mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-10-09 21:14:22 +00:00
fix(network): name the allowlist in the rejection message
This commit is contained in:
@@ -611,6 +611,32 @@ If specific checks fail due to insufficient permissions:
|
||||
Using Public Cloud credentials can limit Keystone API access, so the command above may not work. Verify permissions in the provider's control panel instead.
|
||||
</Warning>
|
||||
|
||||
### Private Keystone Endpoints
|
||||
|
||||
Most OpenStack deployments keep Keystone on an internal network. By default Prowler rejects an `auth_url` that resolves to a non-public address, as an SSRF defense, and the check runs before the SDK connects — on both the connection test and the scan. To scan a private cloud, declare the trusted ranges:
|
||||
|
||||
```console
|
||||
export PROWLER_ALLOWED_PRIVATE_NETWORKS="10.20.0.0/16,192.168.65.254/32"
|
||||
export OS_AUTH_URL="https://keystone.internal:5000/v3"
|
||||
prowler openstack
|
||||
```
|
||||
|
||||
The value is a comma-separated list of IPs and CIDRs. A resolved address inside an allowlisted range is permitted; every other non-public address stays blocked, so link-local (`169.254.169.254`), loopback and the rest of the internal network remain protected. Malformed entries are rejected, and a non-empty allowlist is logged as a relaxed security control. When unset, only public addresses are reachable.
|
||||
|
||||
The variable is read by the process that runs the scan:
|
||||
|
||||
- **CLI**: export it in the shell running `prowler`.
|
||||
- **Docker Compose**: set it in the root `.env`; it reaches the worker through the shared environment file.
|
||||
- **Helm**: add it under `api.djangoConfig`, which is rendered into the API ConfigMap that the worker inherits through `envFrom`.
|
||||
|
||||
```yaml
|
||||
api:
|
||||
djangoConfig:
|
||||
PROWLER_ALLOWED_PRIVATE_NETWORKS: "10.20.0.0/16"
|
||||
```
|
||||
|
||||
In Prowler App the scan runs in the worker, not the API, so setting the variable only on the API container has no effect. The same variable applies to the Kubernetes and IaC providers. The Image provider has its own, `PROWLER_IMAGE_PROVIDER_ALLOWED_PRIVATE_NETWORKS`.
|
||||
|
||||
## Next Steps
|
||||
|
||||
- [Getting Started with OpenStack](/user-guide/providers/openstack/getting-started-openstack) - Run your first scan
|
||||
|
||||
@@ -126,7 +126,10 @@ def validate_outbound_host(host: str) -> None:
|
||||
for address in addresses:
|
||||
if _ip_is_non_public(address) and not _ip_is_allowlisted(address, networks):
|
||||
raise OutboundURLNotAllowedError(
|
||||
f"Host {host!r} resolves to non-public address {address} and cannot be reached"
|
||||
f"Host {host!r} resolves to non-public address {address} and cannot be "
|
||||
f"reached. To scan a target on a private network, list the trusted "
|
||||
f"ranges in the {ALLOWED_PRIVATE_NETWORKS_ENV} environment variable of "
|
||||
f"the process running the scan"
|
||||
)
|
||||
|
||||
|
||||
|
||||
@@ -55,7 +55,7 @@ class OpenStackBaseException(ProwlerException):
|
||||
"remediation": "Use either 'region_name' or 'regions' in your cloud configuration, not both.",
|
||||
},
|
||||
(17012, "OpenStackAuthUrlNotAllowedError"): {
|
||||
"message": "OpenStack auth_url points at a destination the connection test cannot reach",
|
||||
"message": "OpenStack auth_url points at a destination Prowler must not reach",
|
||||
"remediation": "Use an http or https auth_url that resolves to a public address, or allow the private network through PROWLER_ALLOWED_PRIVATE_NETWORKS.",
|
||||
},
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user