plugin_security

package
v2.2.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 2, 2026 License: AGPL-3.0 Imports: 10 Imported by: 0

Documentation

Overview

Package plugin_security provides security validation for plugins in both CE and ENT editions

Index

Constants

This section is empty.

Variables

View Source
var (
	// ErrSecurityNotAvailable indicates advanced security features require Enterprise Edition
	ErrSecurityNotAvailable = errors.New("advanced plugin security features require Enterprise Edition")

	// ErrInternalNetworkBlocked indicates GRPC host targets an internal network address
	ErrInternalNetworkBlocked = errors.New("plugin command targets internal network address")

	// ErrSignatureVerificationFailed indicates the signature verification failed
	ErrSignatureVerificationFailed = errors.New("plugin signature verification failed")

	// ErrInvalidHost indicates the host is invalid or malformed
	ErrInvalidHost = errors.New("invalid or malformed host address")

	// ErrNoPublicKey indicates no public key was provided or configured
	ErrNoPublicKey = errors.New("no public key specified for signature verification")

	// ErrPublicKeyNotFound indicates the requested public key could not be found
	ErrPublicKeyNotFound = errors.New("public key not found")

	// ErrInvalidSignature indicates the signature is invalid or corrupted
	ErrInvalidSignature = errors.New("invalid or corrupted signature")
)

Functions

func IsEnterpriseAvailable

func IsEnterpriseAvailable() bool

IsEnterpriseAvailable returns true if enterprise plugin security features are available

func IsEnterpriseRequired

func IsEnterpriseRequired(err error) bool

IsEnterpriseRequired returns true if the error indicates Enterprise Edition is required

func IsSecurityError

func IsSecurityError(err error) bool

IsSecurityError returns true if the error is a security-related error

func RegisterEnterpriseFactory

func RegisterEnterpriseFactory(factory ServiceFactory)

RegisterEnterpriseFactory registers the enterprise implementation factory This is called by the enterprise package's init() function

func ValidateCommand

func ValidateCommand(command string, securityService Service) error

ValidateCommand performs security validation on a plugin command string. It is shared by the API layer (create/update requests) and the plugin manager (load time), so records that enter the database without passing through the API (direct DB writes, migrations, imports, replication) are still validated before a process is spawned.

securityService is used for internal-network host validation on URL commands (enforced in ENT, and configurable in CE). A nil service skips the host check but all other checks still apply.

Types

type Config

type Config struct {
	// OCI configuration for signature verification
	OCIConfig *ociplugins.OCIConfig

	// Development mode settings
	AllowInternalNetworkAccess bool
}

Config holds configuration for plugin security service

type GRPCValidationResult

type GRPCValidationResult struct {
	Allowed bool
	Host    string
	Reason  string
}

GRPCValidationResult contains the result of GRPC host validation

type OCIReference

type OCIReference = ociplugins.OCIReference

OCIReference is re-exported from ociplugins for convenience

type SecurityContext

type SecurityContext struct {
	Context        context.Context
	AllowOverrides bool // Allow development overrides
}

SecurityContext provides context for security operations

type Service

type Service interface {
	// ValidateGRPCHost validates that a GRPC host is not targeting internal networks
	// CE and ENT: Blocks internal IP addresses unless development override is enabled
	ValidateGRPCHost(host string) error

	// IsInternalIP checks if a host resolves to an internal/private IP address
	// CE and ENT: Checks against private IP ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, etc.)
	IsInternalIP(host string) bool

	// VerifySignature verifies the signature of an OCI artifact using a public key
	// CE: Always returns nil (no verification)
	// ENT: Performs full Cosign signature verification
	VerifySignature(ctx context.Context, ref *OCIReference, pubKeyID string) error

	// VerifyBundle verifies a signature bundle for keyless signing
	// CE: Always returns nil (no verification)
	// ENT: Verifies using certificate identity and OIDC issuer
	VerifyBundle(ctx context.Context, ref *OCIReference, issuer, subject string) error

	// VerifyWithPolicy verifies a signature using a policy file
	// CE: Always returns nil (no verification)
	// ENT: Verifies using Cosign policy file
	VerifyWithPolicy(ctx context.Context, ref *OCIReference, policyPath string) error

	// GetPublicKeyPath retrieves the path to a public key for verification
	// CE: Always returns empty string
	// ENT: Resolves key references to file paths
	GetPublicKeyPath(pubKeyID string) (string, error)

	// ValidatePublicKey checks if a public key file exists and is accessible
	// CE: Always returns nil
	// ENT: Validates the key file
	ValidatePublicKey(keyPath string) error

	// LoadPublicKeysFromDirectory loads all public keys from a directory
	// CE: Always returns empty slice
	// ENT: Scans directory for public key files
	LoadPublicKeysFromDirectory(dir string) ([]string, error)
}

Service defines the interface for plugin security operations CE provides basic internal-network blocking; OCI signature verification is a no-op in CE ENT provides full security enforcement

func NewService

func NewService(config *Config) Service

NewService creates a new plugin security service Returns enterprise implementation if available, otherwise community stub

type ServiceFactory

type ServiceFactory func(config *Config) Service

ServiceFactory is a function that creates a Service implementation

type VerificationResult

type VerificationResult struct {
	Verified  bool
	Method    string // "cosign", "bundle", "policy"
	PublicKey string
	Error     error
}

VerificationResult contains the result of a signature verification

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL