Skip to content

egress: deny CONNECT tunnels to the host API port - #40

Merged
p-linnane merged 1 commit into
mainfrom
egress/deny-api-connect
Sep 13, 2026
Merged

p-linnane merged 1 commit into
mainfrom
egress/deny-api-connect

Conversation

@p-linnane

Copy link
Copy Markdown
Collaborator

CONNECT to APIPort gave a workload a raw tunnel to the host API that skipped the forward path's request inspection, and an upgraded harness could not tell whether an older sidecar image still allowed it.

The proxy now refuses those tunnels with 403, comparing ports by value so a HostPorts spelling cannot reopen them. harness-proxy takes a --require-capability flag that the sidecar launcher and VerifyProxyBinary always pass, so older images exit non-zero instead of running the old policy.

Consumers that set APIPort for a TLS or raw TCP service must move it to HostPorts.

CONNECT to APIPort gave a workload a raw tunnel to the host API that
skipped the forward path's request inspection, and an upgraded harness
could not tell whether an older sidecar image still allowed it.

The proxy now refuses those tunnels with 403, comparing ports by value
so a HostPorts spelling cannot reopen them. harness-proxy takes a
--require-capability flag that the sidecar launcher and
VerifyProxyBinary always pass, so older images exit non-zero instead
of running the old policy.

Signed-off-by: Patrick Linnane <patrick@linnane.io>
@p-linnane
p-linnane merged commit 1c9d1e7 into main Sep 13, 2026
8 checks passed
@p-linnane
p-linnane deleted the egress/deny-api-connect branch September 13, 2026 18:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant