Your message dated Wed, 12 Aug 2026 13:04:59 +0000
with message-id <[email protected]>
and subject line Bug#1144214: fixed in ironic 1:35.0.1-10
has caused the Debian Bug report #1144214,
regarding API ramdisk endpoints require network-level access controls
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1144214: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144214
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: ironic
Version: 1:29.0.5-0+deb13u2
Severity: important
Tags: patch security
X-Debbugs-Cc: Debian Security Team <[email protected]>
As per upstream announce at:
https://wiki.openstack.org/wiki/OSSN/OSSN-0106
Ironic API ramdisk endpoints require network-level access controls
Summary:
The Ironic Bare Metal API combines authenticated endpoints for client use with
unauthenticated endpoints for coordination with the Ironic Python Agent
ramdisk into a single API service. Depending on the deployment architecture,
this can expose security risks if the unauthenticated endpoints are reachable
from untrusted networks.
Affected Services / Software:
ironic: >=6.2.0
/v1/lookup and /v1/heartbeat: API version 1.22 (Newton, ironic 6.2.0)
/v1/continue_inspection: API version 1.84 (2024.2)
Discussion:
Ironic has three endpoints which allow unauthenticated access:
GET /v1/lookup
POST /v1/heartbeat/{node_ident}
POST /v1/continue_inspection
These endpoints are a documented aspect of Ironic's architecture and are
covered in the Ironic security guide. They already have significant security
controls to mitigate risk, such as bootstrapping into credentials via the
agent token mechanism (mandatory since the Victoria release), callback URL
validation, and defaulting to limiting access to nodes whose provisioning
state requires use of them.
Regardless of authentication methodology, operators in multi-tenant or
untrusted environments should deploy a split-horizon API configuration where
the unauthenticated endpoints are not reachable from public or tenant networks.
Using Keystone does not eliminate the need for this network-level separation.
Previously, Ironic only provided policy-based overrides to disable these
endpoints, which required Keystone and left operators using HTTP basic auth or
noauth without an equivalent control. A new ``[api]enable_ramdisk_endpoints``
configuration option is being added to allow any operator, regardless of
authentication methodology, to disable these endpoints on a per-service basis.
For full details on the security model around these endpoints, refer to the
Ironic security guide:
https://docs.openstack.org/ironic/latest/admin/security.html
Recommended Actions:
Operators using Ironic in a multi-tenant or untrusted environment should
configure the Ironic API so that the unauthenticated endpoints are only
accessible from networks where the Ironic Python Agent ramdisk operates. This
can be achieved in several ways depending on infrastructure setup:
1. Run separate public-facing and ramdisk-facing Ironic API services.
WARNING: Disabling the ramdisk endpoints without maintaining a separate API
service that the Ironic Python Agent can reach will break all deployment,
cleaning, inspection, rescue, and servicing workflows. These endpoints must
remain available to the ramdisk on at least one API service.
On the public-facing service, disable the ramdisk endpoints using one of the
following methods:
Set ``[api]enable_ramdisk_endpoints`` to ``False`` in ironic.conf
(anticipated in the 2026.2 Hibiscus cycle, ironic 39.0.0; available earlier
by applying the linked patch).
For Keystone-authenticated deployments, add the following to policy.yaml:
"baremetal:node:ipa_heartbeat": "!"
"baremetal:driver:ipa_lookup": "!"
"baremetal:driver:ipa_continue_inspection": "!"
When using this architecture, the [deploy]external_callback_url setting can
direct the agent callback URL to the internal API service, and the
[service_catalog]endpoint_override setting can override Ironic's own internal
endpoint resolution, if required.
2. Use a fronting HTTP proxy, WSGI runner, or other external method to
restrict access to /v1/lookup, /v1/heartbeat, and /v1/continue_inspection to
only networks which run the Ironic Python Agent. This method requires no
Ironic code changes.
3. Ensure ``[api]restrict_lookup`` remains set to its default value of True.
Disabling this setting removes state-based filtering on the lookup endpoint
and significantly broadens exposure.
Credits:
Tuomo Tanskanen, Ericsson Software Technology (Metal3.io Security Team)
Dmitry Tantsur, Red Hat (Metal3.io Security Team)
Contacts / References
Authors:
Julia Kreger, Red Hat
Jay Faulkner, G-Research OSS
This OSSN: https://wiki.openstack.org/wiki/OSSN/OSSN-0106 Original Launchpad
bugs:
https://bugs.launchpad.net/ironic/+bug/2162821
https://bugs.launchpad.net/ironic/+bug/2162818
Proposed enhancement: https://review.opendev.org/c/openstack/ironic/+/999897
Mailing List : [security-sig] tag on [email protected]
OpenStack Security : https://security.openstack.org/
CVE: none
--- End Message ---
--- Begin Message ---
Source: ironic
Source-Version: 1:35.0.1-10
Done: Thomas Goirand <[email protected]>
We believe that the bug you reported is fixed in the latest version of
ironic, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Thomas Goirand <[email protected]> (supplier of updated ironic package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Wed, 12 Aug 2026 14:39:05 +0200
Source: ironic
Architecture: source
Version: 1:35.0.1-10
Distribution: unstable
Urgency: medium
Maintainer: Debian OpenStack <[email protected]>
Changed-By: Thomas Goirand <[email protected]>
Closes: 1144214
Changes:
ironic (1:35.0.1-10) unstable; urgency=medium
.
* OSSN-0106: API ramdisk endpoints require network-level access controls.
Added upstream patch: "Add [api] enable_ramdisk_endpoints config option"
(Closes: #1144214).
Checksums-Sha1:
77685beeaf2ebc6431aa3bb1b0152d342303c69e 4067 ironic_35.0.1-10.dsc
5df41402ad538491d7b1b78958622d338b969c0f 65204 ironic_35.0.1-10.debian.tar.xz
51099de92168d0e31f433fc88321014fb18faa1c 22521 ironic_35.0.1-10_amd64.buildinfo
Checksums-Sha256:
3461cc3dfa2dcd74e650130a2c8f88620cc90ede339697ddcda94cabcfefb127 4067
ironic_35.0.1-10.dsc
ba693acff0d38dd81af261a7c2ff6de440d77b66847a22ef8a7350ab4a3c5642 65204
ironic_35.0.1-10.debian.tar.xz
d7be8aaa75af467921c1c9f411791d5f53b1f489798f8c8e1afcbfdd87ea860b 22521
ironic_35.0.1-10_amd64.buildinfo
Files:
4500036b5b81f4c1a70ab0c31a526287 4067 net optional ironic_35.0.1-10.dsc
e1f1222f33740fa2d8d06fedfb05da39 65204 net optional
ironic_35.0.1-10.debian.tar.xz
1d7ac59ce97a57c599a0dc61c0adfb91 22521 net optional
ironic_35.0.1-10_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmp8bGEACgkQ1BatFaxr
Q/6bmQ//cX5V2RSH/+pQxeSNI3SUdzm6ZfSMdBZi5AlzcjUFKYP7kke4DQz6TKQ0
KAQ+86Fxhofn+z037v6J1XmmUaZF8b6P4mEAHbZoy7A5K20+bX8C9bTyZ3KGT3+z
4vPOJevo4D0Eh8DOaUt8zW3QF5l6fcwJ1b9aDoeQnrMmyD6WLv/vO60gnAOc4Wvn
QA2rYGSX2DyuT378vN8B0JHpx+xzb22NHpH1UTW4kamha1E14IPc4dpOjCfHqhUI
wiq4BNHOxOsi4QZt/Oef+4E9Rb7yoT3Ztx3SrmN7pOxHbtNSVNBD5ASoYb+FR9r1
je5GC48B5n/39XupF0vJzLT3F4lXipWlCQfWu3TGrz5T5Vev1AIulJjc80WmmFsp
Qnn1eOJVDm2F6IEbPN36xonUCBMUgxy99svrFnxz0arP8WWXewyP/SdB4v21aUyK
9K3wNSZnyf+lTw4JVQzHgcIVn7V9yeYxmNiA92beGdShZadJidzNhpAUrRtNgDHL
MvrtAQzC6QKiL2crF3rH1rncWNp2VIm9+T/4TaVrQxqMZYbrH4UhNSOz4KcdFDPU
h95B+CGFgYFt12LtIsgziSLrHe18VFkQsdcEPvB7cfiJNFIzJTMRUpus6FqzcaOU
ggkHEvv4JkObuEtKO7piGqIVkp8fhYgBk4Kpm8zMpbh/D29x5x0=
=jIsw
-----END PGP SIGNATURE-----
pgpdbPXlgWsqc.pgp
Description: PGP signature
--- End Message ---