket dir to 0750. Needs a v0.1.2 release so argocd-apps can bump the operator image. Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
This commit is contained in:
@@ -35,6 +35,7 @@ func EntrypointDHCP4() string {
|
||||
set -e
|
||||
ORD="${HOSTNAME##*-}"
|
||||
mkdir -p %[1]s
|
||||
chmod 0750 %[1]s
|
||||
sed "s/%[2]s/server${ORD}/g" %[3]s/kea-dhcp4.conf > %[4]s
|
||||
exec %[5]s -c %[4]s
|
||||
`, RunDir, ThisServerPlaceholder, ConfigDir, DHCP4ConfPath, DHCP4Bin)
|
||||
@@ -45,6 +46,7 @@ func EntrypointCtrlAgent() string {
|
||||
return fmt.Sprintf(`#!/bin/sh
|
||||
set -e
|
||||
mkdir -p %[1]s
|
||||
chmod 0750 %[1]s
|
||||
cp %[2]s/kea-ctrl-agent.conf %[3]s
|
||||
exec %[4]s -c %[3]s
|
||||
`, RunDir, ConfigDir, CtrlAgentConfPath, CtrlAgentBin)
|
||||
|
||||
@@ -237,6 +237,18 @@ func TestRenderCtrlAgent(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestEntrypointsHardenSocketDir(t *testing.T) {
|
||||
// Kea 2.6+ rejects a socket dir "more relaxed than 750"; the emptyDir mount
|
||||
// defaults to 0777, so the entrypoints must chmod it before exec'ing kea.
|
||||
want := "chmod 0750 " + RunDir
|
||||
if ep := EntrypointDHCP4(); !strings.Contains(ep, want) {
|
||||
t.Errorf("dhcp4 entrypoint must %q, got:\n%s", want, ep)
|
||||
}
|
||||
if ep := EntrypointCtrlAgent(); !strings.Contains(ep, want) {
|
||||
t.Errorf("ctrl-agent entrypoint must %q, got:\n%s", want, ep)
|
||||
}
|
||||
}
|
||||
|
||||
func TestControlSocketPathAllowedByKea(t *testing.T) {
|
||||
if !strings.HasPrefix(CtrlSocketPath, "/var/run/kea/") {
|
||||
t.Errorf("CtrlSocketPath %q must live under /var/run/kea (kea 2.6+ restriction)", CtrlSocketPath)
|
||||
|
||||
Reference in New Issue
Block a user