Add custom image handling and access policy management

- Implement tests for custom KVM and LXC image creation, ensuring invalid sources and architecture mismatches are rejected.
- Introduce access policy management in CLI, allowing configuration of allowed sources and trusted proxies.
- Add NAT network configuration with validation for RFC1918 compliance and subnet parsing.
- Create panel access policy management, including normalization and evaluation of access decisions based on client IPs and forwarded headers.
- Develop middleware for enforcing access policies in the server, returning appropriate responses for allowed and denied requests.
- Enhance custom image downloading and validation, ensuring integrity and security of downloaded root filesystem archives.
- Include comprehensive tests for all new functionalities to ensure reliability and correctness.
This commit is contained in:
MengMengCode
2026-07-26 04:04:45 +08:00
parent 8283b88ded
commit 38debab1aa
49 changed files with 4504 additions and 246 deletions
+17
View File
@@ -21,6 +21,23 @@ systemctl restart clicd
journalctl -u clicd -n 100 --no-pager
```
## Panel Access Allowlist CLI
```bash
# Show the current policy
clicd access-policy show
# Allow selected addresses and networks; add reverse proxies when needed
clicd access-policy set \
--allow "203.0.113.10,192.168.1.0/24,2001:db8::/32" \
--trusted-proxy "127.0.0.1"
# Disable source restrictions
clicd access-policy disable
```
The same controls are available from the "Panel access allowlist" item in `clicd cli`. Both paths persist the setting and restart the running panel service automatically.
## Security Recommendations
- Do not expose the web panel directly to untrusted networks.