mirror of
https://github.com/MengMengCode/CLICD.git
synced 2026-08-05 05:36:07 +08:00
Add custom image handling and access policy management
- Implement tests for custom KVM and LXC image creation, ensuring invalid sources and architecture mismatches are rejected. - Introduce access policy management in CLI, allowing configuration of allowed sources and trusted proxies. - Add NAT network configuration with validation for RFC1918 compliance and subnet parsing. - Create panel access policy management, including normalization and evaluation of access decisions based on client IPs and forwarded headers. - Develop middleware for enforcing access policies in the server, returning appropriate responses for allowed and denied requests. - Enhance custom image downloading and validation, ensuring integrity and security of downloaded root filesystem archives. - Include comprehensive tests for all new functionalities to ensure reliability and correctness.
This commit is contained in:
@@ -21,6 +21,23 @@ systemctl restart clicd
|
||||
journalctl -u clicd -n 100 --no-pager
|
||||
```
|
||||
|
||||
## Panel Access Allowlist CLI
|
||||
|
||||
```bash
|
||||
# Show the current policy
|
||||
clicd access-policy show
|
||||
|
||||
# Allow selected addresses and networks; add reverse proxies when needed
|
||||
clicd access-policy set \
|
||||
--allow "203.0.113.10,192.168.1.0/24,2001:db8::/32" \
|
||||
--trusted-proxy "127.0.0.1"
|
||||
|
||||
# Disable source restrictions
|
||||
clicd access-policy disable
|
||||
```
|
||||
|
||||
The same controls are available from the "Panel access allowlist" item in `clicd cli`. Both paths persist the setting and restart the running panel service automatically.
|
||||
|
||||
## Security Recommendations
|
||||
|
||||
- Do not expose the web panel directly to untrusted networks.
|
||||
|
||||
Reference in New Issue
Block a user