[WIP] fix(azure): validate metadata IPv4 against guest networking - #80
Draft
Garrett Settles (gsettles01) wants to merge 4 commits into
Draft
Garrett Settles (gsettles01) wants to merge 4 commits into
Garrett Settles (gsettles01) wants to merge 4 commits into
Conversation
Azure WireServer SharedConfig can report an IPv4 address not assigned to the VM, causing etcd to bind to the wrong address. Validate the route-selected IPv4 against the interface and IMDS before metadata consumers start. Keep this in Azure RPM images, preserve the first raw result, and add offline regression coverage. Validation: 22 offline cases and one fresh ARM64 discovery run passed. All three nodes passed regeneration and reboot with SELinux enforcing. Refs: ACL Bug 18833
The helper runs as ExecStartPost after Afterburn has already reached WireServer and IMDS, so the drop-in needs no network-online ordering. The assigned-address check already rejects impossible IPv4 values, so drop the octet range loop. The pattern check still guards the sed rewrite; the invalid-ipv4 test now uses a value it rejects.
Enable the acl-pipelines testAzureMetadataIpv4 step so PR validation runs the offline test on the build agent. The test only needs Bash and jq because ip and curl are fixtures. Enforce cl.metadata.azure so Azure kola runs catch a wrong COREOS_AZURE_IPV4_DYNAMIC. It is registered for Azure only, so QEMU runs never select it. Requires the acl-pipelines testAzureMetadataIpv4 parameter on main. Refs: ACL Bug 18833
Garrett Settles (gsettles01)
deployed
to
development
September 24, 2026 00:58 — with
GitHub Actions
Active
15 tasks
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
On Azure Arm64 VMs, WireServer SharedConfig can report an IPv4 address that is not assigned to the VM (seen:
10.10.10.10). Afterburn writes it toCOREOS_AZURE_IPV4_DYNAMIC, etcd binds to an address the VM does not have, andacl.etcd-member.discoveryfails on Azure aarch64.After Afterburn writes metadata, a new helper checks the route-selected source IPv4 against the interface's assigned addresses and IMDS (matching MAC and IP), and only then corrects
COREOS_AZURE_IPV4_DYNAMIC. The first WireServer result is kept in/run/metadata/flatcar.wireserver. If any check fails, the metadata is left unchanged andcoreos-metadata.servicefails.To keep CI working, merge in this order:
testAzureMetadataIpv4gate parameter. Until it merges, this PR's validation fails on that unknown parameter.cl.metadata.azurecheck the address.Change Log
azure-metadata-ipv4and acoreos-metadata.servicedrop-in that runs it asExecStartPost;manglefs_rpm.shinstalls both in RPM mode only.build_library/rpm/tests/test_azure_metadata_ipv4.sh(22 offline cases; needs only Bash and jq) and run it in PR validation via.pipelines/github-pr-validation.yml.cl.metadata.azureinacl/tests/kola_enforcing.yaml.Type of Change
Does this affect the image build?
Adds the helper and drop-in to the Azure OEM sysext in RPM images. Other platforms and Portage builds are unchanged.
Associated Issues
gsettles/18833-azure-metadata-ip-fix).Test Methodology
[ARM64]-Prod-BuildACL-Nightly1204420.bash build_library/rpm/tests/test_azure_metadata_ipv4.shpasses 22/22 in the SDK container with no network, on a plain Ubuntu host, and in Azure Linux 3 using the pipeline step. Replacing the helper withexit 0makes it fail.acl.etcd-member.discovery. A third failed on an unrelated DNS error while pulling the etcd image (systemd retried it successfully); its metadata was correct on all 3 nodes.coreos-metadata.servicesucceeded with no restarts.cl.metadata.azure,acl.etcd-member.discovery), plus an aclmain baseline wherecl.metadata.azureshould fail.Merge Checklist
All applicable boxes should be checked before merging.