Page MenuHomePhabricator

Move ingress annotations to an allowlist model
Closed, ResolvedPublic

Description

Ingress annotations are inherently specific to the ingress controller software in use (and we're planning to migrate controllers in the near term), and at least with ingress-nginx have a history of enabling various security issues. For those reasons I'd like to make ingress-admission block ingress annotations by default and allowlist specific useful annotations if those are requested.

Event Timeline

fnegri triaged this task as High priority.Wed, Jan 21, 2:35 PM

group_203_bot_f4d95069bb2675e4ce1fff090c1c1620 opened https://gitlab.wikimedia.org/repos/cloud/toolforge/toolforge-deploy/-/merge_requests/1117

ingress-admission: bump to 0.0.77-20260128152724-d2dfd2a6