Affected by GO-2024-3325
and 4 other vulnerabilities
GO-2024-3325: kcp's impersonation allows access to global administrative groups in github.com/kcp-dev/kcp
GO-2025-3538: kcp allows unauthorized creation and deletion of objects in arbitrary workspaces through APIExport Virtual Workspace in github.com/kcp-dev/kcp
GO-2025-3985: kcp is missing update validation allows arbitrary LogicalCluster status patches through initializingworkspaces Virtual Workspace in github.com/kcp-dev/kcp
GO-2026-5088: kcp's cache server is accessible without authentication or authorization checks in github.com/kcp-dev/kcp
GO-2026-6517: kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace in github.com/kcp-dev/kcp
Package syncer and its sub-packages provide the Syncer Virtual Workspace.
It exposes an APIserver URL for each SyncTarget hosting a syncer agent,
with REST endpoints for APIs that have been imported from this SyncTarget and published.
It combines and integrates:
- a controller (APIReconciler) that watches for available APIResourceImports and updates the list of installed APIs
for the corresponding SyncTarget (in the ./controllers package)
- a DynamicVirtualWorkspace instantiation that exposes and serve installed APIs on the right sync-target-dedicated path
through CRD-like handlers (in the ../framework/dynamic package)
- a REST storage implementation, named ForwardingREST, that can dynamically serve resources by delegating to
a KCP workspace-aware client-go dynamic client (in the ../framework/forwardingregistry package)
The builder package is the place where all these components are combined together, especially in the
BuildVirtualWorkspace() function.