Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Applied for security audit #964

Closed
csantanapr opened this issue Mar 10, 2022 · 10 comments
Closed

Applied for security audit #964

csantanapr opened this issue Mar 10, 2022 · 10 comments
Assignees

Comments

@csantanapr
Copy link
Member

csantanapr commented Mar 10, 2022

Applied for CNCF security audit

Having a security audit performed by CNCF contractor for Knative is a requirement for CNCF project graduation.

I was advised by @caniszczyk to go ahead and open a service ticket now, since there is a large backlog for the Security contractor

cc @evankanderson

@csantanapr
Copy link
Member Author

@evankanderson Do you have access now with your knative.team email to service desk?
This will allow you to open a ticket requesting the security audit for knative, this would put us in the queue of a few months to be done.

@evankanderson
Copy link
Member

@csantanapr csantanapr moved this to Todo in CNCF Onboarding Mar 30, 2022
@csantanapr
Copy link
Member Author

Thank you @evankanderson it looks like CNFC got you in contact with the auditor

I dropped an intro to **** amir@ostif.org who will send you a template to fill out in scoping the audit, they will then run an RFP process and find a vendor which CNCF will pay for. The backlog is quite long so I’d expect at least a few months before this officially gets started.

Let us know how it goes once you have more info.

@evankanderson
Copy link
Member

I chatted with Amir on Tuesday, and we filled out an audit questionnaire together:

https://docs.google.com/document/d/1YaEK5zWmOk1G_eFuiJCPYGm7nWc2l97eBK3wINYNJTE/edit

Sometime (possibly post-Kubecon), we'll probably put together two RFPs:

Serving

A standard security audit, taking into account the in-progress encryption of KIngress -> activator -> queue_proxy path.

Eventing

Probably a more protocol-focused audit this time, focusing on modeling necessary controls and mitigations, probably including:

  • TLS capability for Addressable resources with cluster.local endpoints (which can't use public CAs like LetsEncypt)
  • Sender identity (probably OAuth / OpenID Connect rooted in the kube-apiserver's ability to mint tokens, and an aud parameter indicated by the Addressable)
  • Some form of data-plane RBAC to be able to restrict who can send to a given Addressable
  • Necessary RBAC controls on the control plane, possibly by describing the controls to be used with a policy system like Gatekeeper or Kyverno

@evankanderson evankanderson moved this from Todo to In Progress in CNCF Onboarding Apr 28, 2022
@csantanapr
Copy link
Member Author

@evankanderson any updates on this front?

@Amir-Montazery
Copy link

Hi everyone! I have emailed @evankanderson a few times since July about this but have not heard back. We are ready and happy to continue the conversation and help knative get their security audit done as we do with many cncf projects!

@evankanderson
Copy link
Member

evankanderson commented Oct 17, 2022

Sorry, this got dropped under a bunch of vacation and acquisition traffic -- I'll dig out the emails and respond today.

@evankanderson evankanderson moved this from In Progress to Ready to Work in Security WG Roadmap Mar 2, 2023
@evankanderson evankanderson moved this from Ready to Work to In Progress in Security WG Roadmap Jun 8, 2023
@aliok
Copy link
Member

aliok commented Jan 12, 2024

@aliok
Copy link
Member

aliok commented Jan 12, 2024

/close

Copy link

knative-prow bot commented Jan 12, 2024

@aliok: Closing this issue.

In response to this:

/close

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@knative-prow knative-prow bot closed this as completed Jan 12, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Archived in project
Status: In Progress
Development

No branches or pull requests

4 participants