Thanks to visit codestin.com
Credit goes to github.com

Skip to content

feat: wire and persist coder_dlp_policy from provisioner to database - #25464

Closed
jscottmiller wants to merge 4 commits into
mainfrom
feat/dlp-policy-enforcement
Closed

feat: wire and persist coder_dlp_policy from provisioner to database#25464
jscottmiller wants to merge 4 commits into
mainfrom
feat/dlp-policy-enforcement

Conversation

@jscottmiller

@jscottmiller jscottmiller commented May 18, 2026

Copy link
Copy Markdown
Contributor

Adds the plumbing layer for DLP (Data Loss Prevention) policy enforcement. The coder_dlp_policy Terraform resource is wired through the provisioner protocol and persisted to a new template_version_dlp_policies table. No behavioral change; enforcement gates come in a follow-up PR.

  • Extend provisioner proto with DLPPolicy message and pipe it through CompletedJob.
  • Add template_version_dlp_policies table and SQLC queries.
  • Add coderd/dlppolicy package with ForAgent helper for downstream enforcement.

Depends on coder/terraform-provider-coder#510

Note

Generated by Coder Agents on behalf of @jscottmiller

@jscottmiller
jscottmiller force-pushed the feat/dlp-policy-enforcement branch 2 times, most recently from d3987ac to 03c3d89 Compare May 18, 2026 22:08
Adds a new coderd/dlppolicy package whose ForAgent helper loads the
agent's persisted DLP policy under dbauthz.AsSystemRestricted. Callers
have already authorized the request against the workspace; the policy
lookup is a follow-on system-internal read.

Four enforcement gates are wired in:

  * CLI peering. workspaceAgentClientCoordinate returns 403 when
    ssh_access is false. This is the single chokepoint for coder CLI
    peering, so the toggle is coarse and blocks ssh, port-forward, cp,
    and speedtest together.
  * Web terminal. workspaceapps.Server.workspaceAgentPTY returns 403
    before the WebSocket upgrade when web_terminal_access is false.
  * Dashboard Ports tab. workspaceapps.Server.proxyWorkspaceApp returns
    a "Blocked by workspace policy" HTML page when port_forwarding_access
    is false and the request resolves to a port view.
  * Dashboard app proxy. The same handler returns the same HTML page
    when the resolved app slug is not in allowed_applications.

User-facing strings say "workspace policy" and never include the
policy name; internal names and log fields keep "DLP". Browser-facing
denials render site.RenderStaticErrorPage; CLI and JSON callers get
codersdk.Response 403s.

The fix folded in here (originally adbdbfe) reads slugOrPort and
isPort from the signed appToken instead of app.PortInfo() /
app.AppSlugOrPort, because path-based app routing passes an empty
appurl.ApplicationURL into proxyWorkspaceApp and the parsed values are
not reliable on that path.
@jscottmiller
jscottmiller force-pushed the feat/dlp-policy-enforcement branch from 03c3d89 to e1aada6 Compare May 18, 2026 22:32
- Add DLP ssh_access check in rbacAuthorizer.AuthorizeTunnel to gate
  Coder Desktop connections (same data plane as CLI SSH).
- Move app/PTY DLP enforcement from inline proxy.go gates into
  DBTokenProvider.Issue, which is the single source of truth for both
  primary and workspace-proxy token paths.
- Remove Database field from workspaceapps.ServerOptions (no longer
  needed on proxy, fixes nil-panic).
@jscottmiller jscottmiller changed the title feat: persist and enforce coder_dlp_policy at workspace traffic gates feat: wire and persist coder_dlp_policy from provisioner to database May 20, 2026

Copy link
Copy Markdown
Contributor Author

Splitting into two PRs: plumbing (proto+persist) and enforcement (gates). See replacement PRs below.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant