MrMasterbay
b4a72a7395
security: re-scan tail — CSRF/http-splitting/CSP, 2 SSRF, SIEM secret masking, power/drift/schedules IDOR
...
Final batch of the CodeAnt re-scan (all adversarially verified):
- app.py CSRF: the check ran only for JSON/form bodies (if sensitive), so a cross-site
enctype=text/plain form POST (a browser 'simple request') skipped it — now enforced for every
state-changing non-exempt /api/*.
- app.py http-response-splitting (x2 redirect handlers): the untrusted request Host was reflected
into the Location header; now stripped/charset-rejected before use (a configured domain always wins).
- app.py CSP: dropped 'unsafe-eval' from script-src (Babel is pre-compiled, never runs in-browser).
- SSRF: plugins/notifications _send_apprise (prefix blocklist missed decimal/IPv6/metadata) and
nodes._safe_repo_url (root-run bash curl) now go through the url_security guard.
- siem._row_to_target masks secret settings keys (token/password/api_key/secret/authorization)
so a siem.view holder can't read the raw credential back out.
- IDOR: power rate routes (get/upsert/delete, __default__ skipped), drift.acknowledge_event
(gate on the event's cluster), schedules.get_schedules (was fail-open on empty clusters field ->
now get_user_clusters).
277 passing. Residual (LOW, follow-up): vmware/xhm migration-list per-task cluster filter.
2026-07-13 22:10:56 +02:00
MrMasterbay
edbd6e9fd0
release: v0.9.10 — SQLCipher full-DB encryption, LXC terminal, syslog scoping + dep hardening
...
Security
- Full-DB SQLCipher encryption (AES-256-CBC + HMAC-SHA512, format v4) on Linux x86_64.
Auto-migrates plain DBs on first boot post-update (copy → sqlcipher_export →
per-table row-count verify → atomic rename; timestamped .plain.bak retained).
Graceful fallback to plain SQLite + Fernet field-encryption where the
sqlcipher3-binary wheel isn't available (ARM/macOS/Windows).
- Multi-tier master-key loader: PEGAPROX_DB_KEY env → systemd LoadCredentialEncrypted
→ PEGAPROX_KEY_FILE → /etc/pegaprox/secret.key → ~/.config/pegaprox/secret.key →
legacy CONFIG_DIR. Loose-perm files are skipped, never silently used. deploy.sh
Step 5 generates the key outside config/ for fresh installs.
- Dependency floor bumps to clear pip-audit / Snyk findings: flask 3.0.3
(werkzeug 3 RCE fix transit), flask-cors 6.0.0 (CWE-178 + 2 mediums),
gevent 25.4.1 (CVSS 9.3 + 8.3 + 6.9), urllib3 2.5.0, paramiko 4.0.0,
cryptography 46.0.7, h11 0.16.0, pyasn1 0.6.3, setuptools 78.1.1, zipp 3.19.1.
- 42-site reflected-content sanitizer (parse_pve_error html.escape) on Proxmox
passthrough error paths across datacenter/vms/storage/static_files.
Features
- LXC dedicated text terminal — pct enter via PVE built-in termproxy API,
wrapped through the existing SSH-WS transport. Server-side ticket mint, no
shell exec on PegaProx side. vm.console permission gated, audit-logged.
- Cluster-scoped syslog viewer (#387 , PR #399 , contributed by @gyptazy, sponsored
by credativ GmbH). Settings → Syslog Server tab with toggle; filters log rows
by cluster's hostnames/nodes. i18n DE/EN/FR/ES/PT/KO.
- Corporate-layout enhancements across dashboard / VM modals / config tabs
(~1.4k lines of new UI sources).
Operations
- Docker HEALTHCHECK start_period 15s→120s, retries 3→5 to give the
in-process DB migration room on upgrade boot. Subsequent boots short-circuit.
- README: Aikido security audit badge.
- docs/SECURITY.md: new operator guide covering keystore tiers, migration tool,
recovery story, and systemd LoadCredentialEncrypted (TPM2-bound) setup.
2026-05-13 19:18:13 +02:00
mkellermann97
2617b8372b
release: v0.9.9 — FinOps, Sustainability, DR Drills, PWA + comprehensive Security Audit
...
Big release. New top-level features:
- Cost Dashboard / Chargeback — per-VM/tenant rollup, price book, recommendations, PDF + CSV export
- Power & Carbon Tracking — Redfish/IPMI/RAPL aggregation, kWh + CO₂e dashboard, PDF + CSV
- Network Topology Visualization — interactive nodes/bridges/bonds/VLANs/VMs map
- Snapshot Schedules — per-VM or per-tag cron with retention (count + age), 60s tick scheduler
- Config Drift Detection — 6h fingerprint scanner with sorted-CSV normalisation (no false positives on tags/content/nodes)
- SIEM Forwarder — Syslog (UDP/TCP, RFC 5424), Splunk HEC, Elasticsearch, Loki, generic webhook; per-target TLS verify, retry queue
- Cloud-Init Template Library — curated upstream cloud images + custom URL/upload, hardened deploy path
- PWA + Web Push — installable app, offline shell cache, VAPID push (no third-party gateway)
- Insights tab — capacity ETA, fragmentation, idle/oversized VMs, power outliers + PDF export
- Audit Search v2 — faceted full-text + CSV export, fail-closed HMAC chain incl. cluster + severity
- DR Drill Wizard — read-only 11-check structured dry-run for Site Recovery plans, JSON + PDF report
10 new blueprints registered; 4 background workers (drift scanner, SIEM forwarder, snapshot scheduler, push handler) — all idempotent + restart-safe.
Comprehensive security audit (3 rounds):
- C-1: command injection in template library — shlex.quote() + URL/regex whitelist
- H-1: CSRF skip on JSON POSTs — Origin/Referer enforced on every state-changing /api/*
- H-2: 21 transitive CVEs — cryptography 47, requests 2.33.1, pyOpenSSL 26.1, PyJWT 2.12.1, pyasn1 0.6.3, pillow 12.2.0; pip-audit clean
- M-1: VAPID private key encrypted at rest (AES-GCM, transparent migration)
- M-2: audit HMAC includes cluster + severity, fail-closed (legacy 5-field fallback for pre-0.9.9 entries)
- M-3: 17 str(e) leaks replaced with logging.exception() + generic message
- M-4: SIEM TLS verify per-target, default true (removed hardcoded verify=False)
- M-5: opaque session revocation token, constant-time compare
- M-10: V2P password scrubbed on phase=completed/failed
- M-11: webhook URL credential redactor before logging
- M-12: push endpoint host whitelist (RFC1918/loopback/metadata refused)
- B-1: api/push.py used flask.session instead of request.session (every push endpoint 401'd) — replaced with _current_user() helper
Air-gap mode hardening:
- /-route now injects localStorage flag prelude server-side when air_gap_mode=true so the very first page load on a fresh browser doesn't hit cdn.jsdelivr while waiting for /auth/check
- html2canvas onerror handlers (4 spots) refuse CDN fallback when air-gap is on
- html2canvas shipped locally (static/js/html2canvas.min.js)
Bumps:
- pegaprox/constants.py + web/src/constants.js → Beta 0.9.9, build 2026.05.03
- version.json → 0.9.9, update_files now 200 entries
- README.md extended with new feature sections; "What's New" block dropped in favour of GitHub releases as source of truth
- i18n: every new feature shipped in DE/EN/FR/ES/PT/KO/IT
2026-05-03 23:39:39 +02:00
MrMasterbay
12ab14655d
feat: ESXi migration wizard, security hardening, cross-cluster replication fix, portal ISO mount
...
ESXi Migration (#222 ):
- 3-step wizard (Target → Hardware → Advanced) with 28 configurable options
- Auto-detect from ESXi: firmware, guestId, CPU topology, Secure Boot, TPM, SCSI controller
- VGA vmware default, disk attachment fix (per-disk, unused rescue), BIOS/OVMF enforcement
- OS type mapping expanded to 40+ guestId entries
- Consistent disk format (raw first, qcow2 fallback)
Cross-Cluster Replication (#192 ):
- Storage type detection before clone: ZFS/LVM/iSCSI skip snapshot clone
- Verified against PVE storage plugins (RBD correctly excluded from blocklist)
Security Audit (12 fixes):
- Portal session: localStorage → sessionStorage (XSS protection)
- TOTP: valid_window=1 (was default ~2, reduced brute-force window)
- Rate limiting on verify-password endpoint (5 attempts/5min)
- XSS: DOMPurify fallback renders escaped plaintext, not regex-filtered HTML
- Session IP change logging (hijack indicator)
- Apprise SSRF blocklist (file://, localhost, private IPs)
- ISO mount path traversal prevention + iso/ prefix enforcement
- Absolute session timeout: 12h regular, 7d remember (was 24h for all)
- VNC ticket removed from DOM, read from JS state only
- Status page auth key masked in API response
- Plugin load audit logging (trusted/untrusted)
- Ntfy token decrypt support (AES-256-GCM)
Client Portal:
- ISO mount/unmount for customers (configurable allowed ISOs)
- Force Stop button with destructive action warning
Syslog:
- Redesigned UI: severity quick-stats, color-coded badges, facility names, compact filters
- PDF export via generatePegaProxPDF()
2026-04-11 11:09:46 +02:00
mkellermann97
780354aa79
feat: ISO Sync, Push Notifications plugin, DNS caching, bug fixes
...
- ISO/Template Sync: distribute ISOs across cluster nodes via SCP/SFTP
for iSCSI-only setups without shared file storage. Matrix view shows
which files exist on which nodes, sync with progress feedback (#279 )
- Push Notifications plugin (ntfy + apprise) for alerts (#213 )
Supports ntfy.sh, self-hosted ntfy, and 80+ services via apprise
- DNS resolution caching: resolve hostname to IP on connect, eliminates
1M+ DNS queries/day from polling loops (#279 )
- Fix: XCP-ng migration with Ceph RBD storage — use qemu-img for
rbd: URIs instead of dd (#272 )
- Fix: backup directory path now absolute in update.sh (#253 )
- Fix: compliance HTTPS check respects reverse proxy mode (#281 )
- Fix: corporate layout toast notifications rendered via portal to
document.body to avoid z-index/overflow issues with taskbar
- Collapsible Score Weights and CPU Baseline sections in cluster settings
2026-04-10 18:19:19 +02:00