Skip to content

Bug: bootstrap token path lacks rate limiting, lockout, and alerting on failed verifies #77980

@fede-kamel

Description

@fede-kamel

Problem

Audit of the gateway bootstrap-token path turned up a cluster of DoS-shaped issues:

This is the umbrella issue for the bootstrap-token DoS family. Originally filed as a PoC in PR form at #76322 (kept open as the discovery thread); separate fix PRs land each surface piecemeal so review can scope per-change.

Tracking PR

Discovery / PoC: #76322. Per-surface fixes: #77527 (bootstrap-token mutex), #77492 (device-signature CPU).

Metadata

Metadata

Assignees

No one assigned

    Labels

    staleMarked as stale due to inactivity

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions