Files
Joffref a41ecb7295 feat(supervisor): NAT64-aware SSRF checks and driver IPv6 egress settings
A DNS64 answer like 64:ff9b::a00:5 is really 10.0.0.5, but the SSRF
checks treated it as a public IPv6 address. Addresses inside a NAT64
prefix are now checked as the IPv4 address they embed, in policy DNS
and in the CONNECT path. The well-known prefix is always known; other
prefixes come from the new nat64_prefixes driver setting, or from
ipv4only.arpa discovery when the supervisor starts.

policy_dns_ipv6_egress and nat64_prefixes can now be set in the Docker,
Podman, Kubernetes and VM driver configs. Before this, only auto was
reachable in practice.

The supervisor logs its IPv6 egress decision (requested mode, result,
default routes, route state) and the NAT64 prefixes it uses as OCSF
config events.

Tests: route detection fixtures per backend, a start_mediated test with
a fake mediation source and DNS64 upstream, driver arg tests, and an
e2e check of the decision event.

Signed-off-by: Joffref <mjoffre@blaxel.ai>
2026-09-27 17:06:43 -07:00
..