runner: build egress by trust class; auth-flood scratch test !519

merged merged by cmc on 2026-09-29 03:57 UTC · krz/gitbay:runner-egress-260 into main

Discussion

cmc

Build egress by trust class, and the scratch test for #260.

  • The runner starts each podman build under builds/trusted or builds/untrusted in its service cgroup. It refuses to start without build cgroups when it sets limits, takes untrusted builds, or polls over loopback.
  • deploy/gitbay-runner-builds.nft (table inet gitbay_builds) matches build traffic by that cgroup: host loopback closed except DNS, private ranges closed; trusted builds keep the internet and the forge's public 22/80/443; untrusted builds get TCP 80/443 and DNS and not the forge. The drop-in creates the cgroups and loads the table on every start; the egress unit's reload loads it only when installed. make deploy-runner ships and checks it.
  • deploy/runner-auth-flood-test.sh <repo> [--untrusted]: a build failing SSH logins beside the runner; passes only if the build log shows the policy's effect and the runner kept polling.
  • Admin (install, checks, rollback), CI, Threat-Model, Users, Architecture 03/04/07/09/10; CHANGELOG.

Nothing reaches bay1 until make deploy-runner. Validate on a scratch-scoped runner first; the Admin page has the steps and the rollback. #260 closes when the test's result is recorded.

Ref #260