보안 개요
Data Relay Link는 Data Relay Link tunnel authentication과 management-plane trust를 분리합니다. 문제 해결이나 보안 검토에서 두 자격 증명을 혼동하지 않는 것이 중요합니다.한눈에 보는 보안 모델
Relay transport token은 Enrollment Code, Bootstrap Ticket, management API credential과 같은 것이 아닙니다.최초 신뢰 수립
Enrollment와 signed client management는 verified HTTPS를 사용하며 production plain-HTTP fallback은 지원하지 않습니다.Data Relay Link tunnel plane
- Direct: Data Relay Link native TLS control
- Enterprise single-443: Data Relay Link control over WSS
- Relay transport token: tunnel authentication
- Published service traffic: proxy 등록 후 Data Relay Link를 통해 전달
Persistent management identity
Enrollment 후 Client는 persistent ECDSA P-256 management identity를 유지하고 private key는 Client에 남습니다. Signed management request는 freshness/replay protection을 위해 timestamp/nonce 등의 검증과 결합됩니다.Zero-Touch credential 특성
Bootstrap Ticket은 다음 특성을 목표로 합니다.- high entropy
- short-lived
- first-machine bound
- successful enrollment 후 single-use
- server에서 hashed-at-rest
- 사용/만료/revoke 전까지 민감 정보
보호해야 할 Secret
보안 경계
Server나 Client의 local root가 완전히 침해된 상황은 제품 보호 경계 밖입니다.Published stable의 접근제어 경계
현재 published stable은 v2.2.1입니다. 이 버전에는 published TCP service에 대해 제품이 직접 적용하는 서비스별 source-IP allowlist 정책이나 application-style RBAC 계층이 stable 기능으로 포함되어 있지 않습니다. v2.2.1에서는 외부 firewall/security group, target host ACL, SSH account/key, database ACL, target application의 authentication/authorization처럼 해당 접근 경계를 실제로 소유하는 제어를 사용해야 합니다.Product
main / release-preparation tree에는 이후 Access Control Pack 작업이 포함되어 있지만, 해당 기능이 들어간 release가 실제 tag/publish되기 전까지는 published stable 기능으로 간주하지 않습니다.