Skip to content

About

A simple HTTP proxy that fogs over naughty URLs

Resources

Code of conduct

Contributing

Security policy

Stars

1.4k stars

Watchers

79 watching

Forks

Repository files navigation

Smokescreen Test Coverage Status

Smokescreen is a HTTP CONNECT proxy. It proxies most traffic from Stripe to the external world (e.g., webhooks).

Smokescreen restricts which URLs it connects to:

  • It uses a pre-configured hostname ACL to only allow requests addressed to certain allow-listed hostnames, to ensure that no malicious code is attempting to make requests to unexpected services.
  • It also resolves each domain name that is requested, and ensures that it is a publicly routable IP address and not an internal IP address. This prevents a class of attacks where, for instance, our own webhooks infrastructure is used to scan Stripe’s internal network. Smokescreen can also be further configured to allow or deny specific IP addresses or ranges.

Smokescreen also allows us to centralize egress from Stripe, allowing us to give financial partners stable egress IP addresses and abstracting away the details of which Stripe service is making the request.

In typical usage, clients contact Smokescreen over mTLS. Upon receiving a connection, Smokescreen authenticates the client's certificate against a configurable set of CAs and CRLs, extracts the client's identity, and checks the client's requested CONNECT destination against a configurable per-client ACL.

By default, Smokescreen will identify clients by the "common name" in the TLS certificate they present, if any. The client identification function can also be easily replaced; more on this in the usage section.

Dependencies

Smokescreen uses go modules to manage dependencies. The linked page contains documentation, but some useful commands are reproduced below:

  • Adding a dependency: go build go test go mod tidy will automatically fetch the latest version of any new dependencies. Running go mod vendor will vendor the dependency.
  • Updating a dependency: go get dep@v1.1.1 or go get dep@commit-hash will bring in specific versions of a dependency. The updated dependency should be vendored using go mod vendor.

Smokescreen uses a custom fork of goproxy to allow us to support context passing and setting granular timeouts on proxy connections.

Generally, Smokescreen will only support the two most recent Go versions. See the test configuration for details.

Building without Prometheus

Prometheus support is included by default:

go build .

Note: Prometheus is currently opt-out. In a future release, it will become opt-in; consumers that require Prometheus should account for that build change.

To build a binary without Prometheus packages in its compiled dependency graph, pass the smokescreen_no_prometheus build tag:

go build -tags=smokescreen_no_prometheus .

The no-Prometheus binary accepts the usual non-Prometheus configuration, but fails during startup configuration if --expose-prometheus-metrics is set.

Usage

CLI

Run go run . --help (or smokescreen --help for an installed binary) for the current CLI reference. Here are the available options:

   --help, -h                                  Show this help text.
   --config-file FILE                          Load configuration from FILE.  Command line options override values in the file.
   --listen-ip IP                              Listen on interface with address IP.
                                                 This argument is ignored when running under Einhorn. (default: any)
   --listen-port PORT                          Listen on port PORT.
                                                 This argument is ignored when running under Einhorn. (default: 4750)
   --timeout DURATION                          Time out after DURATION when connecting. (default: 10s)
   --proxy-protocol                            Enable PROXY protocol support.
   --allow-self-connections                    Allow connections to local interface addresses on all ports, subject to normal IP and ACL checks. (default: false)
   --most-specific-ip-rules                    Resolve overlapping IP rules by longest prefix, then port specificity; deny wins ties. (default: false)
   --unsafe-ip-filter-bypassed-domain DOMAIN    Bypass IP filters for a destination hostname or *.domain glob. Repeatable.
                                                 ACL and self-connection checks still apply. Trust this domain's DNS.
   --deny-range RANGE                          Add RANGE(in CIDR notation) to list of blocked IP ranges.  Repeatable.
   --allow-range RANGE                         Add RANGE (in CIDR notation) to list of allowed IP ranges.  Repeatable.
   --deny-address value                        Add IP[:PORT] to list of blocked IPs.  Repeatable.
   --allow-address value                       Add IP[:PORT] to list of allowed IPs.  Repeatable.
   --egress-acl-file FILE                      Validate egress traffic against FILE
   --expose-prometheus-metrics                 Exposes metrics via a Prometheus scrapable endpoint.
   --prometheus-metrics-format FORMAT          Metric format: legacy, dual, or v2. (default: "legacy")
                                                 Requires `--expose-prometheus-metrics` to be set.
   --prometheus-endpoint ENDPOINT              Specify endpoint to host Prometheus metrics on. (default: "/metrics")
                                                 Requires `--expose-prometheus-metrics` to be set.
   --prometheus-listen-ip IP                   Listen for Prometheus metrics on interface with address IP. (default: "0.0.0.0")
                                                 Requires `--expose-prometheus-metrics` to be set.
   --prometheus-port PORT                      Specify port to host Prometheus metrics on. (default: "9810")
                                                 Requires `--expose-prometheus-metrics` to be set.
   --resolver-address ADDRESS                  Make DNS requests to ADDRESS (IP:port).  Repeatable.
   --statsd-address ADDRESS                    Send metrics to statsd at ADDRESS (IP:port). (default: "127.0.0.1:8200")
   --tls-server-bundle-file FILE               Authenticate to clients using key and certs from FILE
   --tls-client-ca-file FILE                   Validate client certificates using Certificate Authority from FILE
   --tls-crl-file FILE                         Verify validity of client certificates against Certificate Revocation List from FILE
   --additional-error-message-on-deny MESSAGE  Display MESSAGE in the HTTP response if proxying request is denied
   --disable-acl-policy-action POLICY ACTION   Disable usage of a POLICY ACTION such as "open" in the egress ACL
   --stats-socket-dir DIR                      Enable connection tracking. Will expose one UDS in DIR going by the name of "track-{pid}.sock".
                                                 This should be an absolute path with all symlinks, if any, resolved.
   --stats-socket-file-mode FILE_MODE          Set the filemode to FILE_MODE on the statistics socket (default: "700")
   --unsafe-allow-private-ranges               Allow private IP ranges by default. (default: false)
   --upstream-http-proxy-addr ADDRESS           Set Smokescreen's upstream HTTP proxy address.
   --upstream-https-proxy-addr ADDRESS          Set Smokescreen's upstream HTTPS proxy address.
   --max-concurrent-requests value             Maximum simultaneous requests. 0 = unlimited (default: 0)
   --max-request-rate value                    Maximum requests per second. 0 = unlimited (default: 0)
   --max-request-burst value                   Maximum burst capacity. Must be > max-request-rate when specified.
                                                 Omit to use default (2x max-request-rate).
   --max-concurrent-connect-tunnels value      Maximum number of concurrent CONNECT tunnels.
                                                 Unlike max-concurrent-requests, this limits actual long-lived connections.
                                                 0 = unlimited (default: 0)
   --dns-timeout DURATION                      Maximum time to wait for DNS resolution (default: 5s)
   --version, -v                               print the version

Configuration files

Load the main YAML configuration with --config-file. Explicit CLI options override values in the file. Unknown YAML fields are rejected. YAML names can differ from CLI flags: for example, --listen-ip maps to ip, --listen-port to port, --timeout to connect_timeout, and --egress-acl-file to acl_file. The main configuration and hostname ACL are separate files; the ACL has its own version, services, and default fields.

ip: "127.0.0.1"
port: 4750
connect_timeout: 10s
acl_file: "acl.yaml"

See the YAML configuration fields for supported keys and Development.md for complete local examples. Prometheus and upstream proxy settings are configured through CLI flags or the Go API; the main YAML loader does not accept them.

Prometheus metrics

Enable scraping with --expose-prometheus-metrics. The metrics listener defaults to 0.0.0.0:9810 with path /metrics, independently of the proxy's listen address. Use --prometheus-listen-ip, --prometheus-port, and --prometheus-endpoint to change it. For example, to bind metrics to loopback:

smokescreen --expose-prometheus-metrics --prometheus-listen-ip=127.0.0.1

Select the format with --prometheus-metrics-format=legacy|dual|v2:

  • legacy (default) preserves existing names, units, and histogram buckets.
  • v2 uses the smokescreen_ prefix, seconds for timings, and appropriate byte and connection-duration buckets. See the metric definitions for mappings.
  • dual publishes both formats so you can deploy first and migrate your observability stack later.

Embedded users can pass "dual" or "v2" as the optional final argument to SetupPrometheus or NewPrometheusMetricsClient.

Client Identification

In order to override how Smokescreen identifies its clients, you must:

  • Create a new go project
  • Import Smokescreen
  • Create a Smokescreen configuration using cmd.NewConfiguration
  • Replace smokescreen.Config.RoleFromRequest with your own func(request *http.Request) (string, error)
  • Call smokescreen.StartWithConfig
  • Build your new project and use the resulting executable through its CLI

Here is a fictional example that would split a client certificate's OrganizationalUnit on commas and use the first particle as the service name.

package main

import (...)

func main() {
	// Here is an opportunity to pass your logger
	conf, err := cmd.NewConfiguration(nil, nil)
	if err != nil {
		log.Fatal(err)
	}
	if conf == nil {
		os.Exit(1)
	}

	conf.RoleFromRequest = func(request *http.Request) (string, error) {
		fail := func(err error) (string, error) { return "", err }

		subject := request.TLS.PeerCertificates[0].Subject
		if len(subject.OrganizationalUnit) == 0 {
			fail(fmt.Errorf("warn: Provided cert has no 'OrganizationalUnit'. Can't extract service role."))
		}
		return strings.SplitN(subject.OrganizationalUnit[0], ".", 2)[0], nil
	}

	smokescreen.StartWithConfig(conf, nil)
}

IP Filtering

To control the routing of requests to specific IP addresses or IP blocks, use the deny-address, allow-address, deny-range, and allow-range options in the config.

Overlapping explicit rules default to allow-first: any matching allow rule wins over every matching deny rule. To opt into specificity-based precedence:

most_specific_ip_rules: true

The equivalent CLI flag is --most-specific-ip-rules. Go consumers can set Config.MostSpecificIPRules = true. The default is false, preserving allow-first. An explicitly supplied CLI value overrides YAML, including --most-specific-ip-rules=false to disable a YAML-enabled setting.

In most-specific mode, the longest matching CIDR prefix wins. At equal prefix lengths, a port-specific rule wins over an all-port rule; deny wins remaining ties. Address rules are single-IP networks (/32 or /128). Rule order has no effect. For example, denying 10.0.0.5 overrides allowing 10.0.0.0/24, while allowing 10.0.0.5:443 overrides denying 10.0.0.0/8 for that IP and port.

Ranges match all ports; addresses accept an optional port (IPv6 with a port uses brackets, e.g. [fd00::5]:443). Explicit allows can bypass default IP safety blocks, but hostname ACL checks still apply. Allow rules do not create an exclusive allowlist: unmatched destinations follow the default safety checks. Each DNS answer is evaluated separately; another eligible answer can still be selected when one answer is denied. The self-connection guard takes precedence under both policies.

Smokescreen denies connections to addresses in Config.LocalIPs on every port by default, even if an address is explicitly allowed. StartWithConfig populates LocalIPs from the host's network interfaces unless it is already set.

To disable the self-connection guard, set --allow-self-connections, use the YAML setting below, or set Config.AllowSelfConnections = true after calling NewConfig():

allow_self_connections: true  # defaults to false

With this setting enabled, connections to the proxy host on all ports, including Smokescreen's listening port, follow normal IP and hostname ACL checks and may be allowed.

Use the repeatable --unsafe-ip-filter-bypassed-domain flag, or the main configuration setting below, to bypass IP filtering for trusted destination hostnames:

unsafe_ip_filter_bypassed_domains:
  - login.internal.example.com
  - "*.internal.example.com"

This does not bypass ACL checks and doesn't allow self-connections unless allow_self_connections is also true.

Rate Limiting

Smokescreen supports rate and concurrency limiting to protect against overload:

Option Description
max-concurrent-requests Limits simultaneous in-flight requests. Excess requests receive 503 Service Unavailable.
max-request-rate Limits requests per second using a token bucket algorithm. Excess requests receive 429 Too Many Requests.
max-request-burst Sets token bucket capacity. Must be greater than max-request-rate. Defaults to 2x the rate if omitted.
max-concurrent-connect-tunnels Limits the number of active CONNECT tunnels (long-lived connections). Unlike max-concurrent-requests which only tracks request processing time, this limits actual tunnel connections and prevents resource exhaustion from unbounded CONNECT tunnels. Excess requests receive 429 Too Many Requests.

Note: max-concurrent-requests limits the number of requests being processed, while max-concurrent-connect-tunnels limits the number of active tunnel connections. For CONNECT requests, the request processing completes quickly but the tunnel connection remains open. Use both settings together for complete protection against resource exhaustion.

Example (CLI):

smokescreen --max-concurrent-requests=100 --max-request-rate=50 --max-concurrent-connect-tunnels=50

Example (YAML):

YAML duration values must include a unit accepted by Go (for example, 0s, 500ms, or 10s). Bare numbers are not valid duration values.

connect_timeout: 10s  # defaults to 10s; set to 0s to disable the timeout
max_concurrent_requests: 100
max_request_rate: 50
max_request_burst: 150  # optional, defaults to 2x rate
max_concurrent_connect_tunnels: 50  # limits active CONNECT tunnel connections

Hostname ACLs

A hostname ACL can be described in a YAML formatted file. The ACL, at its top-level, contains a list of services as well as a default behavior.

Three policies are supported:

Policy Behavior
Open Allows all traffic for this service
Report Allows all traffic for this service and warns if client accesses a remote host which is not in the list
Enforce Only allows traffic to remote hosts provided in the list. Will warn and deny if remote host is not in the list

⚠️ The ACL is only applied to hostnames as they appear in the request! If you want to allow or deny traffic based on the destination IP address after DNS resolution, you should be using the config options instead (see the IP Filtering section above).

A host can be specified with or without a wildcard, and a glob may contain at most one wildcard. The host must be in Punycode to prevent ambiguity.

  • A leading *. matches one or more subdomain labels: *.example.com matches api.example.com and a.b.example.com, but not example.com.
  • A * spanning a label other than the leftmost one matches exactly one label: access-analyzer.*.amazonaws.com matches access-analyzer.us-west-2.amazonaws.com, but not access-analyzer.a.b.amazonaws.com.
  • A * after a literal prefix within a label matches one or more characters in that label: api*.example.com matches api-east.example.com, but not api.example.com, api.a.example.com, or a.api-east.example.com.

Apart from the leading *., a wildcard never crosses a .. The labels to its right must form a registrable domain rather than a public suffix such as com, co.uk, or github.io, and the wildcard label must be lowercase ASCII.

Outside of the global_deny_list, these wildcards also only match hosts in the same registrable domain as the labels to their right, according to the public suffix list. This prevents access-analyzer.*.amazonaws.com from matching access-analyzer.s3.amazonaws.com, an S3 bucket that anyone can claim. It also means that hosts that are public suffixes themselves, such as s3.us-west-2.amazonaws.com, or that sit directly under one, such as access-analyzer.us-east-1.amazonaws.com, never match a wildcard; specify such hosts explicitly. When a request is denied or reported only because of this check, the decision reason in the logs and in the response to the client says so:

rule has enforce policy; wildcard 'sts.*.amazonaws.com' was not applied because 'us-east-1.amazonaws.com' is on the public suffix list

To turn the check off for an ACL, set unsafe_allow_wildcards_across_public_suffixes: true at its top level. Wildcards in that ACL's allow lists then also match hosts under public suffixes, including hosts that belong to other tenants, such as S3 buckets. Validation is unchanged.

The global_deny_list always skips this check. There, matching too much only blocks extra hosts, while matching too little would let denied traffic through. Because a wildcard never matches an empty string or a subdomain, denying api*.example.com blocks neither api.example.com nor v1.api-east.example.com; deny those separately if needed.

host valid
example.com yes
*.example.com yes
access-analyzer.*.amazonaws.com yes
api*.example.com yes
web*-canary.example.com yes
web.qa-*.internal.example.com yes
*.*.example.com no
*.api*.example.com no
*example.com no
*-canary.example.com no
ex*ample.com no
login.*.com no
foo*.github.io no
éxämple.com no
example.* hell no

Here is a sample ACL.

Global Hostname Allow/Deny Lists

Optionally, you may specify a global allow list and a global deny list for hostnames in your ACL config.

These lists override the policy, but do not override the allowed_domains list for each role.

For example, specifying example.com in your global_allow_list will allow traffic for that domain on that role, even if that role is set to enforce and does not specify example.com in its allowed domains.

Similarly, specifying malicious.com in your global_deny_list will deny traffic for that domain on a role, even if that role is set to report or open. However, if the host specifies malicious.com in its allowed_domains, traffic to malicious.com will be allowed on that role, regardless of policy.

⚠️ The global_deny_list will only block specific hostnames, not entire destinations. For example, if malicious.com is in the global_deny_list but the IP address that it resolves to is not, roles with an open policy will still be able to access the destination by using its IP address directly. For this reason, we recommend using allowlists instead of denylists whenever it is possible to do so, and blocking IP addresses via config options, not the ACL (see the IP Filtering section above).

If a domain matches both the global_allow_list and the global_deny_list, the global_deny_list behavior takes priority.

Here is a sample ACL specifying these options.

Development and Testing

See Development.md

Contributors

  • Aditya Mukerjee
  • Andreas Fuchs
  • Andrew Dunham
  • Andrew Metcalf
  • Aniket Joshi
  • Ben Ransford
  • Carl Jackson
  • Craig Shannon
  • Evan Broder
  • Marc-André Tremblay
  • Ryan Koppenhaver
  • Harold Simpson

About

A simple HTTP proxy that fogs over naughty URLs

Resources

Code of conduct

Contributing

Security policy

Stars

1.4k stars

Watchers

79 watching

Forks

Releases

Packages

Used by

Contributors

Languages