mirror of
https://github.com/Katakate/k7.git
synced 2026-10-03 12:10:22 +00:00
updated docs with dns-exfiltration-safe defaults and security note
This commit is contained in:
@@ -32,14 +32,14 @@ Body example:
|
||||
}
|
||||
```
|
||||
|
||||
Body example with egress whitelist:
|
||||
Body example with egress whitelist (safe pattern: proxy IP only):
|
||||
|
||||
```json
|
||||
{
|
||||
"name": "my-restricted-sandbox",
|
||||
"image": "alpine:latest",
|
||||
"namespace": "default",
|
||||
"egress_whitelist": ["1.1.1.1/32", "8.8.8.8/32"],
|
||||
"egress_whitelist": ["10.0.0.5/32"],
|
||||
"limits": {"cpu": "500m", "memory": "512Mi"}
|
||||
}
|
||||
```
|
||||
|
||||
@@ -105,12 +105,12 @@ Partial isolation (no inter-VM communication, but external internet allowed):
|
||||
{ "name": "partial-isolation", "image": "alpine:latest" }
|
||||
```
|
||||
|
||||
Whitelist specific external services:
|
||||
Whitelist specific external services (avoid public DNS resolvers):
|
||||
```json
|
||||
{
|
||||
"name": "egress-restricted",
|
||||
"image": "alpine:latest",
|
||||
"egress_whitelist": ["1.1.1.1/32", "8.8.8.8/32"]
|
||||
"egress_whitelist": ["10.0.0.5/32"]
|
||||
}
|
||||
```
|
||||
|
||||
@@ -121,6 +121,10 @@ Whitelist specific external services:
|
||||
- **Administrative access**: `kubectl exec`, `k7 shell`, and API operations bypass network policies
|
||||
</Info>
|
||||
|
||||
<Warning>
|
||||
Do not whitelist public DNS resolver IPs (e.g., 1.1.1.1, 8.8.8.8). Because K7's `egress_whitelist` is CIDR-only (no L7/port rules), allowing those IPs enables outbound DNS (UDP/TCP 53) and DNS-over-HTTPS (443), which can be used for exfiltration. If you want an egress deny with whitelisting, prefer whitelisting only your own egress proxy/gateway IP and enforce DNS/DoH policy at that proxy. Later, whenever we integrate Cilium (a roadmap feature), it will be much simpler as you'll be able to whitelist domain names directly.
|
||||
</Warning>
|
||||
|
||||
### Mitigations when DNS is blocked
|
||||
|
||||
- Use IP/CIDR whitelisting only (no domains post-lockdown)
|
||||
|
||||
Reference in New Issue
Block a user