From 30b712a934b5ba864e8e9968dcfcb28f5f7cfffc Mon Sep 17 00:00:00 2001 From: chen21019 Date: Mon, 14 Sep 2026 16:29:36 +0800 Subject: [PATCH] Package deterministic flat CNI IPAM v0.1.5 --- .github/workflows/codeql-verification.yml | 2 +- .github/workflows/release.yml | 34 ++++++++++----------- .github/workflows/security-release-gate.yml | 10 +++--- README.md | 21 +++++++++++-- scripts/integration-two-node-ipsec | 2 +- scripts/integration-two-node-vxlan | 2 +- scripts/package | 4 +-- scripts/validate | 2 +- 8 files changed, 47 insertions(+), 30 deletions(-) diff --git a/.github/workflows/codeql-verification.yml b/.github/workflows/codeql-verification.yml index eed6ebe..ca9dd07 100644 --- a/.github/workflows/codeql-verification.yml +++ b/.github/workflows/codeql-verification.yml @@ -53,7 +53,7 @@ jobs: cd "$GITHUB_WORKSPACE" go test -run '^$' ./... go test -run '^$' -tags=integration ./store - VERSION_OVERRIDE=0.14.36 ./scripts/build + VERSION_OVERRIDE=0.14.37 ./scripts/build - name: Analyze without publishing temporary alerts uses: github/codeql-action/analyze@db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 # v4.37.8 diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 70fa962..59fb83e 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1,6 +1,6 @@ name: Release IPsec overlay -# A release is dispatched from main only after an annotated v0.14.36 tag and +# A release is dispatched from main only after an annotated v0.14.37 tag and # successful, same-commit Security release gate and CodeQL verification runs. # GHCR, registry attestations, and GitHub Releases are not an atomic transaction. # All source/product/runtime gates precede the image push. A later failure may @@ -9,11 +9,11 @@ on: workflow_dispatch: inputs: release_tag: - description: Existing annotated, numeric v0.14.36 tag at main HEAD + description: Existing annotated, numeric v0.14.37 tag at main HEAD required: true type: choice options: - - v0.14.36 + - v0.14.37 security_run_id: description: Successful same-SHA Security release gate run ID required: true @@ -35,7 +35,7 @@ permissions: attestations: write concurrency: - group: ipsec-vxlan-overlay-release-v0.14.36 + group: ipsec-vxlan-overlay-release-v0.14.37 cancel-in-progress: false jobs: @@ -48,8 +48,8 @@ jobs: CODEQL_RUN_ID: ${{ inputs.codeql_run_id }} RESUME_DIGEST: ${{ inputs.resume_digest }} GH_TOKEN: ${{ github.token }} - SERVICE_IMAGE: ghcr.io/pasturestack/ipsec-vxlan-overlay-network:v0.14.36 - LOCAL_IMAGE: local/pasturestack/ipsec-vxlan-overlay-network:0.14.36 + SERVICE_IMAGE: ghcr.io/pasturestack/ipsec-vxlan-overlay-network:v0.14.37 + LOCAL_IMAGE: local/pasturestack/ipsec-vxlan-overlay-network:0.14.37 TRIVY_IMAGE: aquasec/trivy:0.74.0@sha256:62b1e65e8869bc4b4c6aa4fa2b21595256c7c2f6018a9d9ad61caf87187c1969 GOFLAGS: -mod=vendor GOWORK: off @@ -67,7 +67,7 @@ jobs: run: | set -euo pipefail test "$GITHUB_REF" = refs/heads/main - test "$RELEASE_TAG" = v0.14.36 + test "$RELEASE_TAG" = v0.14.37 [[ "$RELEASE_TAG" =~ ^v[0-9]+\.[0-9]+\.[0-9]+$ ]] [[ "$SECURITY_RUN_ID" =~ ^[0-9]+$ ]] [[ "$CODEQL_RUN_ID" =~ ^[0-9]+$ ]] @@ -152,15 +152,15 @@ jobs: shell: bash run: | set -euo pipefail - VERSION_OVERRIDE=0.14.36 ./scripts/build + VERSION_OVERRIDE=0.14.37 ./scripts/build sha256sum --check evidence/product.sha256 if [ -z "$RESUME_DIGEST" ]; then - VERSION_OVERRIDE=0.14.36 TAG=0.14.36 REPO=local/pasturestack \ + VERSION_OVERRIDE=0.14.37 TAG=0.14.37 REPO=local/pasturestack \ IMAGE_REVISION="$SOURCE_SHA" ./scripts/package test "$(wc -l < dist/images)" -eq 1 grep -Fx "$LOCAL_IMAGE" dist/images test "$(docker image inspect "$LOCAL_IMAGE" \ - --format '{{index .Config.Labels "org.opencontainers.image.version"}}')" = 0.14.36 + --format '{{index .Config.Labels "org.opencontainers.image.version"}}')" = 0.14.37 test "$(docker image inspect "$LOCAL_IMAGE" \ --format '{{index .Config.Labels "org.opencontainers.image.revision"}}')" = "$SOURCE_SHA" docker tag "$LOCAL_IMAGE" "$SERVICE_IMAGE" @@ -178,7 +178,7 @@ jobs: docker pull "$SERVICE_IMAGE@$RESUME_DIGEST" docker tag "$SERVICE_IMAGE@$RESUME_DIGEST" "$SERVICE_IMAGE" test "$(docker image inspect "$SERVICE_IMAGE" \ - --format '{{index .Config.Labels "org.opencontainers.image.version"}}')" = 0.14.36 + --format '{{index .Config.Labels "org.opencontainers.image.version"}}')" = 0.14.37 test "$(docker image inspect "$SERVICE_IMAGE" \ --format '{{index .Config.Labels "org.opencontainers.image.revision"}}')" = "$SOURCE_SHA" verification_container="$(docker create "$SERVICE_IMAGE")" @@ -315,7 +315,7 @@ jobs: run: | set -euo pipefail release_dir="dist/release" - product_dir="$release_dir/ipsec-vxlan-overlay-network-0.14.36-linux-amd64" + product_dir="$release_dir/ipsec-vxlan-overlay-network-0.14.37-linux-amd64" mkdir -p "$product_dir" cp bin/ipsec-vxlan-overlay-network bin/ipsec-vxlan-overlay-topology bin/pasture-cni-resolver \ LICENSE ORIGIN.md SECURITY.md THIRD_PARTY_NOTICES.md "$product_dir/" @@ -327,11 +327,11 @@ jobs: find "$product_dir" -exec touch -h -d "@$source_epoch" {} + tar --sort=name --mtime="@$source_epoch" --owner=0 --group=0 \ --numeric-owner -C "$release_dir" \ - -cJf "$release_dir/ipsec-vxlan-overlay-network-0.14.36-linux-amd64.tar.xz" \ - ipsec-vxlan-overlay-network-0.14.36-linux-amd64 + -cJf "$release_dir/ipsec-vxlan-overlay-network-0.14.37-linux-amd64.tar.xz" \ + ipsec-vxlan-overlay-network-0.14.37-linux-amd64 ( cd "$release_dir" - sha256sum ipsec-vxlan-overlay-network-0.14.36-linux-amd64.tar.xz \ + sha256sum ipsec-vxlan-overlay-network-0.14.37-linux-amd64.tar.xz \ source-sbom.cdx.json image-sbom.cdx.json product.sha256 \ runtime-security.json gate-security-summary.txt image-digest.txt \ release-identity.txt > SHA256SUMS @@ -355,9 +355,9 @@ jobs: run: | set -euo pipefail gh release create "$RELEASE_TAG" --repo "$GITHUB_REPOSITORY" --verify-tag \ - --title 'IPsec Overlay v0.14.36' \ + --title 'IPsec Overlay v0.14.37' \ --notes "Source ${SOURCE_SHA}; Security gate run ${SECURITY_RUN_ID}; CodeQL run ${CODEQL_RUN_ID}. GHCR image ${SERVICE_IMAGE}@$(cat dist/release/image-digest.txt | sed 's/^.*@//')." \ - dist/release/ipsec-vxlan-overlay-network-0.14.36-linux-amd64.tar.xz \ + dist/release/ipsec-vxlan-overlay-network-0.14.37-linux-amd64.tar.xz \ dist/release/source-sbom.cdx.json \ dist/release/image-sbom.cdx.json \ dist/release/product.sha256 \ diff --git a/.github/workflows/security-release-gate.yml b/.github/workflows/security-release-gate.yml index bdcb0f8..f55dddd 100644 --- a/.github/workflows/security-release-gate.yml +++ b/.github/workflows/security-release-gate.yml @@ -18,12 +18,12 @@ jobs: runs-on: ubuntu-24.04 timeout-minutes: 120 env: - CANDIDATE_VERSION: 0.14.36 - VERSION_OVERRIDE: 0.14.36 - TAG: 0.14.36 + CANDIDATE_VERSION: 0.14.37 + VERSION_OVERRIDE: 0.14.37 + TAG: 0.14.37 IMAGE_REVISION: ${{ github.sha }} REPO: local/pasturestack - IMAGE: local/pasturestack/ipsec-vxlan-overlay-network:0.14.36 + IMAGE: local/pasturestack/ipsec-vxlan-overlay-network:0.14.37 GO_VERSION: 1.27.0 GO_LINUX_AMD64_SHA256: 675c26c449cbb18fc24b74650de1eabbae6e16f64326fd85a283fb3b58280685 TRIVY_IMAGE: aquasec/trivy:0.74.0@sha256:62b1e65e8869bc4b4c6aa4fa2b21595256c7c2f6018a9d9ad61caf87187c1969 @@ -280,7 +280,7 @@ jobs: impact_statement:$impact }] | { "@context":"https://openvex.dev/ns/v0.2.0", - "@id":"https://github.com/PastureStack/ipsec-vxlan-overlay-network/security/openvex/dapper/0.14.36", + "@id":"https://github.com/PastureStack/ipsec-vxlan-overlay-network/security/openvex/dapper/0.14.37", author:"PastureStack Security", timestamp:$timestamp, version:1, diff --git a/README.md b/README.md index a5e9dd9..b839ac6 100644 --- a/README.md +++ b/README.md @@ -100,6 +100,23 @@ backend selection, or the router's port 8111 ownership. Source tests hold and release the port and verify the bounded failure path. Image publication, Catalog pinning, and live upgrade acceptance are separate gates for each release. +Published `v0.14.36` updates the packaged preserved bridge compatibility +binary to `v0.7.2`. In the Layer 2 Flat template it honors +`skipBridgeConfigureIP`, so the CNI driver does not add another address to an +operator-owned bridge. It packages `flat-cni-ipam v0.1.4` and does not change +firewall ownership. Catalog Templates `v0.3.11` pins this image in Layer 2 Flat +template version `5`; Server `v1.6.439` embeds that Catalog. + +`v0.14.37` updates only the packaged flat-network IPAM companion to +`flat-cni-ipam v0.1.5`. When a template expresses `bridgeSubnet` with the +network address, the IPAM now selects the same first usable gateway derived by +the bridge plugin if that address is present. This makes restart reconciliation +deterministic when an operator-owned flat bridge also carries a separate host +address. Explicit host addresses still win, and an unresolved multi-address +bridge still fails closed instead of guessing. Firewall ownership and backend +selection remain unchanged. Publication, Catalog pinning, and live reboot +acceptance are separate gates. + The release gate rejects Critical/High findings and secrets in the source, shipped binaries, and runtime image. It scans the disposable Dapper builder separately and retains its raw findings; only exact, already-reviewed @@ -124,8 +141,8 @@ The build is containerized and requires Docker on a Linux AMD64 host: ```sh make test make validate -VERSION_OVERRIDE=0.14.36 make build -TAG=0.14.36 make package +VERSION_OVERRIDE=0.14.37 make build +TAG=0.14.37 make package ``` The package build downloads dependencies anonymously, verifies every standalone binary with SHA-256, pins the Ubuntu base image by digest, resolves every directly installed package from Canonical snapshot `20260808T000000Z` with the exact versions in `ubuntu-apt.lock`, and includes the corresponding strongSwan source archives in the image. Go dependencies are declared in `go.mod`, checksum-bound by `go.sum`, and committed in the standard module-aware `vendor` tree for offline builds. diff --git a/scripts/integration-two-node-ipsec b/scripts/integration-two-node-ipsec index cc50d24..63839d7 100755 --- a/scripts/integration-two-node-ipsec +++ b/scripts/integration-two-node-ipsec @@ -1,7 +1,7 @@ #!/bin/bash set -euo pipefail -image=${IMAGE:-local/pasturestack/ipsec-vxlan-overlay-network:0.14.36} +image=${IMAGE:-local/pasturestack/ipsec-vxlan-overlay-network:0.14.37} old_image=${OLD_IMAGE:-} startup_image=${old_image:-$image} test_id=$$ diff --git a/scripts/integration-two-node-vxlan b/scripts/integration-two-node-vxlan index 61fe656..81b0543 100755 --- a/scripts/integration-two-node-vxlan +++ b/scripts/integration-two-node-vxlan @@ -1,7 +1,7 @@ #!/bin/bash set -euo pipefail -image=${IMAGE:-local/pasturestack/ipsec-vxlan-overlay-network:0.14.36} +image=${IMAGE:-local/pasturestack/ipsec-vxlan-overlay-network:0.14.37} test_id=$$ network="pasture-vxlan-it-${test_id}" node_a="pasture-vxlan-a-${test_id}" diff --git a/scripts/package b/scripts/package index 4add8eb..5e3ebc6 100755 --- a/scripts/package +++ b/scripts/package @@ -15,8 +15,8 @@ PER_HOST_SUBNET_URL=${PER_HOST_SUBNET_URL:-https://github.com/PastureStack/per-h PER_HOST_SUBNET_SHA256=${PER_HOST_SUBNET_SHA256:-d12acca4526eee45d52b87541717ae81432225d9c5dabfd823d6b43631c20e84} HOST_LOCAL_CNI_IPAM_URL=${HOST_LOCAL_CNI_IPAM_URL:-https://github.com/PastureStack/host-local-cni-ipam/releases/download/v0.1.4/host-local-cni-ipam-0.1.4-linux-amd64} HOST_LOCAL_CNI_IPAM_SHA256=${HOST_LOCAL_CNI_IPAM_SHA256:-9bb79b9f269663715f44aea898854df0e0e319a3ba35e4d52db5477cde026e3e} -FLAT_CNI_IPAM_URL=${FLAT_CNI_IPAM_URL:-https://github.com/PastureStack/flat-cni-ipam/releases/download/v0.1.4/flat-cni-ipam-v0.1.4-linux-amd64} -FLAT_CNI_IPAM_SHA256=${FLAT_CNI_IPAM_SHA256:-edbbe0924637381f95b268b259170d80434d3c37e0a5a7519c7e55b2e8957db5} +FLAT_CNI_IPAM_URL=${FLAT_CNI_IPAM_URL:-https://github.com/PastureStack/flat-cni-ipam/releases/download/v0.1.5/flat-cni-ipam-v0.1.5-linux-amd64} +FLAT_CNI_IPAM_SHA256=${FLAT_CNI_IPAM_SHA256:-c0044889348313d84d631e36121068fc5072fb423e25fcd795e6b34424f38de7} MOUNT_PROPAGATION_URL=${MOUNT_PROPAGATION_URL:-https://github.com/PastureStack/mount-propagation/releases/download/v1.0.11/mount-propagation-v1.0.11-linux-amd64} MOUNT_PROPAGATION_SHA256=${MOUNT_PROPAGATION_SHA256:-800bbc2d74c318ccc62d2c3c76846ee1fe307c21daf558c7edcf5de25e393a4b} diff --git a/scripts/validate b/scripts/validate index f84fe5a..8b4f1a3 100755 --- a/scripts/validate +++ b/scripts/validate @@ -49,7 +49,7 @@ for script in scripts/* package/*.sh package/update-platform-ca; do bash -n "$script" done -version=${VERSION_OVERRIDE:-0.14.36} +version=${VERSION_OVERRIDE:-0.14.37} first=$(mktemp -d) trap 'rm -rf "$first"' EXIT VERSION_OVERRIDE="$version" ./scripts/build