Repository navigation
fix(proxy): opt-in console TLS so OIDC works - #210
Merged
Merged
Conversation
DFE_PROXY_TLS=true chains docker-compose.tls.yml: both proxies serve TLS from certs/, the network is pinned and dfe-engine trusts only dfe-proxy's address for X-Forwarded-Proto, so an OIDC callback on a hostname comes back https. Off by default; make refuses a bad cert, an http origin, a subnet clash, a dial flip without make down and any origin that carries a port or path. Fixes #207
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #207
OIDC sign-in could not complete on a Compose stack reached by hostname: the engine's cookies are
Secureoutside a dev posture whiledfe-proxyserved plain HTTP, and the engine built anhttp://callback because it did not trust the proxy'sX-Forwarded-Proto.DFE_PROXY_TLS=true(defaultfalse) chainsdocker-compose.tls.yml:certs/console.crtandconsole.key, usingconfig/proxy/*.tls.yaml. A test holds those equal to the plain configs outside their TLS blocks. The HyperDX ports also keep plain HTTP for in-network callers.DFE_NETWORK_SUBNET, default10.207.0.0/24),dfe-proxygets a static address anddfe-enginetrusts only that address, never the bridge gateway.makerefuses to start on a missing, symlinked or mismatched cert and key, anhttporigin, a subnet that overlaps another Docker network, a dial flip withoutmake downand the auth profile (oauth2-proxy has no TLS yet).makenow refuses an origin that carries a port or path, since Compose appends the port itself.make check-proxyvalidates all four Envoy configs (pinned image, matching dfe-infra's version) and runs in CI.With the dial off,
docker-compose.ymland both plain proxy configs are unchanged.Tested:
make check-hardfail,check-docsandcheck-proxypass, ruff is clean and 931 tests pass. On a live stack with an Okta provider, OIDC sign-in completed overhttps://<hostname>:3000with TLS 1.3 (X25519MLKEM768, AES-256-GCM). The callback returned 303 and the engine logged the real client address. Not tested: rootless Docker and the new CI step on the runner.