Project

General

Profile

Actions

action #176241

open

[spike][timeboxed:10h] Only allow unauthorized asset access on OSD based on network interface size:S

Added by okurz about 1 month ago. Updated 8 days ago.

Status:
Workable
Priority:
Low
Assignee:
-
Category:
Feature requests
Start date:
Due date:
% Done:

0%

Estimated time:
Tags:

Description

Motivation

As discussed in #175902 there are certain use cases where unauthorized, unencrypted asset access is necessary, e.g.

if it turns out we can't or mustn't allow complete unauthenticated access to /iso/ or /repo/ then we could look into the approach to use a dedicated network interface for zone-cc traffic and other traffic, e.g. OSD openQA workers from NUE2. Then we can have separate nginx instances listening on the corresponding server IP addresses of separate interfaces with differing config, i.e. allow unauthenticated traffic within zone-cc but only authenticated traffic from and to other zones

Acceptance Criteria

  • AC1: We know how to configure NGINX to allow/disallow unauthorized assets downloads by network interface.

Suggestions


Related issues 2 (1 open1 closed)

Related to openQA Project (public) - action #176670: Allow-list for OSD asset downloadNew2025-02-06

Actions
Copied from openQA Infrastructure (public) - action #175902: Enable prevention of unauthorized asset downloads on OSD size:SResolvedmkittler2025-01-21

Actions
Actions #1

Updated by okurz about 1 month ago

  • Copied from action #175902: Enable prevention of unauthorized asset downloads on OSD size:S added
Actions #2

Updated by okurz about 1 month ago

  • Description updated (diff)
Actions #3

Updated by okurz about 1 month ago

Actions #4

Updated by okurz 13 days ago

  • Target version changed from future to Ready
Actions #5

Updated by tinita 8 days ago

  • Subject changed from Only allow unauthorized asset access on OSD based on network interface to [spike][timeboxed:10h] Only allow unauthorized asset access on OSD based on network interface size:S
  • Description updated (diff)
  • Status changed from New to Workable
Actions

Also available in: Atom PDF