mirror of
https://github.com/Security-Onion-Solutions/securityonion.git
synced 2026-09-20 06:40:44 +02:00
The Kratos admin API is unauthenticated by design and relies on network isolation, but so-kratos published 0.0.0.0:4434:4434 and daemon.json leaves userland-proxy at its default of true. Docker therefore ran a proxy listener on the host, and any container reached the admin API through the manager IP or the bridge gateway regardless of its docker network. so-kratos now sits alone on a new soauth network and no longer publishes 4434. 4433 is still published, so nginx is unchanged. so-soc is dual homed and reaches the admin API over soauth, with publicHostUrl set explicitly. so-user reaches it through docker exec, and wait_for_kratos polls the container address instead of the host port. firewall/iptables.jinja hardcoded sobridge in every generated DNAT, ACCEPT, masquerade and isolation rule, so it is now driven by a docker:networks map and a per-container networks list. Containers that do not declare one default to sobridge, and .ip still resolves to the primary network's address. soauth is only created on the roles that run so-kratos. Setup already allows a custom docker range, so it now also prompts for the auth network range and writes it to the docker pillar. Grids on the default range need no decision during soup, since they get the same 172.17.2.0/24 a fresh install would. Grids that set a custom range are prompted, defaulting to the adjacent /24, and unattended upgrades take that default with a notice rather than blocking. so-kratos and so-soc are removed in up_to_3.4.0 so the highstate recreates them with the correct network membership.
126 lines
4.9 KiB
YAML
126 lines
4.9 KiB
YAML
docker:
|
|
gateway:
|
|
description: Gateway for the default docker interface.
|
|
helpLink: docker
|
|
advanced: True
|
|
range:
|
|
description: Default docker IP range for containers.
|
|
helpLink: docker
|
|
advanced: True
|
|
networks:
|
|
description: |
|
|
Docker networks used by the grid. sobridge carries most containers and takes its range and
|
|
gateway from the docker.range and docker.gateway settings above. soauth is an isolated
|
|
network for the authentication services, so that the Kratos admin API is only reachable
|
|
from the containers placed on it. Changing these requires a corresponding firewall rebuild.
|
|
helpLink: docker
|
|
readonly: True
|
|
advanced: True
|
|
global: True
|
|
ulimits:
|
|
description: |
|
|
Default ulimit settings applied to all containers via the Docker daemon. Each entry specifies a resource name (e.g. nofile, memlock, core, nproc) with soft and hard limits. Individual container ulimits override these defaults. Valid resource names include: cpu, fsize, data, stack, core, rss, nproc, nofile, memlock, as, locks, sigpending, msgqueue, nice, rtprio, rttime.
|
|
forcedType: "[]{}"
|
|
syntax: json
|
|
advanced: True
|
|
helpLink: docker.html
|
|
uiElements:
|
|
- field: name
|
|
label: Resource Name
|
|
required: True
|
|
regex: ^(cpu|fsize|data|stack|core|rss|nproc|nofile|memlock|as|locks|sigpending|msgqueue|nice|rtprio|rttime)$
|
|
regexFailureMessage: You must enter a valid ulimit name (cpu, fsize, data, stack, core, rss, nproc, nofile, memlock, as, locks, sigpending, msgqueue, nice, rtprio, rttime).
|
|
- field: soft
|
|
label: Soft Limit
|
|
forcedType: int
|
|
- field: hard
|
|
label: Hard Limit
|
|
forcedType: int
|
|
containers:
|
|
so-dockerregistry: &dockerOptions
|
|
final_octet:
|
|
description: Last octet of the container IP address.
|
|
helpLink: docker
|
|
readonly: True
|
|
advanced: True
|
|
global: True
|
|
networks:
|
|
description: |
|
|
Docker networks this container is attached to. The first entry is the container's
|
|
primary network and determines the address its published ports are forwarded to.
|
|
Defaults to sobridge when unset.
|
|
helpLink: docker
|
|
readonly: True
|
|
advanced: True
|
|
global: True
|
|
forcedType: "[]string"
|
|
port_bindings:
|
|
description: List of port bindings for the container.
|
|
helpLink: docker
|
|
advanced: True
|
|
multiline: True
|
|
forcedType: "[]string"
|
|
custom_bind_mounts:
|
|
description: List of custom local volume bindings.
|
|
advanced: True
|
|
helpLink: docker
|
|
multiline: True
|
|
forcedType: "[]string"
|
|
extra_hosts:
|
|
description: List of additional host entries for the container.
|
|
advanced: True
|
|
helpLink: docker
|
|
multiline: True
|
|
forcedType: "[]string"
|
|
extra_env:
|
|
description: List of additional ENV entries for the container.
|
|
advanced: True
|
|
helpLink: docker
|
|
multiline: True
|
|
forcedType: "[]string"
|
|
ulimits:
|
|
description: |
|
|
Ulimit settings for the container. Each entry specifies a resource name (e.g. nofile, memlock, core, nproc) with optional soft and hard limits. Valid resource names include: cpu, fsize, data, stack, core, rss, nproc, nofile, memlock, as, locks, sigpending, msgqueue, nice, rtprio, rttime.
|
|
advanced: True
|
|
helpLink: docker.html
|
|
forcedType: "[]{}"
|
|
syntax: json
|
|
uiElements:
|
|
- field: name
|
|
label: Resource Name
|
|
required: True
|
|
regex: ^(cpu|fsize|data|stack|core|rss|nproc|nofile|memlock|as|locks|sigpending|msgqueue|nice|rtprio|rttime)$
|
|
regexFailureMessage: You must enter a valid ulimit name (cpu, fsize, data, stack, core, rss, nproc, nofile, memlock, as, locks, sigpending, msgqueue, nice, rtprio, rttime).
|
|
- field: soft
|
|
label: Soft Limit
|
|
forcedType: int
|
|
- field: hard
|
|
label: Hard Limit
|
|
forcedType: int
|
|
so-elastic-fleet: *dockerOptions
|
|
so-elasticsearch: *dockerOptions
|
|
so-influxdb: *dockerOptions
|
|
so-kibana: *dockerOptions
|
|
so-kratos: *dockerOptions
|
|
so-hydra: *dockerOptions
|
|
so-logstash: *dockerOptions
|
|
so-nginx: *dockerOptions
|
|
so-nginx-fleet-node: *dockerOptions
|
|
so-redis: *dockerOptions
|
|
so-sensoroni: *dockerOptions
|
|
so-soc: *dockerOptions
|
|
so-strelka-backend: *dockerOptions
|
|
so-strelka-filestream: *dockerOptions
|
|
so-strelka-frontend: *dockerOptions
|
|
so-strelka-manager: *dockerOptions
|
|
so-strelka-gatekeeper: *dockerOptions
|
|
so-strelka-coordinator: *dockerOptions
|
|
so-elastalert: *dockerOptions
|
|
so-elastic-fleet-package-registry: *dockerOptions
|
|
so-idh: *dockerOptions
|
|
so-elastic-agent: *dockerOptions
|
|
so-telegraf: *dockerOptions
|
|
so-suricata: *dockerOptions
|
|
so-zeek: *dockerOptions
|
|
so-kafka: *dockerOptions
|