Merge pull request #5033 from Ricardo-binZzz/fix/sub2api-no-new-privileges
fix(deploy): prevent application privilege gains
This commit is contained in:
@@ -17,6 +17,8 @@ services:
|
||||
NPM_CONFIG_REGISTRY: ${NPM_CONFIG_REGISTRY:-https://registry.npmmirror.com}
|
||||
container_name: sub2api-dev
|
||||
restart: unless-stopped
|
||||
security_opt:
|
||||
- no-new-privileges:true
|
||||
ports:
|
||||
- "${BIND_HOST:-127.0.0.1}:${SERVER_PORT:-8080}:8080"
|
||||
volumes:
|
||||
|
||||
@@ -27,6 +27,8 @@ services:
|
||||
image: weishaw/sub2api:latest
|
||||
container_name: sub2api
|
||||
restart: unless-stopped
|
||||
security_opt:
|
||||
- no-new-privileges:true
|
||||
ulimits:
|
||||
nofile:
|
||||
soft: 100000
|
||||
|
||||
@@ -15,6 +15,8 @@ services:
|
||||
image: weishaw/sub2api:latest
|
||||
container_name: sub2api
|
||||
restart: unless-stopped
|
||||
security_opt:
|
||||
- no-new-privileges:true
|
||||
ulimits:
|
||||
nofile:
|
||||
soft: 100000
|
||||
|
||||
@@ -19,6 +19,8 @@ services:
|
||||
image: weishaw/sub2api:latest
|
||||
container_name: sub2api
|
||||
restart: unless-stopped
|
||||
security_opt:
|
||||
- no-new-privileges:true
|
||||
ulimits:
|
||||
nofile:
|
||||
soft: 100000
|
||||
|
||||
Executable
+44
@@ -0,0 +1,44 @@
|
||||
#!/bin/sh
|
||||
set -eu
|
||||
|
||||
repo_root=$(CDPATH= cd -- "$(dirname -- "$0")/../.." && pwd)
|
||||
cd "$repo_root"
|
||||
|
||||
check_application_security_opt() {
|
||||
file=$1
|
||||
count=$(
|
||||
awk '
|
||||
$0 == " sub2api:" {
|
||||
in_application = 1
|
||||
next
|
||||
}
|
||||
in_application && $0 ~ /^ [A-Za-z0-9_-]+:$/ {
|
||||
in_application = 0
|
||||
}
|
||||
in_application && $0 == " security_opt:" {
|
||||
in_security_opt = 1
|
||||
next
|
||||
}
|
||||
in_application && in_security_opt && $0 == " - no-new-privileges:true" {
|
||||
count++
|
||||
}
|
||||
END { print count + 0 }
|
||||
' "$file"
|
||||
)
|
||||
|
||||
if [ "$count" -ne 1 ]; then
|
||||
printf '%s must enable no-new-privileges exactly once for the sub2api service\n' "$file" >&2
|
||||
exit 1
|
||||
fi
|
||||
}
|
||||
|
||||
for compose_file in \
|
||||
deploy/docker-compose.yml \
|
||||
deploy/docker-compose.local.yml \
|
||||
deploy/docker-compose.standalone.yml \
|
||||
deploy/docker-compose.dev.yml
|
||||
do
|
||||
check_application_security_opt "$compose_file"
|
||||
done
|
||||
|
||||
printf 'docker compose security test passed\n'
|
||||
Reference in New Issue
Block a user