feat: wire and persist coder_dlp_policy from provisioner to database - #25464
Closed
jscottmiller wants to merge 4 commits into
Closed
feat: wire and persist coder_dlp_policy from provisioner to database#25464jscottmiller wants to merge 4 commits into
jscottmiller wants to merge 4 commits into
Conversation
jscottmiller
force-pushed
the
feat/dlp-policy-enforcement
branch
2 times, most recently
from
May 18, 2026 22:08
d3987ac to
03c3d89
Compare
Adds a new coderd/dlppolicy package whose ForAgent helper loads the
agent's persisted DLP policy under dbauthz.AsSystemRestricted. Callers
have already authorized the request against the workspace; the policy
lookup is a follow-on system-internal read.
Four enforcement gates are wired in:
* CLI peering. workspaceAgentClientCoordinate returns 403 when
ssh_access is false. This is the single chokepoint for coder CLI
peering, so the toggle is coarse and blocks ssh, port-forward, cp,
and speedtest together.
* Web terminal. workspaceapps.Server.workspaceAgentPTY returns 403
before the WebSocket upgrade when web_terminal_access is false.
* Dashboard Ports tab. workspaceapps.Server.proxyWorkspaceApp returns
a "Blocked by workspace policy" HTML page when port_forwarding_access
is false and the request resolves to a port view.
* Dashboard app proxy. The same handler returns the same HTML page
when the resolved app slug is not in allowed_applications.
User-facing strings say "workspace policy" and never include the
policy name; internal names and log fields keep "DLP". Browser-facing
denials render site.RenderStaticErrorPage; CLI and JSON callers get
codersdk.Response 403s.
The fix folded in here (originally adbdbfe) reads slugOrPort and
isPort from the signed appToken instead of app.PortInfo() /
app.AppSlugOrPort, because path-based app routing passes an empty
appurl.ApplicationURL into proxyWorkspaceApp and the parsed values are
not reliable on that path.
jscottmiller
force-pushed
the
feat/dlp-policy-enforcement
branch
from
May 18, 2026 22:32
03c3d89 to
e1aada6
Compare
- Add DLP ssh_access check in rbacAuthorizer.AuthorizeTunnel to gate Coder Desktop connections (same data plane as CLI SSH). - Move app/PTY DLP enforcement from inline proxy.go gates into DBTokenProvider.Issue, which is the single source of truth for both primary and workspace-proxy token paths. - Remove Database field from workspaceapps.ServerOptions (no longer needed on proxy, fixes nil-panic).
Contributor
Author
|
Splitting into two PRs: plumbing (proto+persist) and enforcement (gates). See replacement PRs below. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds the plumbing layer for DLP (Data Loss Prevention) policy enforcement. The
coder_dlp_policyTerraform resource is wired through the provisioner protocol and persisted to a newtemplate_version_dlp_policiestable. No behavioral change; enforcement gates come in a follow-up PR.DLPPolicymessage and pipe it throughCompletedJob.template_version_dlp_policiestable and SQLC queries.coderd/dlppolicypackage withForAgenthelper for downstream enforcement.Depends on coder/terraform-provider-coder#510
Note
Generated by Coder Agents on behalf of @jscottmiller