Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 5 additions & 5 deletions docs/adr/index.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -1091,7 +1091,7 @@
},
{
"id": "ADR-017-R5",
"description": "A workspace egress selector is resolved once at CMS launch admission while holding the workspace mutation mutex. The compatibility value inherits the normalized deployment baseline and `none` selects ADR-026 zero egress. The resulting closed mode is persisted on Engine Range, replay-verified, and transported in the exact operation-generation input beside (never inside) scenario/RAES contracts. Workspace identity and mutable policy documents do not cross into Engine provider adapters, task argv/environment, labels, events, or guest metadata.",
"description": "A workspace egress selector is resolved at CMS launch admission while holding the policy workspace mutation mutex. Ordinarily the policy workspace is the range's authorized ownership workspace. For a server-derived CTF participant or managed-spare launch, the immutable event workspace may instead supply policy while the range remains bound to its individual owner's workspace; event ownership and current event-workspace authority must be checked, and public callers may not supply this override. The compatibility value inherits the normalized deployment baseline and `none` selects ADR-026 zero egress. The resulting closed mode is persisted on Engine Range, replay-verified, and transported in the exact operation-generation input beside (never inside) scenario/RAES contracts. Workspace identity and mutable policy documents do not cross into Engine provider adapters, task argv/environment, labels, events, or guest metadata.",
"checks": []
}
],
Expand Down Expand Up @@ -1463,7 +1463,7 @@
},
{
"id": "ADR-026-R6",
"description": "GCP zero egress must be realized behind the existing GCE range-cell provider seam with native Cloud NAT and VPC firewall resources. The stable `ALL_SUBNETWORKS_ALL_IP_RANGES` NAT posture is incompatible with a per-range `none` subnet and must be replaced through a coordinated migration that preserves NAT for existing/default ranges before it is removed. A firewall-only implementation, concurrent per-range patching of one Terraform-owned NAT object, or an unvalidated switch to the currently unreachable `vpc-per-range` mode is prohibited.",
"description": "GCP zero egress must be realized behind the existing GCE range-cell provider seam with native Cloud NAT and VPC firewall resources. A shared-VPC deployment may replace range-owned routers with region-scoped shared Router/NAT capacity only when one owner serializes explicit subnet enrollment and removal, reconciles provider drift, bounds each gateway by provider subnet/port/address limits, and never enrolls a `none` subnet. The Terraform migration-bridge NAT and provisioner-owned NAT must not manage the same subnet or mutate the same Router. The stable `ALL_SUBNETWORKS_ALL_IP_RANGES` NAT posture is incompatible with a per-range `none` subnet; migration must preserve existing/default-range NAT until each subnet is safely transferred. A firewall-only implementation, concurrent per-range patching of a Terraform-owned NAT object, or an unvalidated switch to `vpc-per-range` mode is prohibited.",
"checks": []
}
],
Expand Down Expand Up @@ -2810,7 +2810,7 @@
},
{
"id": "ADR-046-R10",
"description": "Workspace quota and workspace range-policy evaluation compose at one CMS pre-reservation launch-admission seam parameterized by authorized workspace, individual owner, server-derived range source, trusted instantiation purpose, and stable server-minted request correlation. Enforcing concurrent-range quota uses a workspaces-owned durable idempotent reservation identified by workspace, resource, and correlation under the workspace mutation mutex rather than a count-then-create race, remains distinct from the per-user/source active-range constraint and Engine's event/provider-capacity ledger, and releases only on terminal FAILED/DESTROYED convergence (not DESTROYING or CMS soft delete). Member-seat quota composes once in the common locked membership insert used by direct add and invitation acceptance; membership rows remain canonical usage and pending invitations are not seats. Missing policy preserves unlimited compatibility; soft/advisory overage warns and records while hard/enforcing overage records then blocks without rolling its decision evidence back. Quota reads reuse READ_WORKSPACE authority; policy authoring is a service-backed, strict-audited superuser operation reached through the Django-admin escape hatch, never workspace-role authority or a raw model save. Quota decisions pin bounded policy/usage/reason facts as append-only workspaces-domain evidence, with applied-limit audit events emitted transactionally through shared.audit. The workspace egress selector extends the canonical installation RangeEgressMode vocabulary, resolves under the workspace mutation mutex, pins one closed effective decision on the Engine range, and is replay-verified; workspace identity, membership, role, quota/policy documents, and decisions never enter scenario/RAES contracts, provisioner argv/environment, events, provider labels, or guest metadata.",
"description": "Workspace quota and workspace range-policy evaluation compose at one CMS pre-reservation launch-admission seam parameterized by authorized ownership workspace, individual owner, server-derived range source, trusted instantiation purpose, and stable server-minted request correlation. Enforcing concurrent-range quota uses a workspaces-owned durable idempotent reservation identified by ownership workspace, resource, and correlation under the workspace mutation mutex rather than a count-then-create race, remains distinct from the per-user/source active-range constraint and Engine's event/provider-capacity ledger, and releases only on terminal FAILED/DESTROYED convergence (not DESTROYING or CMS soft delete). Member-seat quota composes once in the common locked membership insert used by direct add and invitation acceptance; membership rows remain canonical usage and pending invitations are not seats. Missing policy preserves unlimited compatibility; soft/advisory overage warns and records while hard/enforcing overage records then blocks without rolling its decision evidence back. Quota reads reuse READ_WORKSPACE authority; policy authoring is a service-backed, strict-audited superuser operation reached through the Django-admin escape hatch, never workspace-role authority or a raw model save. Quota decisions pin bounded policy/usage/reason facts as append-only workspaces-domain evidence, with applied-limit audit events emitted transactionally through shared.audit. The workspace egress selector extends the canonical installation RangeEgressMode vocabulary, resolves under its policy workspace mutation mutex, pins one closed effective decision on the Engine range, and is replay-verified. A trusted CTF participant/spare launch may use its immutable event workspace for that selector while retaining individual ownership workspace for scope and quota; two-workspace locking must be ordered and current authority rechecked. Workspace identity, membership, role, quota/policy documents, and decisions never enter scenario/RAES contracts, provisioner argv/environment, events, provider labels, or guest metadata.",
"checks": []
},
{
Expand Down Expand Up @@ -3676,7 +3676,7 @@
"title": "GCP live-fire range cells use provider-enforced isolation and participant-bounded identity",
"status": "accepted",
"scope": "gcp_range_plane",
"decision": "A compromised GCE live-fire guest, including root on a Docker host, is confined by provider-enforced per-range subnet/tag firewall policy, range-owned routing and NAT, a complete deny inventory of the management and range networks, and participant-bounded IAM. Participant-controlled VMs have no external NIC and default to no attached Google service account; a service account may be attached only for an explicitly approved capability that cannot use the existing provisioner bootstrap boundary, and its token is treated as participant-visible, range-bounded, and without Compute, IAM, project Secret Manager, shared Storage, or control-plane authority. Guest or container metadata firewalling is defense in depth: because a root guest can reach the GCE metadata endpoint, containment is proven by absence of a management or cross-range credential and by root-context effective-permission tests, with any retained narrow capability explicitly accepted. Range egress is range-owned: each non-zero-egress range gets its own Cloud NAT and a zero-egress range gets none; any shared NAT is a bounded migration bridge that enrolls only explicitly listed pre-migration subnets and never every subnet. Sanctioned egress lanes target the public-internet complement and operator allow-CIDRs that are validated to exclude the denied-network inventory, so a guest cannot reach management, peer-range, private-service, or metadata destinations through them. The canonical provider-neutral range-cell, egress, instantiation-policy, lifecycle, and escape-report contracts remain authoritative; GCP firewall/NAT/IAM are realizations below them. GDC VM Runtime, scenario Pods, L2 Networks, namespaces, and NetworkAttachmentDefinitions remain non-user validation resources and are not hardened or reopened as participant containment.",
"decision": "A compromised GCE live-fire guest, including root on a Docker host, is confined by provider-enforced per-range subnet/tag firewall policy, explicitly scoped NAT enrollment, a complete deny inventory of the management and range networks, and participant-bounded IAM. Participant-controlled VMs have no external NIC and default to no attached Google service account; a service account may be attached only for an explicitly approved capability that cannot use the existing provisioner bootstrap boundary, and its token is treated as participant-visible, range-bounded, and without Compute, IAM, project Secret Manager, shared Storage, or control-plane authority. Guest or container metadata firewalling is defense in depth: because a root guest can reach the GCE metadata endpoint, containment is proven by absence of a management or cross-range credential and by root-context effective-permission tests, with any retained narrow capability explicitly accepted. Each non-zero-egress range has its own explicit subnet membership on either its range-owned NAT or serialized provisioner-owned regional shared NAT; a zero-egress range has no NAT membership. Terraform's independently owned shared NAT remains only a bounded migration bridge for explicitly listed pre-migration subnets, never every subnet. Sanctioned egress lanes target the public-internet complement and operator allow-CIDRs that are validated to exclude the denied-network inventory, so a guest cannot reach management, peer-range, private-service, or metadata destinations through them. The canonical provider-neutral range-cell, egress, instantiation-policy, lifecycle, and escape-report contracts remain authoritative; GCP firewall/NAT/IAM are realizations below them. GDC VM Runtime, scenario Pods, L2 Networks, namespaces, and NetworkAttachmentDefinitions remain non-user validation resources and are not hardened or reopened as participant containment.",
"rules": [
{
"id": "ADR-056-R1",
Expand All @@ -3685,7 +3685,7 @@
},
{
"id": "ADR-056-R2",
"description": "Range egress is range-owned. Each non-zero-egress range gets its own regional Cloud NAT and a zero-egress (`none`) range gets none; any shared range NAT is a migration bridge that enrolls only the explicitly listed pre-migration subnets for its own region via LIST_OF_SUBNETWORKS and never ALL_SUBNETWORKS (which would NAT a zero-egress range, since a firewall deny does not remove NAT enrollment). The effective ADR-017 egress mode carried by shared.range_cells is the single policy vocabulary: mode `none` creates no range or shared NAT enrollment. Sanctioned public-web egress targets the public-internet complement of the denied-network inventory, and an operator egress allow-CIDR is rejected when it overlaps that inventory, so neither lane can name a management, peer-range, private-service, metadata, or special-use destination by rule precedence or accident. DNS transport is tested separately and may not be inferred from name-resolution failure.",
"description": "Range egress policy and subnet enrollment are range-scoped. A non-zero-egress range in a dedicated VPC gets its own regional Cloud NAT; in a shared VPC, its explicitly listed subnets may be enrolled on serialized, provisioner-owned regional shared NAT. A zero-egress (`none`) range gets no NAT membership. Terraform's separate shared NAT is only a migration bridge for explicitly listed pre-migration subnets; the provisioner may replay an existing bridge-attached range without double enrollment but must refuse subnet deletion until the bridge is drained by its Terraform owner. Neither shared NAT may use ALL_SUBNETWORKS (which would NAT a zero-egress range, since a firewall deny does not remove NAT enrollment). The effective ADR-017 egress mode carried by shared.range_cells is the single policy vocabulary. Sanctioned public-web egress targets the public-internet complement of the denied-network inventory, and an operator egress allow-CIDR is rejected when it overlaps that inventory, so neither lane can name a management, peer-range, private-service, metadata, or special-use destination by rule precedence or accident. DNS transport is tested separately and may not be inferred from name-resolution failure.",
"checks": []
},
{
Expand Down
Loading
Loading