Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[sdk] --trusted-host Automatically added to pip command in Kubeflow Pipelines #11155

Open
diegolovison opened this issue Aug 30, 2024 · 7 comments

Comments

@diegolovison
Copy link
Contributor

Description: The Kubeflow Pipelines component is currently adding the --trusted-host option to the pip command by default. This occurs because the value is being copied directly from the pip_trusted_hosts configuration.

Security Concern: Using the --trusted-host option disables SSL certificate validation for the specified host, which can expose the system to significant security risks. Specifically, it makes the environment vulnerable to man-in-the-middle (MITM) attacks, where an attacker could intercept and potentially alter the packages being installed. This is particularly concerning in environments that require strict security controls, such as airgapped or production systems.

Expected Behavior: The --trusted-host option should not be automatically added to the pip command unless explicitly configured by the user. The default behavior should enforce SSL certificate validation to ensure secure package installations.

Environment

  • KFP version: 2.8.0

Steps to reproduce

@dsl.component(base_image=common_base_image,
               pip_index_urls=['https://myurl.org/simple'])
def flip_coin() -> str:
    """Flip a coin and output heads or tails randomly."""
    import random

    result = "heads" if random.randint(0, 1) == 0 else "tails"
    print(result)
    return result

Expected result

The output was formated and it is generated by the SDK

if ! [ -x "$(command -v pip)" ]; then
    python3 -m ensurepip || python3 -m ensurepip --user || apt-get install python3-pip
fi

PIP_DISABLE_PIP_VERSION_CHECK=1 python3 -m pip install --quiet --no-warn-script-location \
    --index-url https://myurl.org/simple 'kfp==2.1.3' '--no-deps' \
    'typing-extensions>=3.7.4,<5; python_version<"3.9"' && \
    python3 -m pip install --quiet --no-warn-script-location \
    --index-url https://myurl.org/simple 'package1' 'package2' && \
    "$0" "$@"

Materials and Reference


Impacted by this bug? Give it a 👍.

@HumairAK
Copy link
Collaborator

HumairAK commented Aug 30, 2024

The --trusted-host option should not be automatically added to the pip command unless explicitly configured by the user. The default behavior should enforce SSL certificate validation to ensure secure package installations.

100% for this. While this PR: #11151 at least enables the user to opt-in for the secure option. It is unreasonable to require a user, for each component, enable pip installs in a secure way. We should not be adding extra overhead simply to do something securely.

Given the security concerns here, my preference is that we enable no --trusted-host flag by default, even if it can be a breaking change. My concern is most users do not realize that their pipelines might be doing pip installs insecurely.

If maintainers are adamant we do not break backwards compatibility, my alternative suggestion is to do something similar to this caching PR, whereby we allow changing the default behavior via some global cli flag or env var.

@chensun / @zijianjoy wdyt?

Copy link

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@github-actions github-actions bot added the lifecycle/stale The issue / pull request is stale, any activities remove this label. label Oct 30, 2024
Copy link

This issue has been automatically closed because it has not had recent activity. Please comment "/reopen" to reopen it.

@HumairAK HumairAK reopened this Nov 20, 2024
@github-actions github-actions bot removed the lifecycle/stale The issue / pull request is stale, any activities remove this label. label Nov 21, 2024
Copy link

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@github-actions github-actions bot added the lifecycle/stale The issue / pull request is stale, any activities remove this label. label Jan 21, 2025
@hbelmiro
Copy link
Contributor

/lifecycle frozen

@google-oss-prow google-oss-prow bot added lifecycle/frozen and removed lifecycle/stale The issue / pull request is stale, any activities remove this label. labels Jan 21, 2025
@juliusvonkohout
Copy link
Member

@hbelmiro do we have a security label for Issues/Prs?

@hbelmiro
Copy link
Contributor

hbelmiro commented Jan 22, 2025

@hbelmiro do we have a security label for Issues/Prs?

@juliusvonkohout We haven't.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants