初始提交:DSH 多租户平台(dshs)

This commit is contained in:
admin committed 2026-09-13 16:18:10 +08:00
commit 43976fea6a
167 files changed
+24456

No files matched your search

@@ -0,0 +1,18 @@
# 仅控制面(app=dsh-orchestrator)可入 DSH Pod 的 8081(§4.4 单向放行)。
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: allow-controlplane-to-dsh
namespace: dsh-poc
spec:
podSelector:
matchLabels:
app: dsh
policyTypes: [Ingress]
ingress:
- from:
- podSelector:
matchLabels:
app: dsh-orchestrator
ports:
- port: 8081
+10
View File
@@ -0,0 +1,10 @@
# 命名空间内默认拒绝所有 ingress(§3.5 / §4.4)。依赖 CNI 强制(Cilium)。
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: default-deny-ingress
namespace: dsh-poc
spec:
podSelector: {}
policyTypes: [Ingress]
# 空 ingress = 拒绝一切入站
+47
View File
@@ -0,0 +1,47 @@
# 目标 DSH Pod(app=dsh)+ 控制面源(app=dsh-orchestrator)+ 攻击源(app=attacker)。
apiVersion: v1
kind: Pod
metadata:
name: dsh-target
namespace: dsh-poc
labels: { app: dsh, user: u1 }
spec:
automountServiceAccountToken: false
containers:
- name: dsh
image: node:22-alpine
command: ["node", "/app/target.mjs"]
ports: [{ containerPort: 8081 }]
volumeMounts:
- name: script
mountPath: /app
volumes:
- name: script
configMap:
name: dsh-target-script
---
apiVersion: v1
kind: Pod
metadata:
name: controlplane
namespace: dsh-poc
labels: { app: dsh-orchestrator }
spec:
containers:
- name: src
image: busybox:1.36
command: ["sleep", "3600"]
---
apiVersion: v1
kind: Pod
metadata:
name: attacker
namespace: dsh-poc
labels: { app: attacker }
spec:
containers:
- name: src
image: busybox:1.36
command: ["sleep", "3600"]
+43
View File
@@ -0,0 +1,43 @@
#!/usr/bin/env bash
set -euo pipefail
NS=dsh-poc
HERE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
pass() { echo "PASS: $*"; }
fail() { echo "FAIL: $*"; exit 1; }
kubectl create namespace "$NS" --dry-run=client -o yaml | kubectl apply -f - >/dev/null
kubectl create configmap dsh-target-script --from-file="$HERE/target.mjs" -n "$NS" --dry-run=client -o yaml | kubectl apply -f - >/dev/null
echo "== apply pods =="
kubectl apply -f "$HERE/pods.yaml" >/dev/null
kubectl wait -n "$NS" --for=condition=Ready pod/dsh-target --timeout=120s
kubectl wait -n "$NS" --for=condition=Ready pod/controlplane --timeout=120s
kubectl wait -n "$NS" --for=condition=Ready pod/attacker --timeout=120s
echo "== apply NetworkPolicy (default-deny + allow control-plane) =="
kubectl apply -f "$HERE/default-deny.yaml" >/dev/null
kubectl apply -f "$HERE/allow-controlplane.yaml" >/dev/null
sleep 2
IP="$(kubectl get -n "$NS" pod dsh-target -o jsonpath='{.status.podIP}')"
URL="http://$IP:8081/"
echo "target pod IP: $IP"
echo "== control-plane -> dsh (must succeed) =="
if kubectl exec -n "$NS" controlplane -- wget -q -T 5 -O- "$URL" 2>/dev/null | grep -q 'dsh-ok'; then
pass "control-plane reaches dsh:8081"
else
fail "control-plane could NOT reach dsh:8081 (policy or CNI not enforced as expected)"
fi
echo "== attacker -> dsh (must be blocked) =="
if kubectl exec -n "$NS" attacker -- wget -q -T 5 -O- "$URL" >/dev/null 2>&1; then
fail "attacker reached dsh:8081 — NetworkPolicy NOT enforced (flannel? check CNI)"
else
pass "attacker is blocked from dsh:8081 (default-deny enforced)"
fi
echo
echo "ALL ITEM-3 CHECKS PASSED"
+7
View File
@@ -0,0 +1,7 @@
// Target "DSH" for the NetworkPolicy PoC: HTTP 200 on 0.0.0.0:8081.
import { createServer } from 'node:http'
createServer((req, res) => {
res.writeHead(200, { 'Content-Type': 'text/plain' })
res.end('dsh-ok\n')
}).listen(8081, '0.0.0.0', () => console.log('target listening on 0.0.0.0:8081'))