Harden kea socket dir to 0750 in the rendered entrypoints
After v0.1.1 moved the socket dir to /var/run/kea, kea-dhcp4 and kea-ctrl-agent still crash-loop: DHCP4_PARSER_COMMIT_FAIL ... 'socket-name' is invalid: socket path:/var/run/kea does not exist or has more relaxed permissions than 750 Kea 2.6+ refuses a unix-socket directory whose mode is more relaxed than 0750. The shared emptyDir is mounted at /var/run/kea with the default 0777, so kea rejects it. The kea containers run as root, so the entrypoints can tighten it. - chmod 0750 the RunDir in both rendered entrypoints after mkdir. - Assert both entrypoints chmod the socket dir to 0750. Needs a v0.1.2 release so argocd-apps can bump the operator image. Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
This commit is contained in:
@@ -35,6 +35,7 @@ func EntrypointDHCP4() string {
|
|||||||
set -e
|
set -e
|
||||||
ORD="${HOSTNAME##*-}"
|
ORD="${HOSTNAME##*-}"
|
||||||
mkdir -p %[1]s
|
mkdir -p %[1]s
|
||||||
|
chmod 0750 %[1]s
|
||||||
sed "s/%[2]s/server${ORD}/g" %[3]s/kea-dhcp4.conf > %[4]s
|
sed "s/%[2]s/server${ORD}/g" %[3]s/kea-dhcp4.conf > %[4]s
|
||||||
exec %[5]s -c %[4]s
|
exec %[5]s -c %[4]s
|
||||||
`, RunDir, ThisServerPlaceholder, ConfigDir, DHCP4ConfPath, DHCP4Bin)
|
`, RunDir, ThisServerPlaceholder, ConfigDir, DHCP4ConfPath, DHCP4Bin)
|
||||||
@@ -45,6 +46,7 @@ func EntrypointCtrlAgent() string {
|
|||||||
return fmt.Sprintf(`#!/bin/sh
|
return fmt.Sprintf(`#!/bin/sh
|
||||||
set -e
|
set -e
|
||||||
mkdir -p %[1]s
|
mkdir -p %[1]s
|
||||||
|
chmod 0750 %[1]s
|
||||||
cp %[2]s/kea-ctrl-agent.conf %[3]s
|
cp %[2]s/kea-ctrl-agent.conf %[3]s
|
||||||
exec %[4]s -c %[3]s
|
exec %[4]s -c %[3]s
|
||||||
`, RunDir, ConfigDir, CtrlAgentConfPath, CtrlAgentBin)
|
`, RunDir, ConfigDir, CtrlAgentConfPath, CtrlAgentBin)
|
||||||
|
|||||||
@@ -237,6 +237,18 @@ func TestRenderCtrlAgent(t *testing.T) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestEntrypointsHardenSocketDir(t *testing.T) {
|
||||||
|
// Kea 2.6+ rejects a socket dir "more relaxed than 750"; the emptyDir mount
|
||||||
|
// defaults to 0777, so the entrypoints must chmod it before exec'ing kea.
|
||||||
|
want := "chmod 0750 " + RunDir
|
||||||
|
if ep := EntrypointDHCP4(); !strings.Contains(ep, want) {
|
||||||
|
t.Errorf("dhcp4 entrypoint must %q, got:\n%s", want, ep)
|
||||||
|
}
|
||||||
|
if ep := EntrypointCtrlAgent(); !strings.Contains(ep, want) {
|
||||||
|
t.Errorf("ctrl-agent entrypoint must %q, got:\n%s", want, ep)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func TestControlSocketPathAllowedByKea(t *testing.T) {
|
func TestControlSocketPathAllowedByKea(t *testing.T) {
|
||||||
if !strings.HasPrefix(CtrlSocketPath, "/var/run/kea/") {
|
if !strings.HasPrefix(CtrlSocketPath, "/var/run/kea/") {
|
||||||
t.Errorf("CtrlSocketPath %q must live under /var/run/kea (kea 2.6+ restriction)", CtrlSocketPath)
|
t.Errorf("CtrlSocketPath %q must live under /var/run/kea (kea 2.6+ restriction)", CtrlSocketPath)
|
||||||
|
|||||||
Reference in New Issue
Block a user