初始提交:DSH 多租户平台(dshs)
This commit is contained in:
commit
43976fea6a
167 files changed
+24456
No files matched your search
@@ -0,0 +1,18 @@
|
||||
# 仅控制面(app=dsh-orchestrator)可入 DSH Pod 的 8081(§4.4 单向放行)。
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: NetworkPolicy
|
||||
metadata:
|
||||
name: allow-controlplane-to-dsh
|
||||
namespace: dsh-poc
|
||||
spec:
|
||||
podSelector:
|
||||
matchLabels:
|
||||
app: dsh
|
||||
policyTypes: [Ingress]
|
||||
ingress:
|
||||
- from:
|
||||
- podSelector:
|
||||
matchLabels:
|
||||
app: dsh-orchestrator
|
||||
ports:
|
||||
- port: 8081
|
||||
@@ -0,0 +1,10 @@
|
||||
# 命名空间内默认拒绝所有 ingress(§3.5 / §4.4)。依赖 CNI 强制(Cilium)。
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: NetworkPolicy
|
||||
metadata:
|
||||
name: default-deny-ingress
|
||||
namespace: dsh-poc
|
||||
spec:
|
||||
podSelector: {}
|
||||
policyTypes: [Ingress]
|
||||
# 空 ingress = 拒绝一切入站
|
||||
@@ -0,0 +1,47 @@
|
||||
# 目标 DSH Pod(app=dsh)+ 控制面源(app=dsh-orchestrator)+ 攻击源(app=attacker)。
|
||||
apiVersion: v1
|
||||
kind: Pod
|
||||
metadata:
|
||||
name: dsh-target
|
||||
namespace: dsh-poc
|
||||
labels: { app: dsh, user: u1 }
|
||||
spec:
|
||||
automountServiceAccountToken: false
|
||||
containers:
|
||||
- name: dsh
|
||||
image: node:22-alpine
|
||||
command: ["node", "/app/target.mjs"]
|
||||
ports: [{ containerPort: 8081 }]
|
||||
volumeMounts:
|
||||
- name: script
|
||||
mountPath: /app
|
||||
volumes:
|
||||
- name: script
|
||||
configMap:
|
||||
name: dsh-target-script
|
||||
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Pod
|
||||
metadata:
|
||||
name: controlplane
|
||||
namespace: dsh-poc
|
||||
labels: { app: dsh-orchestrator }
|
||||
spec:
|
||||
containers:
|
||||
- name: src
|
||||
image: busybox:1.36
|
||||
command: ["sleep", "3600"]
|
||||
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Pod
|
||||
metadata:
|
||||
name: attacker
|
||||
namespace: dsh-poc
|
||||
labels: { app: attacker }
|
||||
spec:
|
||||
containers:
|
||||
- name: src
|
||||
image: busybox:1.36
|
||||
command: ["sleep", "3600"]
|
||||
@@ -0,0 +1,43 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
NS=dsh-poc
|
||||
HERE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
|
||||
pass() { echo "PASS: $*"; }
|
||||
fail() { echo "FAIL: $*"; exit 1; }
|
||||
|
||||
kubectl create namespace "$NS" --dry-run=client -o yaml | kubectl apply -f - >/dev/null
|
||||
kubectl create configmap dsh-target-script --from-file="$HERE/target.mjs" -n "$NS" --dry-run=client -o yaml | kubectl apply -f - >/dev/null
|
||||
|
||||
echo "== apply pods =="
|
||||
kubectl apply -f "$HERE/pods.yaml" >/dev/null
|
||||
kubectl wait -n "$NS" --for=condition=Ready pod/dsh-target --timeout=120s
|
||||
kubectl wait -n "$NS" --for=condition=Ready pod/controlplane --timeout=120s
|
||||
kubectl wait -n "$NS" --for=condition=Ready pod/attacker --timeout=120s
|
||||
|
||||
echo "== apply NetworkPolicy (default-deny + allow control-plane) =="
|
||||
kubectl apply -f "$HERE/default-deny.yaml" >/dev/null
|
||||
kubectl apply -f "$HERE/allow-controlplane.yaml" >/dev/null
|
||||
sleep 2
|
||||
|
||||
IP="$(kubectl get -n "$NS" pod dsh-target -o jsonpath='{.status.podIP}')"
|
||||
URL="http://$IP:8081/"
|
||||
echo "target pod IP: $IP"
|
||||
|
||||
echo "== control-plane -> dsh (must succeed) =="
|
||||
if kubectl exec -n "$NS" controlplane -- wget -q -T 5 -O- "$URL" 2>/dev/null | grep -q 'dsh-ok'; then
|
||||
pass "control-plane reaches dsh:8081"
|
||||
else
|
||||
fail "control-plane could NOT reach dsh:8081 (policy or CNI not enforced as expected)"
|
||||
fi
|
||||
|
||||
echo "== attacker -> dsh (must be blocked) =="
|
||||
if kubectl exec -n "$NS" attacker -- wget -q -T 5 -O- "$URL" >/dev/null 2>&1; then
|
||||
fail "attacker reached dsh:8081 — NetworkPolicy NOT enforced (flannel? check CNI)"
|
||||
else
|
||||
pass "attacker is blocked from dsh:8081 (default-deny enforced)"
|
||||
fi
|
||||
|
||||
echo
|
||||
echo "ALL ITEM-3 CHECKS PASSED"
|
||||
@@ -0,0 +1,7 @@
|
||||
// Target "DSH" for the NetworkPolicy PoC: HTTP 200 on 0.0.0.0:8081.
|
||||
import { createServer } from 'node:http'
|
||||
|
||||
createServer((req, res) => {
|
||||
res.writeHead(200, { 'Content-Type': 'text/plain' })
|
||||
res.end('dsh-ok\n')
|
||||
}).listen(8081, '0.0.0.0', () => console.log('target listening on 0.0.0.0:8081'))
|
||||
Reference in new issue
Block a user