Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/codeql-verification.yml
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,7 @@ jobs:
cd "$GITHUB_WORKSPACE"
go test -run '^$' ./...
go test -run '^$' -tags=integration ./store
VERSION_OVERRIDE=0.14.36 ./scripts/build
VERSION_OVERRIDE=0.14.37 ./scripts/build

- name: Analyze without publishing temporary alerts
uses: github/codeql-action/analyze@db488ddef3bf6cb639b32c2e9a7c0a7ea8271d28 # v4.37.8
Expand Down
34 changes: 17 additions & 17 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
name: Release IPsec overlay

# A release is dispatched from main only after an annotated v0.14.36 tag and
# A release is dispatched from main only after an annotated v0.14.37 tag and
# successful, same-commit Security release gate and CodeQL verification runs.
# GHCR, registry attestations, and GitHub Releases are not an atomic transaction.
# All source/product/runtime gates precede the image push. A later failure may
Expand All @@ -9,11 +9,11 @@ on:
workflow_dispatch:
inputs:
release_tag:
description: Existing annotated, numeric v0.14.36 tag at main HEAD
description: Existing annotated, numeric v0.14.37 tag at main HEAD
required: true
type: choice
options:
- v0.14.36
- v0.14.37
security_run_id:
description: Successful same-SHA Security release gate run ID
required: true
Expand All @@ -35,7 +35,7 @@ permissions:
attestations: write

concurrency:
group: ipsec-vxlan-overlay-release-v0.14.36
group: ipsec-vxlan-overlay-release-v0.14.37
cancel-in-progress: false

jobs:
Expand All @@ -48,8 +48,8 @@ jobs:
CODEQL_RUN_ID: ${{ inputs.codeql_run_id }}
RESUME_DIGEST: ${{ inputs.resume_digest }}
GH_TOKEN: ${{ github.token }}
SERVICE_IMAGE: ghcr.io/pasturestack/ipsec-vxlan-overlay-network:v0.14.36
LOCAL_IMAGE: local/pasturestack/ipsec-vxlan-overlay-network:0.14.36
SERVICE_IMAGE: ghcr.io/pasturestack/ipsec-vxlan-overlay-network:v0.14.37
LOCAL_IMAGE: local/pasturestack/ipsec-vxlan-overlay-network:0.14.37
TRIVY_IMAGE: aquasec/trivy:0.74.0@sha256:62b1e65e8869bc4b4c6aa4fa2b21595256c7c2f6018a9d9ad61caf87187c1969
GOFLAGS: -mod=vendor
GOWORK: off
Expand All @@ -67,7 +67,7 @@ jobs:
run: |
set -euo pipefail
test "$GITHUB_REF" = refs/heads/main
test "$RELEASE_TAG" = v0.14.36
test "$RELEASE_TAG" = v0.14.37
[[ "$RELEASE_TAG" =~ ^v[0-9]+\.[0-9]+\.[0-9]+$ ]]
[[ "$SECURITY_RUN_ID" =~ ^[0-9]+$ ]]
[[ "$CODEQL_RUN_ID" =~ ^[0-9]+$ ]]
Expand Down Expand Up @@ -152,15 +152,15 @@ jobs:
shell: bash
run: |
set -euo pipefail
VERSION_OVERRIDE=0.14.36 ./scripts/build
VERSION_OVERRIDE=0.14.37 ./scripts/build
sha256sum --check evidence/product.sha256
if [ -z "$RESUME_DIGEST" ]; then
VERSION_OVERRIDE=0.14.36 TAG=0.14.36 REPO=local/pasturestack \
VERSION_OVERRIDE=0.14.37 TAG=0.14.37 REPO=local/pasturestack \
IMAGE_REVISION="$SOURCE_SHA" ./scripts/package
test "$(wc -l < dist/images)" -eq 1
grep -Fx "$LOCAL_IMAGE" dist/images
test "$(docker image inspect "$LOCAL_IMAGE" \
--format '{{index .Config.Labels "org.opencontainers.image.version"}}')" = 0.14.36
--format '{{index .Config.Labels "org.opencontainers.image.version"}}')" = 0.14.37
test "$(docker image inspect "$LOCAL_IMAGE" \
--format '{{index .Config.Labels "org.opencontainers.image.revision"}}')" = "$SOURCE_SHA"
docker tag "$LOCAL_IMAGE" "$SERVICE_IMAGE"
Expand All @@ -178,7 +178,7 @@ jobs:
docker pull "$SERVICE_IMAGE@$RESUME_DIGEST"
docker tag "$SERVICE_IMAGE@$RESUME_DIGEST" "$SERVICE_IMAGE"
test "$(docker image inspect "$SERVICE_IMAGE" \
--format '{{index .Config.Labels "org.opencontainers.image.version"}}')" = 0.14.36
--format '{{index .Config.Labels "org.opencontainers.image.version"}}')" = 0.14.37
test "$(docker image inspect "$SERVICE_IMAGE" \
--format '{{index .Config.Labels "org.opencontainers.image.revision"}}')" = "$SOURCE_SHA"
verification_container="$(docker create "$SERVICE_IMAGE")"
Expand Down Expand Up @@ -315,7 +315,7 @@ jobs:
run: |
set -euo pipefail
release_dir="dist/release"
product_dir="$release_dir/ipsec-vxlan-overlay-network-0.14.36-linux-amd64"
product_dir="$release_dir/ipsec-vxlan-overlay-network-0.14.37-linux-amd64"
mkdir -p "$product_dir"
cp bin/ipsec-vxlan-overlay-network bin/ipsec-vxlan-overlay-topology bin/pasture-cni-resolver \
LICENSE ORIGIN.md SECURITY.md THIRD_PARTY_NOTICES.md "$product_dir/"
Expand All @@ -327,11 +327,11 @@ jobs:
find "$product_dir" -exec touch -h -d "@$source_epoch" {} +
tar --sort=name --mtime="@$source_epoch" --owner=0 --group=0 \
--numeric-owner -C "$release_dir" \
-cJf "$release_dir/ipsec-vxlan-overlay-network-0.14.36-linux-amd64.tar.xz" \
ipsec-vxlan-overlay-network-0.14.36-linux-amd64
-cJf "$release_dir/ipsec-vxlan-overlay-network-0.14.37-linux-amd64.tar.xz" \
ipsec-vxlan-overlay-network-0.14.37-linux-amd64
(
cd "$release_dir"
sha256sum ipsec-vxlan-overlay-network-0.14.36-linux-amd64.tar.xz \
sha256sum ipsec-vxlan-overlay-network-0.14.37-linux-amd64.tar.xz \
source-sbom.cdx.json image-sbom.cdx.json product.sha256 \
runtime-security.json gate-security-summary.txt image-digest.txt \
release-identity.txt > SHA256SUMS
Expand All @@ -355,9 +355,9 @@ jobs:
run: |
set -euo pipefail
gh release create "$RELEASE_TAG" --repo "$GITHUB_REPOSITORY" --verify-tag \
--title 'IPsec Overlay v0.14.36' \
--title 'IPsec Overlay v0.14.37' \
--notes "Source ${SOURCE_SHA}; Security gate run ${SECURITY_RUN_ID}; CodeQL run ${CODEQL_RUN_ID}. GHCR image ${SERVICE_IMAGE}@$(cat dist/release/image-digest.txt | sed 's/^.*@//')." \
dist/release/ipsec-vxlan-overlay-network-0.14.36-linux-amd64.tar.xz \
dist/release/ipsec-vxlan-overlay-network-0.14.37-linux-amd64.tar.xz \
dist/release/source-sbom.cdx.json \
dist/release/image-sbom.cdx.json \
dist/release/product.sha256 \
Expand Down
10 changes: 5 additions & 5 deletions .github/workflows/security-release-gate.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,12 +18,12 @@ jobs:
runs-on: ubuntu-24.04
timeout-minutes: 120
env:
CANDIDATE_VERSION: 0.14.36
VERSION_OVERRIDE: 0.14.36
TAG: 0.14.36
CANDIDATE_VERSION: 0.14.37
VERSION_OVERRIDE: 0.14.37
TAG: 0.14.37
IMAGE_REVISION: ${{ github.sha }}
REPO: local/pasturestack
IMAGE: local/pasturestack/ipsec-vxlan-overlay-network:0.14.36
IMAGE: local/pasturestack/ipsec-vxlan-overlay-network:0.14.37
GO_VERSION: 1.27.0
GO_LINUX_AMD64_SHA256: 675c26c449cbb18fc24b74650de1eabbae6e16f64326fd85a283fb3b58280685
TRIVY_IMAGE: aquasec/trivy:0.74.0@sha256:62b1e65e8869bc4b4c6aa4fa2b21595256c7c2f6018a9d9ad61caf87187c1969
Expand Down Expand Up @@ -280,7 +280,7 @@ jobs:
impact_statement:$impact
}] | {
"@context":"https://openvex.dev/ns/v0.2.0",
"@id":"https://github.com/PastureStack/ipsec-vxlan-overlay-network/security/openvex/dapper/0.14.36",
"@id":"https://github.com/PastureStack/ipsec-vxlan-overlay-network/security/openvex/dapper/0.14.37",
author:"PastureStack Security",
timestamp:$timestamp,
version:1,
Expand Down
21 changes: 19 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -100,6 +100,23 @@ backend selection, or the router's port 8111 ownership. Source tests hold and
release the port and verify the bounded failure path. Image publication,
Catalog pinning, and live upgrade acceptance are separate gates for each release.

Published `v0.14.36` updates the packaged preserved bridge compatibility
binary to `v0.7.2`. In the Layer 2 Flat template it honors
`skipBridgeConfigureIP`, so the CNI driver does not add another address to an
operator-owned bridge. It packages `flat-cni-ipam v0.1.4` and does not change
firewall ownership. Catalog Templates `v0.3.11` pins this image in Layer 2 Flat
template version `5`; Server `v1.6.439` embeds that Catalog.

`v0.14.37` updates only the packaged flat-network IPAM companion to
`flat-cni-ipam v0.1.5`. When a template expresses `bridgeSubnet` with the
network address, the IPAM now selects the same first usable gateway derived by
the bridge plugin if that address is present. This makes restart reconciliation
deterministic when an operator-owned flat bridge also carries a separate host
address. Explicit host addresses still win, and an unresolved multi-address
bridge still fails closed instead of guessing. Firewall ownership and backend
selection remain unchanged. Publication, Catalog pinning, and live reboot
acceptance are separate gates.

The release gate rejects Critical/High findings and secrets in the source,
shipped binaries, and runtime image. It scans the disposable Dapper builder
separately and retains its raw findings; only exact, already-reviewed
Expand All @@ -124,8 +141,8 @@ The build is containerized and requires Docker on a Linux AMD64 host:
```sh
make test
make validate
VERSION_OVERRIDE=0.14.36 make build
TAG=0.14.36 make package
VERSION_OVERRIDE=0.14.37 make build
TAG=0.14.37 make package
```

The package build downloads dependencies anonymously, verifies every standalone binary with SHA-256, pins the Ubuntu base image by digest, resolves every directly installed package from Canonical snapshot `20260808T000000Z` with the exact versions in `ubuntu-apt.lock`, and includes the corresponding strongSwan source archives in the image. Go dependencies are declared in `go.mod`, checksum-bound by `go.sum`, and committed in the standard module-aware `vendor` tree for offline builds.
Expand Down
2 changes: 1 addition & 1 deletion scripts/integration-two-node-ipsec
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
#!/bin/bash
set -euo pipefail

image=${IMAGE:-local/pasturestack/ipsec-vxlan-overlay-network:0.14.36}
image=${IMAGE:-local/pasturestack/ipsec-vxlan-overlay-network:0.14.37}
old_image=${OLD_IMAGE:-}
startup_image=${old_image:-$image}
test_id=$$
Expand Down
2 changes: 1 addition & 1 deletion scripts/integration-two-node-vxlan
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
#!/bin/bash
set -euo pipefail

image=${IMAGE:-local/pasturestack/ipsec-vxlan-overlay-network:0.14.36}
image=${IMAGE:-local/pasturestack/ipsec-vxlan-overlay-network:0.14.37}
test_id=$$
network="pasture-vxlan-it-${test_id}"
node_a="pasture-vxlan-a-${test_id}"
Expand Down
4 changes: 2 additions & 2 deletions scripts/package
Original file line number Diff line number Diff line change
Expand Up @@ -15,8 +15,8 @@ PER_HOST_SUBNET_URL=${PER_HOST_SUBNET_URL:-https://github.com/PastureStack/per-h
PER_HOST_SUBNET_SHA256=${PER_HOST_SUBNET_SHA256:-d12acca4526eee45d52b87541717ae81432225d9c5dabfd823d6b43631c20e84}
HOST_LOCAL_CNI_IPAM_URL=${HOST_LOCAL_CNI_IPAM_URL:-https://github.com/PastureStack/host-local-cni-ipam/releases/download/v0.1.4/host-local-cni-ipam-0.1.4-linux-amd64}
HOST_LOCAL_CNI_IPAM_SHA256=${HOST_LOCAL_CNI_IPAM_SHA256:-9bb79b9f269663715f44aea898854df0e0e319a3ba35e4d52db5477cde026e3e}
FLAT_CNI_IPAM_URL=${FLAT_CNI_IPAM_URL:-https://github.com/PastureStack/flat-cni-ipam/releases/download/v0.1.4/flat-cni-ipam-v0.1.4-linux-amd64}
FLAT_CNI_IPAM_SHA256=${FLAT_CNI_IPAM_SHA256:-edbbe0924637381f95b268b259170d80434d3c37e0a5a7519c7e55b2e8957db5}
FLAT_CNI_IPAM_URL=${FLAT_CNI_IPAM_URL:-https://github.com/PastureStack/flat-cni-ipam/releases/download/v0.1.5/flat-cni-ipam-v0.1.5-linux-amd64}
FLAT_CNI_IPAM_SHA256=${FLAT_CNI_IPAM_SHA256:-c0044889348313d84d631e36121068fc5072fb423e25fcd795e6b34424f38de7}
MOUNT_PROPAGATION_URL=${MOUNT_PROPAGATION_URL:-https://github.com/PastureStack/mount-propagation/releases/download/v1.0.11/mount-propagation-v1.0.11-linux-amd64}
MOUNT_PROPAGATION_SHA256=${MOUNT_PROPAGATION_SHA256:-800bbc2d74c318ccc62d2c3c76846ee1fe307c21daf558c7edcf5de25e393a4b}

Expand Down
2 changes: 1 addition & 1 deletion scripts/validate
Original file line number Diff line number Diff line change
Expand Up @@ -49,7 +49,7 @@ for script in scripts/* package/*.sh package/update-platform-ca; do
bash -n "$script"
done

version=${VERSION_OVERRIDE:-0.14.36}
version=${VERSION_OVERRIDE:-0.14.37}
first=$(mktemp -d)
trap 'rm -rf "$first"' EXIT
VERSION_OVERRIDE="$version" ./scripts/build
Expand Down
Loading