forked from stripe/smokescreen
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Get smokescreen up to date with the upstream (#2)
* add a custom interface for the resolver instead of forcing *net.Resolver (stripe#187) * feature/add prometheus metrics (stripe#179) * STORY-25143 - Add prometheus metrics to smokescreen * STORY-25143 - Cleanup * STORY-25143 - Fix tests to compare new metric labels * STORY-25143 - Host prometheus endpoint on separate port * STORY-25143 - Use value provided via command line flag * STORY-25143 - Add prometheus timing metrics * STORY-25143 - Fix nil map assignment and prometheus metric name sanitisation * STORY-25143 - Cleanup comments * STORY-25143 - Remove some repetition + add further unit testing * STORY-25143 - Document new prometheus features in README + add port flag to prometheus config * STORY-25143 - Make PR requested changes: * Don't export metrics list * Follow project sytlistic choices * STORY-25143 - Rename only one receiver * STORY-25143 - Add new `--expose-prometheus-metrics` flag to CLI to toggle exposing prometheus metrics * Small cleanup of timer metrics * Fix go module vendoring * Use ElementsMatch to ignore order * Just use require * Move the custom request handler call after the main acl check * Use local server instead of httpbin (stripe#192) * Do not return a denyError for DNS resolution failures (stripe#194) * dont return denial errors for dns resolution failures * fix test * move DNSError check into net.Error assertion, extend test * fix integration test * add AcceptResponseHandler to modify accepted responses (stripe#196) * add AcceptResponseHandler to modify accepted responses * customer->custom * Update docs to clarify global_deny_list (stripe#197) * update docs to clarify global_deny_list behavior * consistent example domain * be more concise * Use AcceptResponseHandler in goproxy https CONNECT hook (stripe#199) * pipe AcceptResponseHandler into new goproxy hook * update comment * go mod vendor * unit test * use smokescreenctx in acceptresponsehandler * fix unit tests * Export SmokescreenContext type (stripe#200) * export SmokescreenContext type * also export AclDecision * ResolvedAddr too * consistent caps * Update pkg/smokescreen/smokescreen.go Co-authored-by: jjiang-stripe <55402658+jjiang-stripe@users.noreply.github.com> * export Decision --------- Co-authored-by: jjiang-stripe <55402658+jjiang-stripe@users.noreply.github.com> * generate new test pki (stripe#206) * allow listen address specification for prom (stripe#203) * Bump golang.org/x/net from 0.7.0 to 0.17.0 (stripe#204) Bumps [golang.org/x/net](https://github.com/golang/net) from 0.7.0 to 0.17.0. - [Commits](golang/net@v0.7.0...v0.17.0) --- updated-dependencies: - dependency-name: golang.org/x/net dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * bump go versions (stripe#207) * update dependency * configure addr in smokescreen and add unit test * use fmt * try this workaround * variable name change * Update docs to disambiguate ACL vs --deny-address behavior (stripe#210) * update docs to clarify how IP filtering works --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: JulesD <JulesDT@users.noreply.github.com> Co-authored-by: Josh McConnell <josh.mcconnell465@gmail.com> Co-authored-by: Kevin Vincent <kevinv@stripe.com> Co-authored-by: kevinv-stripe <102822342+kevinv-stripe@users.noreply.github.com> Co-authored-by: Sergey Rud <sergeyrud@stripe.com> Co-authored-by: cmoresco-stripe <106690468+cmoresco-stripe@users.noreply.github.com> Co-authored-by: Craig Shannon <cds@stripe.com> Co-authored-by: jjiang-stripe <55402658+jjiang-stripe@users.noreply.github.com> Co-authored-by: Timofey Bakunin <36561672+ne-bknn@users.noreply.github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Yuxi Xie <xieyuxi@stripe.com> Co-authored-by: xieyuxi-stripe <141708814+xieyuxi-stripe@users.noreply.github.com>
- Loading branch information
1 parent
83ed067
commit f2e36a3
Showing
617 changed files
with
108,730 additions
and
5,471 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,27 +1,33 @@ | ||
-----BEGIN CERTIFICATE----- | ||
MIIEnjCCA4agAwIBAgIUVX3IM4foGZSavx8CYfWm5035gs8wDQYJKoZIhvcNAQEL | ||
BQAwgeYxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRYwFAYDVQQH | ||
Ew1TYW4gRnJhbmNpc2NvMSMwIQYDVQQKExpOb3QgQSBDb21wYW55IENBIEZvciBU | ||
ZXN0czFgMF4GA1UECxNXT29wcyBJIGRpZCBpdCBhZ2FpbiwgSSBwbGF5ZWQgd2l0 | ||
aCB5b3VyIGhlYXJ0LCBnb3QgbG9zdCBpbiB0aGUgZ2FtZS4gT2ggYmFieSBiYWJ5 | ||
IGJhYnkuMSMwIQYDVQQDExpUZXN0IENlcnRpZmljYXRlIEF1dGhvcml0eTAeFw0x | ||
ODA4MTYyMDAwMDBaFw0yMzA4MTUyMDAwMDBaMIHmMQswCQYDVQQGEwJVUzETMBEG | ||
A1UECBMKQ2FsaWZvcm5pYTEWMBQGA1UEBxMNU2FuIEZyYW5jaXNjbzEjMCEGA1UE | ||
ChMaTm90IEEgQ29tcGFueSBDQSBGb3IgVGVzdHMxYDBeBgNVBAsTV09vcHMgSSBk | ||
aWQgaXQgYWdhaW4sIEkgcGxheWVkIHdpdGggeW91ciBoZWFydCwgZ290IGxvc3Qg | ||
aW4gdGhlIGdhbWUuIE9oIGJhYnkgYmFieSBiYWJ5LjEjMCEGA1UEAxMaVGVzdCBD | ||
ZXJ0aWZpY2F0ZSBBdXRob3JpdHkwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK | ||
AoIBAQDB/IYY40+YyUyo42bUh6JWgs5ywdCi7nokoYET4VnXiIvxtWAFksAZnNk2 | ||
T+2RqXJuZbknZLNaOFhDsOz21q52zO57T3Q9q7X7XqeW7kAnQ5rkNV1liL3FbUgq | ||
pm9Ask3wRPU9qx5S8ToBdck25tN4mwjAHmqswaEhfGVK1rXJyuBb2CQO3AWADkOt | ||
Q8PbiEJus40elY49iYp7vRgNIt53HpD5L9O6hDGLCw0HQDPceGdAVc+CcJMlIJ/0 | ||
W0rGmZbAEZVsoOYYQ0+2aPkIKw+PJ0DMXugZxlXFTUeHn55slMwL7nmN1MIYDElY | ||
YOvQR391npmjPuSGp9fEhgDmgjSTAgMBAAGjQjBAMA4GA1UdDwEB/wQEAwIBBjAP | ||
BgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBSHjuAR3Zu6D8nvU8Uif7TEMN/ujjAN | ||
BgkqhkiG9w0BAQsFAAOCAQEAKBmSNB2Htl+nu1/PHrc5pi1UmV9ySrAi1g/DAzDR | ||
iGwDV5M+fUzdLg9Gb+Pg6b0HaIQRfUs4+qKgzbjCvqfdvk9806BH/1Rpvltiebom | ||
owk4XSr/28dEpx7VYBl/FC35J4NQ2IIiBM3m8vSoXHWxxONgq3kew0iPdeoJf7Sx | ||
h2UCaRlAd2IFjZcjUTqEY9nT6VzADoLpYuz5Fol41/iAsULnbut5ALI3IPFjzObm | ||
DapuCX9xWMoaZ9MzsPMZwxt/KF/NqBXwiOkqzdJhchcnmPerZGq7jIg7VV6pBr4j | ||
FGmMujqO/UZWu9D/QosIotF3OWlGL5NaZ8isVJ/GJrNJXg== | ||
MIIFtzCCA5+gAwIBAgIUcYbxViF/fKZg1BwwMGN2FL6EGTIwDQYJKoZIhvcNAQEL | ||
BQAwazELMAkGA1UEBhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFjAUBgNVBAcM | ||
DVNhbiBGcmFuY2lzY28xGTAXBgNVBAoMEFNtb2tlc2NyZWVuIFRlc3QxFDASBgNV | ||
BAsMC1Ntb2tlc2NyZWVuMB4XDTIzMTEwNzIyMDU1NVoXDTMzMTEwNDIyMDU1NVow | ||
azELMAkGA1UEBhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFjAUBgNVBAcMDVNh | ||
biBGcmFuY2lzY28xGTAXBgNVBAoMEFNtb2tlc2NyZWVuIFRlc3QxFDASBgNVBAsM | ||
C1Ntb2tlc2NyZWVuMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAx4a5 | ||
2Y4XpdumUADBTa3oIY9kFHvH+yquzRyD4ngRCTKmDq4r1SKpZBQluG18ihf6f7GS | ||
7BFAl2wIcRt5fZtWmpKgZynLrCx+fiBVrnxKdsiVkZp/nY8hLDnweInYXX6J3UP2 | ||
vmrTl+jGAoylDgQ3aS3gkhVc3QjI6pSg58cDKZYNX22J0whp2DiRHD5T1pYWWAaK | ||
5Aw0XR1SatvsLSKu6Xga7heTOZH0M06KYSs8h4BklSAdRR7xP+u1VqnXWPKetj8g | ||
WnqoEQummIrDEZMZAiV3KJANdkDfa66vKnEweIAymqempXK+35gqAmI3ErO4quWD | ||
mAaZ6iZLzpZxJRNpRyF7LNi5fntaOA67r80yDel6VfaDekoEqVwI6jXCSbLdqzyj | ||
lD47RQDVZmKX6SSi/skb9lsHc2HpejJyMEDXQPgn+keulIg+/088qWwGgRRTpipt | ||
NIl2+RSKnK+fqoIhUVQdV9yBJ3MVWXH/H2KfVrOy/TARsai9CsfC6Mt3xM5cOE0r | ||
WFjybZO1QStenRXjFKMD15zoVM+fYQRYTuO0t1ICSgWAbPNjWpYkTXocbYq/flGY | ||
KTGfRGAuiEMuRC1HSjgT+ZhARB353oNgfNinh8M/cwGpAPwvsUtLOSTI3z+gZ/eh | ||
0hE5zAUmI9a7X8t9cXDgiYb6PwTYt7CsY/0YTwMCAwEAAaNTMFEwHQYDVR0OBBYE | ||
FCJvjD/Gk7eKYbHd4RaBgeyQbY3SMB8GA1UdIwQYMBaAFCJvjD/Gk7eKYbHd4RaB | ||
geyQbY3SMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADggIBAJ5FMe89 | ||
sAQ0YtAj7LmBqx73DlrmwNZ/00N5IZJgoiBYxGQvsc7Y69vBSkiX0ZuJ5i1rkJqL | ||
ngJTdycOKzc1ofa6kf3JPrxk3EeGEEqCDdByI2eUB9oVxcGtqL1/eAXVYwFjXupY | ||
/CRkrv1qVSfioyNw1JrLxu0j+zqlfYFc/hUAvPm7HEHTnDKePxf+r1fqztudD4ld | ||
kjrcxW4otWHxEP4oyadyrcF7NWQK9vgzyXlB3lj57b8qlfrcniCnqYVFsRoCCFoa | ||
+fETmhzgyNsUG5N2YfvDHd8yYuKyRKm+dDnVCN+RIov32oTvIFY5qHdpyjv30wvB | ||
0hhGpeTgeXY/ddVJu2BU8Ni8xgbKB9tRgPiO88bN4aWKoM6TRlhWfbcvpGKWY9ED | ||
CVzILzUDydhaqB8iC0NYlcBrooVl7MHkvl/7KW9QC+WKrsIXWeF48sUOtOpTvkfY | ||
nBjD+1RfHLML66WoferPNoDB1T6vkIcRKbHESYRfRwvsgD2fqVsepvJREt63yHKz | ||
KJHD/XxJAxMjrqAxqz1t4c/yg2dHA14jL/VgIooUfbvtiljFaDml0tdEIB4n0Ddy | ||
ckpj/iwIwJsg2yVVuStqWEPeErVmsdsDKbtn3KV6Y7wAQcSWFhJVYwiy78atgxOk | ||
CIQtLAJVo2DMgpZEHAmrkGlJ/a44blA/zd4b | ||
-----END CERTIFICATE----- |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,21 +1,18 @@ | ||
-----BEGIN X509 CRL----- | ||
MIIDijCCAnICAQEwDQYJKoZIhvcNAQELBQAwgeYxCzAJBgNVBAYTAlVTMRMwEQYD | ||
VQQIEwpDYWxpZm9ybmlhMRYwFAYDVQQHEw1TYW4gRnJhbmNpc2NvMSMwIQYDVQQK | ||
ExpOb3QgQSBDb21wYW55IENBIEZvciBUZXN0czFgMF4GA1UECxNXT29wcyBJIGRp | ||
ZCBpdCBhZ2FpbiwgSSBwbGF5ZWQgd2l0aCB5b3VyIGhlYXJ0LCBnb3QgbG9zdCBp | ||
biB0aGUgZ2FtZS4gT2ggYmFieSBiYWJ5IGJhYnkuMSMwIQYDVQQDExpUZXN0IENl | ||
cnRpZmljYXRlIEF1dGhvcml0eRcNMTgwODE2MjAyOTE1WhcNMTkwMjEyMjAyOTE1 | ||
WjAjMCECEHD0KS8QbJYZeDE3OU4loLoXDTE4MDgxNjIwMjkwNFqgggEwMIIBLDCC | ||
ASgGA1UdIwSCAR8wggEbgBSHjuAR3Zu6D8nvU8Uif7TEMN/ujqGB7KSB6TCB5jEL | ||
MAkGA1UEBhMCVVMxEzARBgNVBAgTCkNhbGlmb3JuaWExFjAUBgNVBAcTDVNhbiBG | ||
cmFuY2lzY28xIzAhBgNVBAoTGk5vdCBBIENvbXBhbnkgQ0EgRm9yIFRlc3RzMWAw | ||
XgYDVQQLE1dPb3BzIEkgZGlkIGl0IGFnYWluLCBJIHBsYXllZCB3aXRoIHlvdXIg | ||
aGVhcnQsIGdvdCBsb3N0IGluIHRoZSBnYW1lLiBPaCBiYWJ5IGJhYnkgYmFieS4x | ||
IzAhBgNVBAMTGlRlc3QgQ2VydGlmaWNhdGUgQXV0aG9yaXR5ghRVfcgzh+gZlJq/ | ||
HwJh9abnTfmCzzANBgkqhkiG9w0BAQsFAAOCAQEAL6CaIzWHsH1ndzG83OhqMsuI | ||
8Tlm8Yu8kYkCTvq4V5wpFUxtG7Pf8pKi1M8I9PsF+YTa58Atwb5RLMACi9RIj/hn | ||
zRMWMy4zUIChIuzM7y5MVT4z7amqjzRXZIlJOQkedjWW+qU3a2c5YYZjvDHUJ5dj | ||
MdAqU9lxafntKQDwOH8EYsMqSYNRQgJ6DzkRFb+ASaLvEtX+AOQhx55BsmpfEMNP | ||
dzDaQVvXIeGIWT3O9ZkHvIBS4+hUj1cWoCZncnAbNgUSW/LvxllucWQiyzYfAf9I | ||
J+djj/piXhXnU5AETozVFoIusSU3Fmh0FMfdHDl8y9EYGBZYMze1dluVlvmX5w== | ||
MIIC2zCBxAIBATANBgkqhkiG9w0BAQsFADBrMQswCQYDVQQGEwJVUzETMBEGA1UE | ||
CAwKQ2FsaWZvcm5pYTEWMBQGA1UEBwwNU2FuIEZyYW5jaXNjbzEZMBcGA1UECgwQ | ||
U21va2VzY3JlZW4gVGVzdDEUMBIGA1UECwwLU21va2VzY3JlZW4XDTIzMTEwNzIx | ||
NDMyMFoXDTIzMTIwNzIxNDMyMFowFDASAgEBFw0yMzExMDcyMTQzMTRaoA8wDTAL | ||
BgNVHRQEBAICEAEwDQYJKoZIhvcNAQELBQADggIBAI7yGPw4/A+7WMrqghIcsbZK | ||
UuLRA7R0AlKIzQGJ/4Tk+ZJF1mlhQrB7kB89yPq7b+CssldnvWpIH67yn3snKtdU | ||
QYOxvXfds2wJn4kyWo46Nnz4/1huc2r4sNEvyvTLEH6VRxivHGR2UncODPkNVpcu | ||
eBoFUwUZrh9aWUcBY1/ilPcWq7JwyGQsuIM7IBLkaWb75ZV+poEzufIVVxKUhCbB | ||
YK56ik7HxDk9YyrX3+69dpCFAsOtg3STph4CpKLHmmarJ6rRGJ1gTa5prva7kfZD | ||
ewYuyjJHhonHPR9WkiVeMm6SV7Odmhw0t8p2TMRx2xre+jdIuHZ7OrPxpd0f+XU9 | ||
NFMzUyccS9WrPbztcWW7c0bTA0wfESCxMQ5HccG3JHy5kVGCj8pugOUk1j1WmTo7 | ||
D+8qlEnRaIaKUfK7Hp+8X8tGtG3D7Dt+N466i9C6zOfCerP0A8hl0c+UQucpy/cg | ||
G04P7Fpv6b5/yazVReoBcmCFFFPJ04P+MH2h/OIOo4lQjR735H3zRTiCqUpWpQQO | ||
O6gL8AnoulS7H9IVvUJi1C3HEUnA7GBrkILoi5g94O8NICLq781v7ACUz9gBV6P1 | ||
y5ev/z5Dz9jWbFa4YjY8DQjLPmulYPSJWDmvVEuYHgjvEZTER+fJfJQwMZCQ5bhA | ||
T4MWh0an1F6H6uTv1Rpc | ||
-----END X509 CRL----- |
Oops, something went wrong.