Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .github/workflows/security-release-gate.yml
Original file line number Diff line number Diff line change
Expand Up @@ -139,6 +139,7 @@ jobs:
set -euo pipefail
cd "$GITHUB_WORKSPACE"
IMAGE="$IMAGE" ./scripts/integration-two-node-vxlan
IMAGE="$IMAGE" ./scripts/integration-optional-cni-isolated
IMAGE="$IMAGE" \
OLD_IMAGE='ghcr.io/pasturestack/ipsec-vxlan-overlay-network@sha256:4d8a51e04bdd27fea3cb2949158103d43e0d2470907c328f76f7a0c6ccec8608' \
./scripts/integration-two-node-ipsec
Expand Down
7 changes: 7 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -102,6 +102,13 @@ TAG=0.14.33 make package

The package build downloads dependencies anonymously, verifies every standalone binary with SHA-256, pins the Ubuntu base image by digest, resolves every directly installed package from Canonical snapshot `20260808T000000Z` with the exact versions in `ubuntu-apt.lock`, and includes the corresponding strongSwan source archives in the image. Go dependencies are declared in `go.mod`, checksum-bound by `go.sum`, and committed in the standard module-aware `vendor` tree for offline builds.

The release gate also runs `scripts/integration-optional-cni-isolated` against
the image it just packaged. Inside a disposable, network-isolated container it
checks the bundled per-host-subnet and flat-bridge CNI binaries through ADD,
bridge connectivity, and DEL. A local reproduction must set `IMAGE` to the
exact image under review. This does not replace a live Catalog, Metadata API,
host-port, cross-host, or host-reboot acceptance test.

The health reconciler canonicalizes strongSwan VICI CHILD_SA runtime names before comparing them with configured peer names. This prevents a VICI unique-ID suffix from being misclassified as a missing SA during a rolling replacement.

## Host firewall backends
Expand Down
58 changes: 58 additions & 0 deletions scripts/integration-optional-cni-isolated
Original file line number Diff line number Diff line change
@@ -0,0 +1,58 @@
#!/usr/bin/env bash
set -euo pipefail

# Exercise the exact CNI binaries bundled in the catalog-pinned image without
# changing the host namespace, managed networks, or Docker daemon settings.
image=${IMAGE:?Set IMAGE to the exact packaged image to verify}
docker image inspect "$image" >/dev/null

docker run --rm -i --privileged --network none --entrypoint /bin/bash "$image" -s <<'CONTAINER'
set -euo pipefail
export CNI_PATH=/opt/cni/bin CNI_CONTAINERID=optional-cni-smoke CNI_IFNAME=eth0

check_link() {
local namespace=$1 address=$2 gateway=$3
ip netns exec "$namespace" ip -4 address show eth0 | grep -q "$address"
ip netns exec "$namespace" ping -c 2 -W 2 "$gateway" >/dev/null
}

# Per-host subnet: address allocation and bridge traffic stay inside this
# disposable container's network and mount namespaces.
ip netns add qa-perhost
export CNI_NETNS=/run/netns/qa-perhost 'CNI_ARGS=IgnoreUnknown=1;MACAddress=02:42:37:ff:01:01'
perhost='{"cniVersion":"0.1.0","name":"qa-perhost","type":"pasture-bridge","bridge":"brphqa","bridgeSubnet":"10.55.243.0/24","isDefaultGateway":true,"hostNat":false,"ipam":{"type":"host-local-cni-ipam","subnet":"10.55.243.0/24","dataDir":"/tmp/cni-state"}}'
if ! result=$(CNI_COMMAND=ADD /opt/cni/bin/pasture-bridge <<<"$perhost"); then
printf 'per-host CNI ADD: %s\n' "$result" >&2
exit 1
fi
check_link qa-perhost 10.55.243. 10.55.243.1
CNI_COMMAND=DEL /opt/cni/bin/pasture-bridge <<<"$perhost" >/dev/null
if ip netns exec qa-perhost ip link show eth0 >/dev/null 2>&1; then
echo 'per-host CNI DEL left eth0 behind' >&2
exit 1
fi
ip netns del qa-perhost
echo 'PER_HOST_CNI=pass'

# Flat bridge: the physical LAN bridge is represented by a pre-created
# bridge inside this container. A direct address avoids depending on a real
# platform Metadata API; the Metadata lookup path has its own source tests.
ip link add brflatqa type bridge
ip address add 10.55.244.1/24 dev brflatqa
ip link set brflatqa up
ip netns add qa-flat
export CNI_NETNS=/run/netns/qa-flat 'CNI_ARGS=IgnoreUnknown=1;MACAddress=02:42:37:ff:01:02;IPAddress=10.55.244.2/24'
flat='{"cniVersion":"0.1.0","name":"qa-flat","type":"pasture-bridge","bridge":"brflatqa","bridgeSubnet":"10.55.244.1/24","skipBridgeConfigureIP":true,"skipFastPath":true,"hostNat":false,"ipam":{"type":"flat-cni-ipam","metadataAddress":"169.254.169.250"}}'
if ! result=$(CNI_COMMAND=ADD /opt/cni/bin/pasture-bridge <<<"$flat"); then
printf 'flat CNI ADD: %s\n' "$result" >&2
exit 1
fi
check_link qa-flat 10.55.244.2 10.55.244.1
CNI_COMMAND=DEL /opt/cni/bin/pasture-bridge <<<"$flat" >/dev/null
if ip netns exec qa-flat ip link show eth0 >/dev/null 2>&1; then
echo 'flat CNI DEL left eth0 behind' >&2
exit 1
fi
ip netns del qa-flat
echo 'FLAT_CNI=pass'
CONTAINER
Loading