ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘-ingress-nginx ื”ืžืืคืฉืจื•ืช ืœื”ืชืคืฉืจ ืขืœ ืืฉื›ื•ืœื•ืช Kubernetes

ื‘ื‘ืงืจ ingress-nginx ืฉืคื•ืชื— ืขืœ ื™ื“ื™ ืคืจื•ื™ืงื˜ Kubernetes, ื–ื•ื”ื• ืฉืœื•ืฉ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื”ืžืืคืฉืจื•ืช, ื‘ืชืฆื•ืจืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ, ื’ื™ืฉื” ืœื”ื’ื“ืจื•ืช ืฉืœ ืื•ื‘ื™ื™ืงื˜ Ingress, ืืฉืจ, ื‘ื™ืŸ ื”ื™ืชืจ, ืžืื—ืกืŸ ืื™ืฉื•ืจื™ื ืœื’ื™ืฉื” ืœืฉืจืชื™ Kubernetes, ื”ืžืืคืฉืจ ื’ื™ืฉื” ืžื•ืขื“ืคืช. ืœืืฉื›ื•ืœ. ื”ื‘ืขื™ื•ืช ืžื•ืคื™ืขื•ืช ืจืง ื‘ื‘ืงืจ ingress-nginx ืžืคืจื•ื™ืงื˜ Kubernetes ื•ืื™ื ืŸ ืžืฉืคื™ืขื•ืช ืขืœ ื‘ืงืจ kubernetes-ingress ืฉืคื•ืชื— ืขืœ ื™ื“ื™ ืžืคืชื—ื™ NGINX.

ื‘ืงืจ ื”ื›ื ื™ืกื” ืคื•ืขืœ ื›ืฉืขืจ ื•ืžืฉืžืฉ ื‘-Kubernetes ืœืืจื’ื•ืŸ ื’ื™ืฉื” ืžื”ืจืฉืช ื”ื—ื™ืฆื•ื ื™ืช ืœืฉื™ืจื•ืชื™ื ื‘ืชื•ืš ื”ืืฉื›ื•ืœ. ื‘ืงืจ ingress-nginx ื”ื•ื ื”ืคื•ืคื•ืœืจื™ ื‘ื™ื•ืชืจ ื•ืžืฉืชืžืฉ ื‘ืฉืจืช NGINX ื›ื“ื™ ืœื”ืขื‘ื™ืจ ื‘ืงืฉื•ืช ืœืืฉื›ื•ืœ, ืœื ืชื‘ ื‘ืงืฉื•ืช ื—ื™ืฆื•ื ื™ื•ืช ื•ืื™ื–ื•ืŸ ืขื•ืžืกื™ื. ืคืจื•ื™ืงื˜ Kubernetes ืžืกืคืง ื‘ืงืจื™ ื›ื ื™ืกืช ืœื™ื‘ื” ืขื‘ื•ืจ AWS, GCE ื•-nginx, ืฉื”ืื—ืจื•ืŸ ืฉื‘ื”ื ืื™ื ื• ืงืฉื•ืจ ื‘ืฉื•ื ืื•ืคืŸ ืœื‘ืงืจ kubernetes-ingress ื”ืžืชื•ื—ื–ืง ืขืœ ื™ื“ื™ F5/NGINX.

ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘-ingress-nginx ื”ืžืืคืฉืจื•ืช ืœื”ืชืคืฉืจ ืขืœ ืืฉื›ื•ืœื•ืช Kubernetes

ื”ืคื’ื™ืขื•ื™ื•ืช CVE-2023-5043 ื•-CVE-2023-5044 ืžืืคืฉืจื•ืช ืœืš ืœื”ืคืขื™ืœ ืืช ื”ืงื•ื“ ืฉืœืš ื‘ืฉืจืช ืขื ื”ื–ื›ื•ื™ื•ืช ืฉืœ ืชื”ืœื™ืš ื‘ืงืจ ื”ื›ื ื™ืกื”, ื‘ืืžืฆืขื•ืช "nginx.ingress.kubernetes.io/configuration-snippet" ื•-"nginx.ingress .kubernetes" ื›ื“ื™ ืœื”ื—ืœื™ืฃ ืื•ืชื• ื‘-.io/permanent-redirect." ื‘ื™ืŸ ื”ื™ืชืจ, ื–ื›ื•ื™ื•ืช ื”ื’ื™ืฉื” ืฉื”ื•ืฉื’ื• ืžืืคืฉืจื•ืช ืœืš ืœืื—ื–ืจ ืืกื™ืžื•ืŸ ื”ืžืฉืžืฉ ืœืื™ืžื•ืช ื‘ืจืžืช ื ื™ื”ื•ืœ ื”ืืฉื›ื•ืœื•ืช. ืคื’ื™ืขื•ืช CVE-2022-4886 ืžืืคืฉืจืช ืœืš ืœืขืงื•ืฃ ืืช ืื™ืžื•ืช ื ืชื™ื‘ ื”ืงื•ื‘ืฅ ื‘ืืžืฆืขื•ืช ื”ื•ืจืืช log_format.

ืฉืชื™ ื”ืคื’ื™ืขื•ื™ื•ืช ื”ืจืืฉื•ื ื•ืช ืžื•ืคื™ืขื•ืช ืจืง ื‘ืžื”ื“ื•ืจื•ืช ingress-nginx ืœืคื ื™ ื’ืจืกื” 1.9.0, ื•ื”ืื—ืจื•ื ื” - ืœืคื ื™ ื’ืจืกื” 1.8.0. ื›ื“ื™ ืœื‘ืฆืข ืชืงื™ืคื”, ืœืชื•ืงืฃ ื—ื™ื™ื‘ืช ืœื”ื™ื•ืช ื’ื™ืฉื” ืœืชืฆื•ืจื” ืฉืœ ืื•ื‘ื™ื™ืงื˜ ื”ื›ื ื™ืกื”, ืœืžืฉืœ ื‘ืืฉื›ื•ืœื•ืช Kubernetes ืžืจื•ื‘ื™ ื“ื™ื™ืจื™ื, ื‘ื”ื ื ื™ืชื ืช ืœืžืฉืชืžืฉื™ื ื”ื™ื›ื•ืœืช ืœื™ืฆื•ืจ ืื•ื‘ื™ื™ืงื˜ื™ื ื‘ืžืจื—ื‘ ื”ืฉืžื•ืช ืฉืœื”ื.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”