Introduce DISABLE_INSECURE_FEATURES to disable insecure command executions (#1)

* introduce DISABLE_INSECURE_FEATURES to disable insecure executions

Signed-off-by: Quan TRAN <account@itscaro.me>

* disable remote sources when DISABLE_INSECURE_FEATURES is set to "true"

Signed-off-by: Quan TRAN <account@itscaro.me>

* refactor envvar package

Signed-off-by: Quan TRAN <account@itscaro.me>

* (test) fix test fixtures

Signed-off-by: Quan TRAN <account@itscaro.me>

* use absolute path to avoid unit test failure

Signed-off-by: Quan TRAN <account@itscaro.me>

* Fix conflicts

Co-authored-by: Yusuke Kuoka <ykuoka@gmail.com>
This commit is contained in:
Quan TRAN
2022-06-05 15:15:06 +09:00
committed by GitHub
co-authored by Yusuke Kuoka
parent 789af92c09
commit 577f54af7a
21 changed files with 261 additions and 33 deletions
+32 -1
View File
@@ -8,16 +8,38 @@ import (
"os/exec"
"path/filepath"
"reflect"
"strconv"
"strings"
"text/template"
"github.com/ghodss/yaml"
"github.com/helmfile/helmfile/pkg/envvar"
"github.com/helmfile/helmfile/pkg/helmexec"
"golang.org/x/sync/errgroup"
)
type Values = map[string]interface{}
var DisableInsecureFeaturesErr = DisableInsecureFeaturesError{envvar.DisableInsecureFeatures + " is active, insecure function calls are disabled"}
type DisableInsecureFeaturesError struct {
err string
}
func (e DisableInsecureFeaturesError) Error() string {
return e.err
}
var (
disableInsecureFeatures bool
skipInsecureTemplateFunctions bool
)
func init() {
disableInsecureFeatures, _ = strconv.ParseBool(os.Getenv(envvar.DisableInsecureFeatures))
skipInsecureTemplateFunctions, _ = strconv.ParseBool(os.Getenv(envvar.SkipInsecureTemplateFunctions))
}
func (c *Context) createFuncMap() template.FuncMap {
funcMap := template.FuncMap{
"envExec": c.EnvExec,
@@ -36,7 +58,7 @@ func (c *Context) createFuncMap() template.FuncMap {
"fetchSecretValue": fetchSecretValue,
"expandSecretRefs": fetchSecretValues,
}
if c.preRender {
if c.preRender || skipInsecureTemplateFunctions {
// disable potential side-effect template calls
funcMap["exec"] = func(string, []interface{}, ...string) (string, error) {
return "", nil
@@ -48,6 +70,15 @@ func (c *Context) createFuncMap() template.FuncMap {
return "", nil
}
}
if disableInsecureFeatures {
// disable insecure functions
funcMap["exec"] = func(string, []interface{}, ...string) (string, error) {
return "", DisableInsecureFeaturesErr
}
funcMap["readFile"] = func(string) (string, error) {
return "", DisableInsecureFeaturesErr
}
}
return funcMap
}