misc: updated remaining proxy remnants

This commit is contained in:
Sheen Capadngan
2025-09-09 04:09:36 +08:00
parent 0ed6601a66
commit c297961d04
2 changed files with 33 additions and 33 deletions
@@ -123,7 +123,7 @@ export const injectIdentity = fp(
} }
// Authentication is handled on a route-level // Authentication is handled on a route-level
if (req.url === "/api/v1/proxies/register-instance-relay") { if (req.url === "/api/v1/relays/register-instance-relay") {
return; return;
} }
@@ -15,28 +15,28 @@ This document explains the internal security architecture and how tenant isolati
The gateway system uses multiple certificate authorities depending on deployment configuration: The gateway system uses multiple certificate authorities depending on deployment configuration:
**For Organizations Using Infisical-Managed Proxies:** **For Organizations Using Infisical-Managed Relays:**
- **Instance proxy SSH Client CA & Server CA** - Gateway ↔ Infisical Proxy Server authentication - **Instance relay SSH Client CA & Server CA** - Gateway ↔ Infisical Relay Server authentication
- **Instance proxy PKI Client CA & Server CA** - Platform ↔ Infisical Proxy Server authentication - **Instance relay PKI Client CA & Server CA** - Platform ↔ Infisical Relay Server authentication
- **Organization Gateway Client CA & Server CA** - Platform ↔ Gateway authentication - **Organization Gateway Client CA & Server CA** - Platform ↔ Gateway authentication
**For Organizations Using Customer-Deployed Proxies:** **For Organizations Using Customer-Deployed Relays:**
- **Organization proxy SSH Client CA & Server CA** - Gateway ↔ Customer Proxy Server authentication - **Organization relay SSH Client CA & Server CA** - Gateway ↔ Customer Relay Server authentication
- **Organization proxy PKI Client CA & Server CA** - Platform ↔ Customer Proxy Server authentication - **Organization relay PKI Client CA & Server CA** - Platform ↔ Customer Relay Server authentication
- **Organization Gateway Client CA & Server CA** - Platform ↔ Gateway authentication - **Organization Gateway Client CA & Server CA** - Platform ↔ Gateway authentication
### Certificate Hierarchy ### Certificate Hierarchy
``` ```
Instance Level (Shared Proxies): Instance Level (Shared Relays):
├── Instance Proxy SSH CA (Gateway ↔ Proxy) ├── Instance Relay SSH CA (Gateway ↔ Relay)
├── Instance Proxy PKI CA (Platform ↔ Proxy) ├── Instance Relay PKI CA (Platform ↔ Relay)
Organization Level: Organization Level:
├── Organization Proxy SSH CA (Gateway ↔ Org Proxy) ├── Organization Relay SSH CA (Gateway ↔ Org Relay)
├── Organization Proxy PKI CA (Platform ↔ Org Proxy) ├── Organization Relay PKI CA (Platform ↔ Org Relay)
└── Organization Gateway CA (Platform ↔ Gateway) └── Organization Gateway CA (Platform ↔ Gateway)
``` ```
@@ -47,26 +47,26 @@ Organization Level:
When a gateway is first deployed: When a gateway is first deployed:
1. Authenticates with Infisical using machine identity token 1. Authenticates with Infisical using machine identity token
2. Receives SSH certificates for proxy server authentication 2. Receives SSH certificates for relay server authentication
3. Establishes SSH reverse tunnel to assigned proxy server 3. Establishes SSH reverse tunnel to assigned relay server
4. Certificate issuance varies by proxy configuration: 4. Certificate issuance varies by relay configuration:
- **Infisical-managed proxy**: Receives Instance proxy SSH client certificate + Instance proxy SSH Server CA - **Infisical-managed relay**: Receives Instance relay SSH client certificate + Instance relay SSH Server CA
- **Customer-deployed proxy**: Receives Organization proxy SSH client certificate + Organization proxy SSH Server CA - **Customer-deployed relay**: Receives Organization relay SSH client certificate + Organization relay SSH Server CA
### 2. SSH Tunnel Authentication ### 2. SSH Tunnel Authentication
Gateway ↔ Proxy Server communication uses SSH certificate authentication: Gateway ↔ Relay Server communication uses SSH certificate authentication:
- **Gateway Authentication**: - **Gateway Authentication**:
- Presents SSH client certificate (Instance or Organization proxy SSH Client CA) - Presents SSH client certificate (Instance or Organization relay SSH Client CA)
- Certificate contains gateway identification and permissions - Certificate contains gateway identification and permissions
- Proxy server validates certificate against appropriate SSH Client CA - Relay server validates certificate against appropriate SSH Client CA
- **Proxy Server Authentication**: - **Relay Server Authentication**:
- Presents SSH server certificate (Instance or Organization proxy SSH Server CA) - Presents SSH server certificate (Instance or Organization relay SSH Server CA)
- Gateway validates certificate against appropriate SSH Server CA - Gateway validates certificate against appropriate SSH Server CA
- Ensures gateway connects to legitimate proxy infrastructure - Ensures gateway connects to legitimate relay infrastructure
### 3. Application Traffic Security ### 3. Application Traffic Security
@@ -82,7 +82,7 @@ End-to-end encryption for application data:
- mTLS-encrypted application traffic travels through SSH reverse tunnels - mTLS-encrypted application traffic travels through SSH reverse tunnels
- Creates double encryption: mTLS payload within SSH tunnel - Creates double encryption: mTLS payload within SSH tunnel
- Proxy servers cannot decrypt either encryption layer - Relay servers cannot decrypt either encryption layer
3. **Traffic Isolation**: 3. **Traffic Isolation**:
- Each gateway maintains separate SSH tunnels - Each gateway maintains separate SSH tunnels
@@ -95,23 +95,23 @@ End-to-end encryption for application data:
The architecture provides tenant isolation through multiple certificate authority layers: The architecture provides tenant isolation through multiple certificate authority layers:
- **Instance-level CAs**: Shared proxy infrastructure uses instance-level certificates - **Instance-level CAs**: Shared relay infrastructure uses instance-level certificates
- **Organization-level CAs**: Each organization has unique certificate authorities - **Organization-level CAs**: Each organization has unique certificate authorities
- **Proxy deployment flexibility**: Organizations can choose shared or dedicated proxy infrastructure - **Relay deployment flexibility**: Organizations can choose shared or dedicated relay infrastructure
- **Cryptographic separation**: Cross-tenant communication is cryptographically impossible - **Cryptographic separation**: Cross-tenant communication is cryptographically impossible
### Authentication Flows by Deployment Type ### Authentication Flows by Deployment Type
**Infisical-Managed Proxy Deployments:** **Infisical-Managed Relay Deployments:**
- Gateway authenticates with proxy using Instance proxy SSH certificates - Gateway authenticates with relay using Instance relay SSH certificates
- Platform authenticates with proxy using Instance proxy PKI certificates - Platform authenticates with relay using Instance relay PKI certificates
- Platform authenticates with gateway using Organization Gateway certificates - Platform authenticates with gateway using Organization Gateway certificates
**Customer-Deployed Proxy Deployments:** **Customer-Deployed Relay Deployments:**
- Gateway authenticates with proxy using Organization proxy SSH certificates - Gateway authenticates with relay using Organization relay SSH certificates
- Platform authenticates with proxy using Organization proxy PKI certificates - Platform authenticates with relay using Organization relay PKI certificates
- Platform authenticates with gateway using Organization Gateway certificates - Platform authenticates with gateway using Organization Gateway certificates
### Resource Access Control ### Resource Access Control
@@ -125,5 +125,5 @@ The architecture provides tenant isolation through multiple certificate authorit
2. **Network Isolation**: 2. **Network Isolation**:
- Each organization's traffic flows through isolated certificate-authenticated channels - Each organization's traffic flows through isolated certificate-authenticated channels
- Proxy servers route traffic based on certificate validation without content access - Relay servers route traffic based on certificate validation without content access
- Gateway validates all incoming connections against Organization Gateway Client CA - Gateway validates all incoming connections against Organization Gateway Client CA