mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: block CONNECT tunnels to private/reserved IP ranges (#23109)
## Description Blocks `CONNECT` tunnels to private and reserved IP ranges in aibridgeproxyd, preventing the proxy from being used to reach internal networks. The Coder access URL is always exempt (hostname+port match) so the proxy can reach its own deployment. It is possible to exempt additional ranges via `CODER_AIBRIDGE_PROXY_ALLOWED_PRIVATE_CIDRS`. DNS rebinding is handled differently per path: * Direct (no upstream proxy): validate the resolved IP right before the TCP dial, no window between check and connect. * Upstream proxy: Resolves and checks before forwarding to the upstream dialer. A small rebinding window exists since the upstream proxy re-resolves independently. ## Changes * Add blocked IP denylist covering private, reserved, and special-purpose ranges * Add `AllowedPrivateCIDRs` option with CLI flag and env var * Wire IP checks into `proxy.ConnectDial` for both upstream and direct paths * Add tests for blocked/allowed cases across direct dial, upstream proxy, CIDR exemptions, and CoderAccessURL exemption Notes: documentation will be handled in a follow-up PR. Closes: https://github.com/coder/security/issues/124
This commit is contained in:
Generated
+3
@@ -163,6 +163,9 @@ curl -X GET http://coder-server:8080/api/v2/deployment/config \
|
||||
"agent_stat_refresh_interval": 0,
|
||||
"ai": {
|
||||
"aibridge_proxy": {
|
||||
"allowed_private_cidrs": [
|
||||
"string"
|
||||
],
|
||||
"cert_file": "string",
|
||||
"domain_allowlist": [
|
||||
"string"
|
||||
|
||||
Generated
+24
-11
@@ -618,6 +618,9 @@
|
||||
|
||||
```json
|
||||
{
|
||||
"allowed_private_cidrs": [
|
||||
"string"
|
||||
],
|
||||
"cert_file": "string",
|
||||
"domain_allowlist": [
|
||||
"string"
|
||||
@@ -634,17 +637,18 @@
|
||||
|
||||
### Properties
|
||||
|
||||
| Name | Type | Required | Restrictions | Description |
|
||||
|---------------------|-----------------|----------|--------------|-------------|
|
||||
| `cert_file` | string | false | | |
|
||||
| `domain_allowlist` | array of string | false | | |
|
||||
| `enabled` | boolean | false | | |
|
||||
| `key_file` | string | false | | |
|
||||
| `listen_addr` | string | false | | |
|
||||
| `tls_cert_file` | string | false | | |
|
||||
| `tls_key_file` | string | false | | |
|
||||
| `upstream_proxy` | string | false | | |
|
||||
| `upstream_proxy_ca` | string | false | | |
|
||||
| Name | Type | Required | Restrictions | Description |
|
||||
|-------------------------|-----------------|----------|--------------|-------------|
|
||||
| `allowed_private_cidrs` | array of string | false | | |
|
||||
| `cert_file` | string | false | | |
|
||||
| `domain_allowlist` | array of string | false | | |
|
||||
| `enabled` | boolean | false | | |
|
||||
| `key_file` | string | false | | |
|
||||
| `listen_addr` | string | false | | |
|
||||
| `tls_cert_file` | string | false | | |
|
||||
| `tls_key_file` | string | false | | |
|
||||
| `upstream_proxy` | string | false | | |
|
||||
| `upstream_proxy_ca` | string | false | | |
|
||||
|
||||
## codersdk.AIBridgeTokenUsage
|
||||
|
||||
@@ -745,6 +749,9 @@
|
||||
```json
|
||||
{
|
||||
"aibridge_proxy": {
|
||||
"allowed_private_cidrs": [
|
||||
"string"
|
||||
],
|
||||
"cert_file": "string",
|
||||
"domain_allowlist": [
|
||||
"string"
|
||||
@@ -2697,6 +2704,9 @@ CreateWorkspaceRequest provides options for creating a new workspace. Only one o
|
||||
"agent_stat_refresh_interval": 0,
|
||||
"ai": {
|
||||
"aibridge_proxy": {
|
||||
"allowed_private_cidrs": [
|
||||
"string"
|
||||
],
|
||||
"cert_file": "string",
|
||||
"domain_allowlist": [
|
||||
"string"
|
||||
@@ -3272,6 +3282,9 @@ CreateWorkspaceRequest provides options for creating a new workspace. Only one o
|
||||
"agent_stat_refresh_interval": 0,
|
||||
"ai": {
|
||||
"aibridge_proxy": {
|
||||
"allowed_private_cidrs": [
|
||||
"string"
|
||||
],
|
||||
"cert_file": "string",
|
||||
"domain_allowlist": [
|
||||
"string"
|
||||
|
||||
Reference in New Issue
Block a user