Find a file
Tim Gross e8bfef8148 search: fix ACL filtering for plugins and variables
ACL permissions for the search endpoints are done in three passes. The
first (the `sufficientSearchPerms` method) is for performance and coarsely
rejects requests based on the passed-in context parameter if the user has no
permissions to any object in that context. The second (the
`filteredSearchContexts` method) filters out contexts based on whether the user
has permissions either to the requested namespace or again by context (to catch
the "all" context). Finally, when iterating over the objects available, we do
the usual filtering in the iterator.

Internal testing found several bugs in this filtering:
* CSI plugins can be searched by any authenticated user.
* Variables can be searched if the user has `job:read` permissions to the
  variable's namespace instead of `variable:list`.
* Variables cannot be searched by wildcard namespace.

This is an information leak of the plugin names and variable paths, which we
don't consider to be privileged information but intended to protect anyways.

This changeset fixes these bugs by ensuring CSI plugins are filtered in the 1st
and 2nd pass ACL filters, and changes variables to check `variable:list` in the
2nd pass filter unless the wildcard namespace is passed (at which point we'll
fallback to filtering in the iterator).

Fixes: CVE-2023-3300
Fixes: #17906
2023-07-18 12:09:55 -04:00
.changelog search: fix ACL filtering for plugins and variables 2023-07-18 12:09:55 -04:00
.github backport of commit 0cb728ed68165888245cf8bc72e4dece5123ef4f (#17918) 2023-07-12 09:52:00 -05:00
.release Prepare for next release 2023-07-11 15:19:58 +00:00
.semgrep [COMPLIANCE] Add Copyright and License Headers 2023-04-10 15:36:59 +00:00
.tours Make number of scheduler workers reloadable (#11593) 2022-01-06 11:56:13 -05:00
acl search: fix ACL filtering for plugins and variables 2023-07-18 12:09:55 -04:00
api build(deps): bump github.com/hashicorp/cronexpr in /api (#17787) 2023-07-10 11:23:00 +01:00
ci [COMPLIANCE] Add Copyright and License Headers 2023-04-10 15:36:59 +00:00
client Prepare for next release 2023-07-11 15:19:58 +00:00
command Generate files for 1.6.0-rc.1 release 2023-07-11 15:19:54 +00:00
contributing Update checklist-rpc-endpoint.md (#17698) 2023-06-27 10:52:38 +02:00
demo compliance: add headers with fixed copywrite tool (#17353) 2023-05-30 09:20:32 -05:00
dev repo: block pushing to release branches in git hook (#17377) 2023-06-01 09:36:20 -05:00
drivers Include parent job ID as a Docker container label (#17843) 2023-07-10 11:27:45 -04:00
e2e e2e: respect timeout value when waiting for allocs in v3. (#17800) 2023-07-10 09:47:10 +01:00
helper Add the ability to customise the details of the CA (#17309) 2023-07-11 08:53:09 +01:00
integrations Update metric names (#16894) 2023-04-18 13:25:42 -07:00
internal/testing/apitests [COMPLIANCE] Add Copyright and License Headers 2023-04-10 15:36:59 +00:00
jobspec Add disable_file parameter to job's vault stanza (#13343) 2023-06-23 15:15:04 -04:00
jobspec2 Add disable_file parameter to job's vault stanza (#13343) 2023-06-23 15:15:04 -04:00
lib dep: update from jwt/v4 to jwt/v5 (#17062) 2023-05-03 11:17:38 -07:00
nomad search: fix ACL filtering for plugins and variables 2023-07-18 12:09:55 -04:00
plugins Include parent job ID as a Docker container label (#17843) 2023-07-10 11:27:45 -04:00
scheduler core: remove unnecessary call to SetNodes and adds DC downgrade test (#17655) 2023-06-22 13:26:14 -04:00
scripts [COMPLIANCE] Add Copyright and License Headers (#17732) 2023-06-26 11:11:17 -05:00
terraform ci: run 'make check' as reusable workflow (#17600) 2023-06-20 08:17:13 +01:00
testutil tests: enable newer windows (#17401) 2023-06-02 11:38:38 -05:00
tools tools: update dependencies and use tree set (#16974) 2023-04-25 07:47:19 -05:00
ui Report shows a 3rd party browser extension puts a banner at the top of page and awkwardly shifts nav; this fixes that (#17783) 2023-06-30 17:09:42 -04:00
version Prepare for next release 2023-07-11 15:19:58 +00:00
website acl: fix parsing of policies with blocks w/o label 2023-07-18 12:09:37 -04:00
.copywrite.hcl build: add agent bindata file to copywrite ignore list. (#17507) 2023-06-14 11:13:59 +01:00
.git-blame-ignore-revs add copywrite headers commit to ignore-revs config file (#17037) 2023-05-01 10:57:43 -04:00
.gitattributes Remove invalid gitattributes 2018-02-14 14:47:43 -08:00
.gitignore git: ignore .fleet directory (#16144) 2023-02-13 07:39:30 -06:00
.go-version build: update to go1.20.5 (#17451) 2023-06-07 11:44:59 -04:00
.golangci.yml [COMPLIANCE] Add Copyright and License Headers 2023-04-10 15:36:59 +00:00
.semgrepignore build: disable semgrep on structs.go for now 2022-02-01 10:09:49 -06:00
build_linux_arm.go [COMPLIANCE] Add Copyright and License Headers 2023-04-10 15:36:59 +00:00
CHANGELOG-unsupported.md docs: split out unsupported versions in changelog (#17704) 2023-06-23 15:17:57 -04:00
CHANGELOG.md Prepare release 1.6.0-rc.1 2023-07-11 11:09:18 -04:00
CODEOWNERS build: update deprecated GitHub Actions (#17218) 2023-05-17 08:57:28 -04:00
Dockerfile build: add Docker image (#17017) 2023-06-23 15:57:09 -04:00
GNUmakefile ci: remove circleci (#17502) 2023-06-12 16:28:19 -05:00
go.mod deps: update cronexpr to capture license file in SBOM tools (#17733) 2023-06-27 07:58:20 -05:00
go.sum deps: update cronexpr to capture license file in SBOM tools (#17733) 2023-06-27 07:58:20 -05:00
LICENSE [COMPLIANCE] Update MPL 2.0 LICENSE (#14884) 2022-10-13 08:43:12 -04:00
main.go [COMPLIANCE] Add Copyright and License Headers 2023-04-10 15:36:59 +00:00
main_test.go [COMPLIANCE] Add Copyright and License Headers 2023-04-10 15:36:59 +00:00
README.md Adds public roadmap project to readme 2023-03-20 15:11:38 -07:00
Vagrantfile dev: make cni, consul, dev, docker, and vault scripts Lima compat. (#16689) 2023-03-28 16:21:14 +01:00

Nomad License: MPL 2.0 Discuss

HashiCorp Nomad logo

Nomad is a simple and flexible workload orchestrator to deploy and manage containers (docker, podman), non-containerized applications (executable, Java), and virtual machines (qemu) across on-prem and clouds at scale.

Nomad is supported on Linux, Windows, and macOS. A commercial version of Nomad, Nomad Enterprise, is also available.

Nomad provides several key features:

  • Deploy Containers and Legacy Applications: Nomads flexibility as an orchestrator enables an organization to run containers, legacy, and batch applications together on the same infrastructure. Nomad brings core orchestration benefits to legacy applications without needing to containerize via pluggable task drivers.

  • Simple & Reliable: Nomad runs as a single binary and is entirely self contained - combining resource management and scheduling into a single system. Nomad does not require any external services for storage or coordination. Nomad automatically handles application, node, and driver failures. Nomad is distributed and resilient, using leader election and state replication to provide high availability in the event of failures.

  • Device Plugins & GPU Support: Nomad offers built-in support for GPU workloads such as machine learning (ML) and artificial intelligence (AI). Nomad uses device plugins to automatically detect and utilize resources from hardware devices such as GPU, FPGAs, and TPUs.

  • Federation for Multi-Region, Multi-Cloud: Nomad was designed to support infrastructure at a global scale. Nomad supports federation out-of-the-box and can deploy applications across multiple regions and clouds.

  • Proven Scalability: Nomad is optimistically concurrent, which increases throughput and reduces latency for workloads. Nomad has been proven to scale to clusters of 10K+ nodes in real-world production environments.

  • HashiCorp Ecosystem: Nomad integrates seamlessly with Terraform, Consul, Vault for provisioning, service discovery, and secrets management.

Quick Start

Testing

See Learn: Getting Started for instructions on setting up a local Nomad cluster for non-production use.

Optionally, find Terraform manifests for bringing up a development Nomad cluster on a public cloud in the terraform directory.

Production

See Learn: Nomad Reference Architecture for recommended practices and a reference architecture for production deployments.

Documentation

Full, comprehensive documentation is available on the Nomad website: https://www.nomadproject.io/docs

Guides are available on HashiCorp Learn.

Roadmap

A timeline of major features expected for the next release or two can be found in the Public Roadmap.

This roadmap is a best guess at any given point, and both release dates and projects in each release are subject to change. Do not take any of these items as commitments, especially ones later than one major release away.

Contributing

See the contributing directory for more developer documentation.