)]}'
{"/COMMIT_MSG":[{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"0f5c2af53d25154c48d789a52d4aa6dd789f2585","unresolved":false,"context_lines":[{"line_number":6,"context_line":""},{"line_number":7,"context_line":"[OSSN-0106] Ironic API ramdisk endpoints require network-level access controls"},{"line_number":8,"context_line":""},{"line_number":9,"context_line":"Advisory for operators regarding the three unauthenticated ramdisk"},{"line_number":10,"context_line":"endpoints in the Ironic API (lookup, heartbeat, continue_inspection)"},{"line_number":11,"context_line":"and the recommended deployment architecture to restrict access from"},{"line_number":12,"context_line":"untrusted networks."}],"source_content_type":"text/x-gerrit-commit-message","patch_set":2,"id":"1a423104_2f43c532","line":9,"updated":"2026-08-11 15:19:57.000000000","message":"Nit: I would avoid the use of the term \"advisory\" when discussing a security note, just to minimize confusion with our actual security advisories. It\u0027s not in the text of the publication in this case, at least, so not especially critical more of a reminder for future changes.","commit_id":"3f824274ec69273ae1b3e3da5ac6fc35cdb1278e"}],"/PATCHSET_LEVEL":[{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"4f6e573de0e56404b0e47ffbb1be4986cbf22c93","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":1,"id":"602c86d9_9ff8fd1f","updated":"2026-08-07 16:42:06.000000000","message":"Here\u0027s a very pared down draft; I suspect the \"best answer\" will lie somewhere between our levels of verbosity:\n\n## Summary ##\nIronic API combines authenticated endpoints for client use with unauthenticated endpoints for coordination with remote servers into a single API service. This can expose security risks to an operating cloud depending on their use case and deployment methodology.\n\n## Description ##\nIronic has three endpoints which allow unauthenticated access:\n- ``/v1/lookup``\n- ``/v1/heartbeat``\n- ``/v1/continue_inspection``\n\nAll of these endpoints already have significant security controls to mitigate risk; such as bootstrapping into credentials (``agent_token``) and defaulting to limiting access to the endpoints for Nodes whose state doesn\u0027t require use of them.\n\nIronic provided instructions to completely disable these endpoints for an API service only applied to Keystone-authenticated installations and provided no method for standalone users to secure their environment. As a result, Ironic has added ``[api]/enable_ramdisk_endpoints`` as a config option available to Ironic operators, regardless of authentication methodology.\n\n## Reccomended Actions ##\nOperators using Ironic in a multitenant or untrusted environment are encouraged to configure Ironic API in such a way that these unauthenticated endpoints are only accessible from the Ironic Python Agent ramdisks.\n\nThis can be achieved different ways depending on infrastructure setup; two supported methods include:\n- Running a separate public-facing and ramdisk-facing Ironic API service; on the public-facing Ironic API service, ensure the patch linked in this OSSN in applied and ``[api]/enable_ramdisk_endpoints`` is set to ``false``.\n- Using a fronting HTTP proxy, WSGI runner, or other external method to restrict the relevant endpoints to access only from networks which might run Ironic Python Agent. This method of securing requires no Ironic code changes.","commit_id":"e23f7af1ad7f542cee3388cb171ebf7fde283d14"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"7c34b40a1e300563c581837eed1d0711c1e7da39","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"b2d103f8_5ab62e8c","updated":"2026-08-07 16:04:03.000000000","message":"Marking WIP until I can get some ironic maintainers to look at this.","commit_id":"e23f7af1ad7f542cee3388cb171ebf7fde283d14"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"eb05620343932d270763c8db3188d2c1396fde6d","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":1,"id":"b8339f35_5ca9abce","in_reply_to":"602c86d9_9ff8fd1f","updated":"2026-08-07 17:41:33.000000000","message":"We\u0027re likely a week from having enable_ramdisk_endpoints, and I was trying to avoid that for now, but if there is consensus on that front as a simplified path we could take it.","commit_id":"e23f7af1ad7f542cee3388cb171ebf7fde283d14"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"9d7162bb0a5f48fe3f0651443a94f0c30e731d9f","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":1,"id":"c32a5c01_ff3529f7","in_reply_to":"b8339f35_5ca9abce","updated":"2026-08-07 17:48:27.000000000","message":"IMO there is zero urgency in getting this OSSN out; and it would make sense to me to get the enable_ramdisk_endpoints change ready (and backports in place, if not merged) before pushing this.","commit_id":"e23f7af1ad7f542cee3388cb171ebf7fde283d14"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"504548265116fb9aec9da18b84e11aae8137017c","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":2,"id":"35b1812b_e41d43c6","updated":"2026-08-10 15:20:31.000000000","message":"Ideally we land the Ironic change, or get a bucket of +2s on it, before we land this.","commit_id":"3f824274ec69273ae1b3e3da5ac6fc35cdb1278e"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"dc2e68d36aea7296966762c7b770a39c7486642a","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":2,"id":"0949e48a_fef3f9be","in_reply_to":"35b1812b_e41d43c6","updated":"2026-08-10 18:13:08.000000000","message":"Ironic change just landed, FWIW. So we can always revise it or the next official release will be 38.0.0 most likely.","commit_id":"3f824274ec69273ae1b3e3da5ac6fc35cdb1278e"}],"security-notes/OSSN-0106":[{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"4f6e573de0e56404b0e47ffbb1be4986cbf22c93","unresolved":true,"context_lines":[{"line_number":3,"context_line":""},{"line_number":4,"context_line":"### Summary ###"},{"line_number":5,"context_line":"The Ironic Bare Metal API contains three endpoints designed for use by"},{"line_number":6,"context_line":"the ironic-python-agent (IPA) deploy ramdisk that intentionally bypass"},{"line_number":7,"context_line":"Keystone authentication. These endpoints are a known aspect of the"},{"line_number":8,"context_line":"service architecture and are already documented in the Ironic security"},{"line_number":9,"context_line":"guide, however operators must take deliberate steps to restrict access"}],"source_content_type":"application/octet-stream","patch_set":1,"id":"0003ca02_96ee448a","line":6,"updated":"2026-08-07 16:42:06.000000000","message":"I typically go \"Ironic-Python-Agent\" or \"Ironic Python Agent\" in advisories.","commit_id":"e23f7af1ad7f542cee3388cb171ebf7fde283d14"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"4f6e573de0e56404b0e47ffbb1be4986cbf22c93","unresolved":true,"context_lines":[{"line_number":7,"context_line":"Keystone authentication. These endpoints are a known aspect of the"},{"line_number":8,"context_line":"service architecture and are already documented in the Ironic security"},{"line_number":9,"context_line":"guide, however operators must take deliberate steps to restrict access"},{"line_number":10,"context_line":"to them from untrusted networks."},{"line_number":11,"context_line":""},{"line_number":12,"context_line":"### Affected Services / Software ###"},{"line_number":13,"context_line":"- ironic: \u003e\u003d6.2.0"}],"source_content_type":"application/octet-stream","patch_set":1,"id":"1a59354f_2fe102a0","line":10,"updated":"2026-08-07 16:42:06.000000000","message":"I\u0027d mention here that there was a gap: we could only disable these endpoints (in ironic) for operators using keystone; not for those using http basic auth or noauth.","commit_id":"e23f7af1ad7f542cee3388cb171ebf7fde283d14"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"4f6e573de0e56404b0e47ffbb1be4986cbf22c93","unresolved":true,"context_lines":[{"line_number":43,"context_line":"ramdisk, by nature, boots on bare metal hardware that has no pre-staged"},{"line_number":44,"context_line":"credentials. The corresponding policy rules use an empty check string"},{"line_number":45,"context_line":"(``check_str\u003d\u0027\u0027``), meaning the policy check always permits access"},{"line_number":46,"context_line":"regardless of credentials."},{"line_number":47,"context_line":""},{"line_number":48,"context_line":"Several mitigations already exist within the Ironic codebase:"},{"line_number":49,"context_line":""}],"source_content_type":"application/octet-stream","patch_set":1,"id":"2b99dc3c_4ad3feb3","line":46,"updated":"2026-08-07 16:42:06.000000000","message":"I would edit this down signficantly -- both the description and the summary. We don\u0027t need to explain the entire set of API endpoints or why they exist; only that they are secured as much as the model allows while still providing unauthenticated access. We do not need to detail the security model here -- if we think it\u0027s important information, we should put it in Ironic and link it from here.\n\nThis document should consist primarily of operator-actions to mitigate.","commit_id":"e23f7af1ad7f542cee3388cb171ebf7fde283d14"}]}
