Harden node boundaries, restrict RPC APIs, and secure secret handling - #44
Open
mertcano wants to merge 2 commits into
Open
Harden node boundaries, restrict RPC APIs, and secure secret handling#44mertcano wants to merge 2 commits into
mertcano wants to merge 2 commits into
Conversation
Why The node previously exposed operator-facing APIs and metrics on every host interface, allowed wildcard HTTP and WebSocket origins, and enabled broad debug/transaction-pool APIs by default. The entrypoint script enabled shell command tracing (set -x), risking the exposure of environment variables and secrets in logs. Local environment files lacked ignore rules, creating a risk of accidental credential commits. How Removed set -x from entrypoint.sh and introduced an explicit readability check for the shared JWT file, ensuring the node fails closed if the file is unreadable. Replaced wildcard origins with loopback defaults (http://localhost,[http://127.0.0.1](http://127.0.0.1)) and restricted default HTTP/WebSocket APIs to web3,eth,net. Bound all operator RPC, Engine API, and metrics ports to 127.0.0.1 in docker-compose.yaml, while intentionally preserving public P2P exposure. Added strict .env* exclusion rules to .gitignore. Security changes Prevents unauthorized external access to node operations and metrics by isolating host interfaces to loopback boundaries. Mitigates SSRF and unauthorized cross-origin requests by strictly scoping CORS and WebSocket origins. Eliminates potential JWT secret leakage in Docker execution logs and enforces secure node initialization. Testing Verified that git diff --check passes with zero whitespace or syntax errors.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The node previously exposed operator-facing APIs and metrics on every host interface, allowed wildcard HTTP and WebSocket origins, and enabled broad debug/transaction-pool APIs by default. The entrypoint script enabled shell command tracing (set -x), risking the exposure of environment variables and secrets in logs. Local environment files lacked ignore rules, creating a risk of accidental credential commits.
How
Removed set -x from entrypoint.sh and introduced an explicit readability check for the shared JWT file, ensuring the node fails closed if the file is unreadable. Replaced wildcard origins with loopback defaults (http://localhost,[http://127.0.0.1](http://127.0.0.1)) and restricted default HTTP/WebSocket APIs to web3,eth,net. Bound all operator RPC, Engine API, and metrics ports to 127.0.0.1 in docker-compose.yaml, while intentionally preserving public P2P exposure. Added strict .env* exclusion rules to .gitignore.
Security changes
Prevents unauthorized external access to node operations and metrics by isolating host interfaces to loopback boundaries. Mitigates SSRF and unauthorized cross-origin requests by strictly scoping CORS and WebSocket origins. Eliminates potential JWT secret leakage in Docker execution logs and enforces secure node initialization.
Testing
Verified that git diff --check passes with zero whitespace or syntax errors.