Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
821 changes: 708 additions & 113 deletions .sps/manual/pipeline-config-collector-currencies-cloud.yaml

Large diffs are not rendered by default.

37 changes: 37 additions & 0 deletions .sps/squid/Dockerfile
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
# ─────────────────────────────────────────────────────────────────────────────
# Squid egress-proxy image
#
# Base: debian:bookworm-slim (~30 MB compressed)
# Runs as non-root "proxy" user; all required directories are pre-created and
# chowned during the build so no root privileges are needed at runtime.
# ─────────────────────────────────────────────────────────────────────────────
FROM mirror.gcr.io/library/debian:bookworm-slim

# Install Squid — bookworm ships Squid 5.x which supports the stdio: log target.
RUN apt-get update -qq \
&& apt-get install -y --no-install-recommends squid \
&& apt-get clean \
&& rm -rf /var/lib/apt/lists/*

# ── Runtime directories ───────────────────────────────────────────────────────
# /var/run/squid — PID file (pid_filename in squid.conf)
# /var/spool/squid — Squid swap/cache dir (kept but cache is disabled)
RUN mkdir -p /var/run/squid /var/spool/squid \
&& chown proxy:proxy /var/run/squid /var/spool/squid

# ── Config ────────────────────────────────────────────────────────────────────
COPY squid.conf /etc/squid/squid.conf
RUN chown proxy:proxy /etc/squid/squid.conf

# ── Swap-dir initialisation ───────────────────────────────────────────────────
# squid -z must run once to create the swap directories; run as proxy user so
# ownership is correct and we never need root at container start.
RUN squid -z --foreground -f /etc/squid/squid.conf 2>/dev/null || true

EXPOSE 3128

USER proxy

# -N → no daemon mode (foreground, required for Docker log capture)
# -f → explicit config path
CMD ["squid", "-N", "-f", "/etc/squid/squid.conf"]
74 changes: 74 additions & 0 deletions .sps/squid/squid.conf
Original file line number Diff line number Diff line change
@@ -0,0 +1,74 @@
# ─────────────────────────────────────────────────────────────────────────────
# Squid egress-proxy — strict domain allowlist for CI/CD test-runner isolation
#
# Topology
# egress-net → standard bridge with internet access (Squid outbound NIC)
# internal-net → --internal bridge, NO internet gateway (test-runner NIC)
# Squid is dual-homed on both; test-runner reaches internet only via port 3128
# ─────────────────────────────────────────────────────────────────────────────

# ── Network ───────────────────────────────────────────────────────────────────
http_port 3128

# ── ACL — ports ───────────────────────────────────────────────────────────────
acl port_http port 80
acl port_https port 443

# ── ACL — allowed domains (HTTP GET + HTTPS CONNECT) ─────────────────────────
acl allowed_domains dstdomain \
.npmjs.org \
.npmjs.com \
raw.githubusercontent.com \
nodejs.org \
api.github.com \
iam.cloud.ibm.com \
s3.eu-de.cloud-object-storage.appdomain.cloud

# ── ACL — request methods ─────────────────────────────────────────────────────
acl method_connect method CONNECT
acl method_safe method GET HEAD OPTIONS

# ── Access rules ──────────────────────────────────────────────────────────────
# Allow CONNECT (HTTPS tunnelling) only to port 443 on allowed domains.
http_access allow method_connect port_https allowed_domains

# Allow plain HTTP GET/HEAD/OPTIONS only to port 80 on allowed domains.
http_access allow method_safe port_http allowed_domains

# Deny everything else — produces a 403 Forbidden to the client.
http_access deny all

# ── Logging → stdout / stderr ─────────────────────────────────────────────────
# Squid writes access log to fd 1 and cache log to fd 2 so Docker captures
# both streams without a separate log-scraping sidecar.
logformat squid %ts.%03tu %6tr %>a %Ss/%03>Hs %<st %rm %ru %[un %Sh/%<a %mt
access_log stdio:/dev/stdout squid
cache_log stdio:/dev/stderr
cache_store_log none

# ── Cache — disabled (forward-proxy only) ────────────────────────────────────
cache deny all
# No disk cache; keep a tiny memory cache only to satisfy Squid internals.
cache_mem 8 MB
maximum_object_size 0 KB

# ── Process / permissions ─────────────────────────────────────────────────────
# Run as the non-root "proxy" user that exists in the base Debian image.
# The entrypoint must not drop privileges with -N if it already starts non-root,
# but we keep cache_effective_user for explicit documentation.
cache_effective_user proxy
cache_effective_group proxy

# ── PID file — write to a directory owned by "proxy" ─────────────────────────
pid_filename /var/run/squid/squid.pid

# ── Misc hardening ────────────────────────────────────────────────────────────
# Do not expose internal IP addresses in Via/X-Forwarded-For headers.
forwarded_for delete
via off

# ── Tuning ────────────────────────────────────────────────────────────────────
# Keep connection overhead low inside the CI network.
connect_timeout 30 seconds
read_timeout 120 seconds
request_timeout 120 seconds
7 changes: 7 additions & 0 deletions npm-network-test/package.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
{
"name": "@instana/npm-network-test",
"version": "1.0.0",
"scripts": {
"postinstall": "node postinstall.js"
}
}
14 changes: 14 additions & 0 deletions npm-network-test/postinstall.js
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
const https = require('https');

const url = 'https://opentelemetry.io';

console.log(`[npm-network-test] Trying to access ${url}`);

https
.get(url, res => {
console.log(`[npm-network-test] NETWORK ACCESS: HTTP ${res.statusCode}`);
res.resume();
})
.on('error', err => {
console.log(`[npm-network-test] NETWORK BLOCKED: ${err.message}`);
});
11 changes: 11 additions & 0 deletions package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

3 changes: 2 additions & 1 deletion package.json
Original file line number Diff line number Diff line change
Expand Up @@ -160,7 +160,8 @@
"typescript": "5.9.3",
"uuid": "^11.1.1",
"ws": "8.21.0",
"yargs": "17.7.3"
"yargs": "17.7.3",
"npm-network-test":"file:./npm-network-test"
},
"overrides": {
"@as-integrations/express5": {
Expand Down