Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 5 additions & 2 deletions docs/how-it-works/policies/network-rules.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -353,8 +353,11 @@ OpenShell blocks connections to private network addresses by default to prevent
server-side request forgery (SSRF). An endpoint with an exact hostname can still
reach the private addresses that its hostname resolves to, unless the endpoint
comes from an approved [policy advisor](/how-it-works/policies/advisor)
proposal. Loopback, link-local, and unspecified addresses, including the cloud
metadata address `169.254.169.254`, are always blocked.
proposal. Network policy never authorizes an outbound endpoint whose destination
is loopback, link-local, or unspecified, including the cloud metadata address
`169.254.169.254`. This restriction does not apply to sandbox-local loopback
connections: a workload can reach a service listening on `127.0.0.1` in the
same sandbox.

Use `allowed_ips` to limit the addresses an endpoint can reach, or to let a
wildcard host such as `*.internal.example` reach private addresses. This rule
Expand Down
17 changes: 10 additions & 7 deletions docs/how-it-works/policies/schema.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -137,13 +137,16 @@ reach the private addresses they resolve to, unless the endpoint comes from an
approved policy advisor proposal. Wildcard and hostless endpoints can reach
private addresses only through `allowed_ips`.

Loopback, link-local, and unspecified addresses, including the cloud metadata
address `169.254.169.254`, are always blocked. `openshell policy update` rejects
an `allowed_ips` entry that overlaps them, and in a complete policy such an
entry blocks every connection to the endpoint. OpenShell also blocks the
Kubernetes and etcd control-plane ports 2379, 2380, 6443, 10250, and 10255 on
endpoints that use an exact hostname, an IP address, or `allowed_ips`. A rule
for `host.openshell.internal` can still reach services on the gateway host.
Network policy never authorizes an outbound endpoint whose destination is
loopback, link-local, or unspecified, including the cloud metadata address
`169.254.169.254`. This does not prevent a workload from connecting to a
sandbox-local service listening on loopback. `openshell policy update` rejects
an `allowed_ips` entry that overlaps the blocked ranges, and in a complete
policy such an entry blocks every connection to the endpoint. OpenShell also
blocks the Kubernetes and etcd control-plane ports 2379, 2380, 6443, 10250,
and 10255 on endpoints that use an exact hostname, an IP address, or
`allowed_ips`. A rule for `host.openshell.internal` can still reach services on
the gateway host.

#### Inspection Fields

Expand Down
2 changes: 1 addition & 1 deletion docs/observability/logging.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -194,7 +194,7 @@ Common reason phrases emitted by the sandbox include:
| Reason | Meaning |
|---|---|
| `no matching policy` | OPA evaluated the request and no allow rule matched. |
| `resolves to always-blocked address` | The destination resolved to loopback, link-local, or unspecified. These ranges are always blocked, even when listed in `allowed_ips`. |
| `resolves to always-blocked address` | An outbound policy endpoint resolved to loopback, link-local, or unspecified. Network policy cannot authorize these destinations, even when they appear in `allowed_ips`; sandbox-local loopback connections do not use this policy path. |
| `resolves to <ip> which is not in allowed_ips, connection rejected` | The destination resolved to an IP outside the policy's `allowed_ips` allowlist. |
| `DNS resolution failed for <host>:<port>` | The proxy could not resolve the destination. |
| `port <n> is a blocked control-plane port, connection rejected` | The destination port matches a control-plane port (etcd, Kubernetes API, kubelet) and is always blocked. |
Expand Down
Loading