Skip to content

Expire DNS-learned permissions and make shared-IP decisions deterministic #240

Description

@JimBugwadia

User outcome

An address stops inheriting permission after its DNS association expires; lookup order does not unpredictably change access.

Current behavior

The ingress snooper learns A records into a per-pod LRU map. Associations do not expire by TTL and the last name learned for a shared address wins. See runtimepolicy.md, Limits of domain names.

Scope

  • Design bounded name/address associations with TTL expiry and deterministic allow/deny conflict rules.
  • Define policy deletion, re-resolution, CNAME, zero TTL, eviction, and restart semantics.
  • Keep enforcement and reported attribution consistent; explicitly retain DNS visibility limits.

Acceptance

  • Injected-time tests show an expired allowed address is blocked under default deny and renewed records refresh permission.
  • Reversing DNS answer order for two names sharing an IP produces the same documented verdict.
  • Capacity losses are counted and policy programming failures are visible.
  • Kind checks cover rotation and a shared-IP conflict; no claim of encrypted-host identity enforcement.

Dependencies and boundaries

Needed before shipping wildcard-domain enforcement as reliable dynamic allowlisting. Exact-address proxy routing does not depend on this.

Validation and completion

  • Table-driven tests pin the stated invariant, including invalid input and policy updates.
  • For code changes: make build and make test; significant changes also require make kind-install and a targeted behavioral check. Pipeline, collector, evaluator, or reporter changes require make smoke-quickstart.
  • Kernel changes use the pinned BPF builder, generated-artifact verification, verifier loading, and allowed/denied behavior tests on supported hook paths.
  • Update DESIGN, development guidance where affected, and the RuntimePolicy reference and limits. Every rejected user rule must reach an operator log and policy condition; count every observation drop. Preserve the reporter redaction boundary.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingpriority/P1High: correctness, security or truth gap

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions