flyingcircusio / nixpkgs

The Flying Circus platform, based on NixOS
https://flyingcircus.io
MIT License
3 stars 6 forks source link

Fix 127887: disable accepting route advertisements on configured inte… #1072

Closed ctheune closed 4 years ago

ctheune commented 4 years ago

@flyingcircusio/release-managers

Release process

Impact:

None

Changelog:

Security implications

Customer traffic should not appear on non-target VMs. As this only affecte the frontend network, additional security policies already required that this should be encrypted and from our analysis we have only seen encrypted traffic flooded anyway.

Validated the new settings with our previous platform (which already used the setting but got lost at some point in the migration). Also checked on customer affected machine that this setting solves the problem and manually verified that the changed automation code is applied properly.