Skip to content

Harden node boundaries, restrict RPC APIs, and secure secret handling - #44

Open
mertcano wants to merge 2 commits into
giwa-io:mainfrom
mertcano:mertcano-patch-1
Open

Harden node boundaries, restrict RPC APIs, and secure secret handling#44
mertcano wants to merge 2 commits into
giwa-io:mainfrom
mertcano:mertcano-patch-1

Conversation

@mertcano

Copy link
Copy Markdown

Why

The node previously exposed operator-facing APIs and metrics on every host interface, allowed wildcard HTTP and WebSocket origins, and enabled broad debug/transaction-pool APIs by default. The entrypoint script enabled shell command tracing (set -x), risking the exposure of environment variables and secrets in logs. Local environment files lacked ignore rules, creating a risk of accidental credential commits.

How

Removed set -x from entrypoint.sh and introduced an explicit readability check for the shared JWT file, ensuring the node fails closed if the file is unreadable. Replaced wildcard origins with loopback defaults (http://localhost,[http://127.0.0.1](http://127.0.0.1)) and restricted default HTTP/WebSocket APIs to web3,eth,net. Bound all operator RPC, Engine API, and metrics ports to 127.0.0.1 in docker-compose.yaml, while intentionally preserving public P2P exposure. Added strict .env* exclusion rules to .gitignore.

Security changes

Prevents unauthorized external access to node operations and metrics by isolating host interfaces to loopback boundaries. Mitigates SSRF and unauthorized cross-origin requests by strictly scoping CORS and WebSocket origins. Eliminates potential JWT secret leakage in Docker execution logs and enforces secure node initialization.

Testing

Verified that git diff --check passes with zero whitespace or syntax errors.

Why

The node previously exposed operator-facing APIs and metrics on every host interface, allowed wildcard HTTP and WebSocket origins, and enabled broad debug/transaction-pool APIs by default.  The entrypoint script enabled shell command tracing (set -x), risking the exposure of environment variables and secrets in logs.  Local environment files lacked ignore rules, creating a risk of accidental credential commits.  

How

Removed set -x from entrypoint.sh and introduced an explicit readability check for the shared JWT file, ensuring the node fails closed if the file is unreadable.  Replaced wildcard origins with loopback defaults (http://localhost,[http://127.0.0.1](http://127.0.0.1)) and restricted default HTTP/WebSocket APIs to web3,eth,net.  Bound all operator RPC, Engine API, and metrics ports to 127.0.0.1 in docker-compose.yaml, while intentionally preserving public P2P exposure.  Added strict .env* exclusion rules to .gitignore.  

Security changes

Prevents unauthorized external access to node operations and metrics by isolating host interfaces to loopback boundaries.  Mitigates SSRF and unauthorized cross-origin requests by strictly scoping CORS and WebSocket origins.  Eliminates potential JWT secret leakage in Docker execution logs and enforces secure node initialization.  

Testing

Verified that git diff --check passes with zero whitespace or syntax errors.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant