| frickler | gthiemonge: please check https://review.opendev.org/c/openstack/releases/+/1006610 when you have a moment | 06:54 |
|---|---|---|
| gthiemonge | frickler: ack | 07:35 |
| frickler | ty | 07:51 |
| rm_work | Yeah it isn’t GOOD since heartbeat key could cause like … DoS? | 08:06 |
| rm_work | I don’t think there’s any other escalation though or leaks, we were pretty careful just design wise | 08:07 |
| gthiemonge | rm_work: the amphora-agent TLS stuff can be retrieved too | 08:18 |
| gthiemonge | rm_work: it also depends on the isolation of the management network, for instance in our downstream, it's totally isolated, but in other deployments it may give you access to the other internal networks | 08:19 |
| rm_work | True | 08:42 |
| rm_work | Well I left a comment on the bug, not that it matters 😅 | 08:53 |
| rm_work | I remember we very specifically attempted to architect for a rogue amphora, and I’m glad we did 😇 | 08:53 |
| rm_work | Still a real problem obviously, but I’d not be panicking as much as a deployer I think as otherwise | 08:55 |
| gthiemonge | rm_work: thanks for adding the comment, yeah I agree the CVE score doesn't really reflect the severity of the issue | 09:06 |
| rm_work | I’d need to check to verify it’s still the case, but per our original design on paper, the amphora should only be able to get config for itself even if you can impersonate it | 11:52 |
| rm_work | I hope that’s still true | 11:53 |
| gthiemonge | rm_work: the octavia services push the config (and TLS stuff) to the amps, an amphora cannot fetch anything from the control plane | 12:47 |
| rm_work | Right, I did think there was a “you should resend the config” trigger | 16:12 |
| rm_work | But again, shouldn’t leak anything | 16:13 |
| -opendevstatus- NOTICE: The Gerrit service on review.opendev.org will be offline momentarily while we upgrade to a new patch release, but should return within a few minutes | 23:01 | |
Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!