Skip to content

chore(cluster): guard gRPC listener isolation - #512

Merged
yordis merged 1 commit into
masterfrom
yordis/chore-grpc-endpoint-isolation-parity
Sep 24, 2026
Merged

yordis merged 1 commit into
masterfrom
yordis/chore-grpc-endpoint-isolation-parity

Conversation

@yordis

@yordis yordis commented Sep 24, 2026 •

Copy link
Copy Markdown
Member
  • Cluster traffic must remain isolated from client traffic as TCP transport is retired. A real listener-level safety check reduces the risk of exposing internal services on the client port.

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Signed-off-by: Yordis Prieto <yordis.prieto@gmail.com>
@yordis
yordis requested a review from a team as a code owner September 24, 2026 05:22
@cursor

cursor Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

PR Summary

Medium Risk
Changes the cluster node HTTP pipeline and enforces client vs cluster gRPC isolation at the listener; behavior should match the prior inline middleware but affects security-sensitive routing.

Overview
Refactors listener-level gRPC routing guard into a reusable UseEndpointPolicy ASP.NET Core middleware extension, replacing the inline middleware in Program.cs with the same behavior: requests that don’t match the listener’s role for the route get 404.

Adds EndpointPolicyKestrelTests to lock in isolation on two TLS Kestrel listeners: client monitoring gRPC succeeds only on the client port, cluster gossip only on the cluster port, and cross-listener calls fail without invoking the wrong service.

Reviewed by Cursor Bugbot for commit a6423ab. Bugbot is set up for automated code reviews on this repo. Configure here.

@coderabbitai

coderabbitai Bot commented Sep 24, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 8 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 4ca1d47c-dd7c-40a3-ba99-b72e022b3dee

📥 Commits

Reviewing files that changed from the base of the PR and between 56eb784 and a6423ab.

📒 Files selected for processing (3)
  • src/EventStore.ClusterNode/Components/Services/EndpointPolicy.cs
  • src/EventStore.ClusterNode/Program.cs
  • src/EventStore.Core.Tests/Regression/EndpointPolicyKestrelTests.cs

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@yordis
yordis merged commit e306569 into master Sep 24, 2026
38 of 40 checks passed
@yordis
yordis deleted the yordis/chore-grpc-endpoint-isolation-parity branch September 24, 2026 17:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant