Repository navigation
Phase 2 S12.e: authoritative allowlistRef mode (fail-closed) - #120
Merged
Merged
Conversation
Pal Lakatos-Toth (pallakatos)
force-pushed
the
phase2-s12-e-authoritative
branch
from
April 30, 2026 01:22
061e557 to
7afa009
Compare
Promote spec.networkPolicy.allowlistRef from status-only to authoritative source for NetworkPolicy egress. * Lift AZURECLAW_FEATURE_SIGNED_ALLOWLIST env gate (always-on). * Add resolve_allowlist[_with_handle] in controller/src/policy_fetcher.rs implementing the four-branch decision tree: (1) no ref + inline → legacy inline path (2) ref + verify ok → artifact endpoints (LKG updated) (3) ref + verify fails + LKG present → LKG endpoints (4) ref + verify fails + no LKG → fail-closed (no user egress, no pod) * Add in-process per-(ns,name) last-known-good cache. Controller restart drops the LKG deliberately so the first post-restart reconcile of a verify-failing sandbox cannot ride a stale allowlist across an operator-visible event. * Surface three status conditions: AllowlistVerified (existing), AllowlistAuthoritative (new), AllowlistDrift (new) with 2-reconcile InlineCleared debounce. * Reconciler computes resolution once, drives both NP egress and status. fail_closed_no_lkg short-circuits pod deployment. * Helm CRD: new Allowlist printer column (priority 1); allowlistRef description updated. * CHANGELOG, audit doc, policy-canonical-format.md updated. * Tests: 401 → 412 controller (16 new − 5 removed feature-gate); full workspace cargo fmt/clippy/test green; helm lint green. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Pal Lakatos-Toth (pallakatos)
force-pushed
the
phase2-s12-e-authoritative
branch
from
April 30, 2026 01:33
7afa009 to
cf65a9b
Compare
Pal Lakatos-Toth (pallakatos)
added a commit
that referenced
this pull request
May 12, 2026
Promote spec.networkPolicy.allowlistRef from status-only to authoritative source for NetworkPolicy egress. * Lift AZURECLAW_FEATURE_SIGNED_ALLOWLIST env gate (always-on). * Add resolve_allowlist[_with_handle] in controller/src/policy_fetcher.rs implementing the four-branch decision tree: (1) no ref + inline → legacy inline path (2) ref + verify ok → artifact endpoints (LKG updated) (3) ref + verify fails + LKG present → LKG endpoints (4) ref + verify fails + no LKG → fail-closed (no user egress, no pod) * Add in-process per-(ns,name) last-known-good cache. Controller restart drops the LKG deliberately so the first post-restart reconcile of a verify-failing sandbox cannot ride a stale allowlist across an operator-visible event. * Surface three status conditions: AllowlistVerified (existing), AllowlistAuthoritative (new), AllowlistDrift (new) with 2-reconcile InlineCleared debounce. * Reconciler computes resolution once, drives both NP egress and status. fail_closed_no_lkg short-circuits pod deployment. * Helm CRD: new Allowlist printer column (priority 1); allowlistRef description updated. * CHANGELOG, audit doc, policy-canonical-format.md updated. * Tests: 401 → 412 controller (16 new − 5 removed feature-gate); full workspace cargo fmt/clippy/test green; helm lint green. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Promote
spec.networkPolicy.allowlistReffrom status-only (S12.b) toauthoritative source for NetworkPolicy egress. Lifts the
`AZURECLAW_FEATURE_SIGNED_ALLOWLIST` env gate (always-on).
What changed
`resolve_allowlist[_with_handle]` implements the 4-branch
decision tree:
(`Verified=True`, `Authoritative=True/Verified`,
`Drift=…` if inline differs)
(`Authoritative=False/StaleLKG`)
pod not deployed, Degraded + requeue
(`Authoritative=False/FailedClosed`).
controller restart drops it deliberately so a stale allowlist
cannot ride across an operator-visible event.
normalization. `InlineCleared` debounce (≤2 reconciles) before
the condition drops out of status.
rules and status patch. `fail_closed_no_lkg` short-circuits pod
deployment after writing the (no-user-rules) NP and stamping
Degraded.
`allowlistRef` description updated.
`docs/security-audits/2026-04-30-phase2-s12-e-authoritative.md`,
new "Authoritative mode" section in
`docs/policy-canonical-format.md`, CHANGELOG entry.
Tests
`controller/src/policy_fetcher.rs` (resolution branches, LKG round
trip, restart simulation, security property that inline is never a
silent fallback, drift normalization, malformed signer policy, …).
`cargo fmt --all && cargo clippy --all-targets -- -D warnings && cargo test --all`
green. `helm lint deploy/helm/azureclaw` green.
Migration
None. There is no installed base; the prior gate defaulted off, so no
production cluster relied on the old behavior. Operators who set
`allowlistRef` will now see verify run on the next reconcile —
either publish a SignerPolicy (S12.d) or unset the ref to keep using
inline endpoints.
Threat model
See `docs/security-audits/2026-04-30-phase2-s12-e-authoritative.md`.
Key properties:
deploy the pod
🤖 Generated with the assistance of GitHub Copilot.