This is an automated email from the ASF dual-hosted git repository.
damccorm pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/beam.git
The following commit(s) were added to refs/heads/master by this push:
new 929359adba9 Enforce TLS 1.2+ on ARC webhook GCE Ingress (#40382)
929359adba9 is described below
commit 929359adba9770e61dd79e86bea743764f64f22f
Author: Danny McCormick <[email protected]>
AuthorDate: Thu Oct 1 19:26:16 2026 +0000
Enforce TLS 1.2+ on ARC webhook GCE Ingress (#40382)
---
.../arc/config/arc_frontend_config.tpl | 24 ++++++++++++++++++++++
.github/gh-actions-self-hosted-runners/arc/gke.tf | 7 +++++++
.../arc/kubernetes.tf | 6 ++++++
.../gh-actions-self-hosted-runners/arc/locals.tf | 1 +
4 files changed, 38 insertions(+)
diff --git
a/.github/gh-actions-self-hosted-runners/arc/config/arc_frontend_config.tpl
b/.github/gh-actions-self-hosted-runners/arc/config/arc_frontend_config.tpl
new file mode 100644
index 00000000000..0dbfb8c4354
--- /dev/null
+++ b/.github/gh-actions-self-hosted-runners/arc/config/arc_frontend_config.tpl
@@ -0,0 +1,24 @@
+#
+# Licensed to the Apache Software Foundation (ASF) under one
+# or more contributor license agreements. See the NOTICE file
+# distributed with this work for additional information
+# regarding copyright ownership. The ASF licenses this file
+# to you under the Apache License, Version 2.0 (the
+# "License"); you may not use this file except in compliance
+# with the License. You may obtain a copy of the License at
+#
+# http://www.apache.org/licenses/LICENSE-2.0
+#
+# Unless required by applicable law or agreed to in writing,
+# software distributed under the License is distributed on an
+# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+# KIND, either express or implied. See the License for the
+# specific language governing permissions and limitations
+# under the License.
+#
+apiVersion: networking.gke.io/v1beta1
+kind: FrontendConfig
+metadata:
+ name: arc-webhook-frontend-config
+spec:
+ sslPolicy: ${ssl_policy}
diff --git a/.github/gh-actions-self-hosted-runners/arc/gke.tf
b/.github/gh-actions-self-hosted-runners/arc/gke.tf
index c6c3c967838..35b4e661338 100644
--- a/.github/gh-actions-self-hosted-runners/arc/gke.tf
+++ b/.github/gh-actions-self-hosted-runners/arc/gke.tf
@@ -114,6 +114,13 @@ data "google_compute_global_address" "actions-runner-ip" {
name = var.existing_ip_name == "" ?
google_compute_global_address.actions-runner-ip[0].name : var.existing_ip_name
}
+resource "google_compute_ssl_policy" "actions-runner-ssl-policy" {
+ count = var.deploy_webhook != "false" ? 1 : 0
+ name = "${var.environment}-actions-runner-ssl-policy"
+ profile = "MODERN"
+ min_tls_version = "TLS_1_2"
+}
+
data google_service_account "service_account" {
account_id = var.service_account_id
}
\ No newline at end of file
diff --git a/.github/gh-actions-self-hosted-runners/arc/kubernetes.tf
b/.github/gh-actions-self-hosted-runners/arc/kubernetes.tf
index 0a36e1fa2ba..91a9b2d8cb2 100644
--- a/.github/gh-actions-self-hosted-runners/arc/kubernetes.tf
+++ b/.github/gh-actions-self-hosted-runners/arc/kubernetes.tf
@@ -32,6 +32,12 @@ resource "kubectl_manifest" "arc_webhook_certificate" {
override_namespace = "arc"
depends_on = [helm_release.arc]
}
+resource "kubectl_manifest" "arc_webhook_frontend_config" {
+ count = var.deploy_webhook != "false" ? 1 : 0
+ yaml_body = templatefile("config/arc_frontend_config.tpl", {
ssl_policy = google_compute_ssl_policy.actions-runner-ssl-policy[0].name })
+ override_namespace = "arc"
+ depends_on = [helm_release.arc]
+}
resource "kubectl_manifest" "arc_deployment_additional" {
diff --git a/.github/gh-actions-self-hosted-runners/arc/locals.tf
b/.github/gh-actions-self-hosted-runners/arc/locals.tf
index 7820ce3e8aa..28094e1863d 100644
--- a/.github/gh-actions-self-hosted-runners/arc/locals.tf
+++ b/.github/gh-actions-self-hosted-runners/arc/locals.tf
@@ -34,6 +34,7 @@ locals {
"githubWebhookServer.service.type" = "NodePort"
"githubWebhookServer.ingress.annotations.kubernetes\\.io/ingress\\.global-static-ip-name"
= var.deploy_webhook != "false" ?
data.google_compute_global_address.actions-runner-ip[0].name : "not-configured"
"githubWebhookServer.ingress.annotations.networking\\.gke\\.io/managed-certificates"
= "managed-cert"
+
"githubWebhookServer.ingress.annotations.networking\\.gke\\.io/v1beta1\\.FrontendConfig"
= "arc-webhook-frontend-config"
"githubWebhookServer.ingress.annotations.kubernetes\\.io/ingress\\.class" =
"gce"
}
}
\ No newline at end of file