Skip to main content

Threat model and hardening invariants

Straw assumes every caller, Control, Egress worker, NATS account, Redis instance, JetStream bucket, and receipt store inside one deployment belongs to one trust boundary. It does not isolate mutually hostile tenants.

ThreatEnforced invariantOperator verification
SSRF, metadata ranges, DNS rebinding/CNAME changesDirect-local Egress resolves and validates every dial address. Trusted upstream-proxy pools validate literal targets but delegate hostname DNS to the provider, so local CIDR/CNAME enforcement is unavailable for hostnames.Run destination-policy and Egress tests; configure provider destination ACLs against private, metadata, loopback, and special-use ranges.
Redirect/proxy bypassRedirects remain disabled; proxy pools bind a Control pool claim to one worker profile and always use bounded CONNECT without direct fallback.Use fresh proxy pool IDs, keep trusted_remote_resolution explicit, and deny private/metadata networks at the provider.
Header/request smugglingNames, values, ordered duplicates, lengths, hop-by-hop behavior, frames, and total bodies are validatedKeep reverse proxy parsing strict and do not rewrite signed protocol frames
Credential/log disclosureSeparate request/admin bearer tokens; signed receipt URLs are short-lived; structured logs must omit tokens, headers, URLs, bodies, and object credentialsSearch logs and diagnostic bundles with synthetic canary secrets
NATS subject impersonationSubjects are bounded and protocol messages signed/validatedGive components only required publish/subscribe permissions and TLS credentials
Admin compromiseAdmin authentication is separate from request authentication and should be network-isolatedDo not expose /admin/ or /api/v1/admin/* publicly
Redis loss or stale ownerTTLs, fencing, instance leases, and explicit degraded readiness prevent silent ownership reuseExercise the owned HA failure drill before release
Receipt corruption/replayDeclared size/SHA-256 is checked at completion and consumption; assignment references bind identity and expiryUse least-privilege bucket policy, encryption, lifecycle retention, and clock synchronization
Malicious custom workerA worker is inside the trust boundary but remains bounded by capabilities, flow control, deadlines, and protocol validationIssue distinct NATS credentials; run conformance before admission
Resource exhaustionRequest/response/frame/time/concurrency/object limits are explicit and validatedSet proxy/body limits, container resources, NATS payload limits, and alerts

Security findings are triaged by the security contact in SECURITY.md. Critical/high reachable issues block release; exceptions require a private owner, rationale, compensating control, and expiry. Dependency, CodeQL, secret, image, and vulnerability scans run in CI. See Security for per-profile deployment controls.