Skip to content

Block admin public endpoints - #98

Merged
saranggalada merged 4 commits into
mainfrom
sarang/block-public-endpoints
May 7, 2026
Merged

saranggalada merged 4 commits into
mainfrom
sarang/block-public-endpoints

Conversation

@saranggalada

@saranggalada saranggalada commented May 1, 2026 •

Copy link
Copy Markdown
Collaborator

Goal: On the public KMS hostname, only client key flows stay open; admin and platform routes must go through private access (VNet / ledger private FQDN).

What changes:

  • Application Gateway WAF is set to Prevention (via locals.tf) so rules are enforced.
  • force_firewall_policy_association = true so the WAF policy is reliably applied.
  • Custom rules:
    • Allow GET /app/pubkey (BeginsWith), GET allowlist regex for listpubkeys, POST paths for key / unwrapKey (fmt preserved).
    • Block any other /app/... (admin APIs: heartbeat, refresh, proposals, policies, etc.).
    • Block /node/..., /gov/..., /receipt... so CCF ledger surfaces aren’t exposed on the public listener.
  • OWASP CRS: selectively disable 942340 / 942430 / 942440 on this policy so legitimate KMS JSON/key/unwrapKey POSTs aren’t tripped before enforcement.

@saranggalada saranggalada changed the title Sarang/block public endpoints Block admin public endpoints May 1, 2026
@saranggalada
saranggalada merged commit f3df7d9 into main May 7, 2026
10 checks passed

This branch was previously deployed

2 inactive deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants