Skip to content

Conversation

@daveads
Copy link
Contributor

@daveads daveads commented Jul 8, 2025

CRE rule NGINX Ingress ConfigMap size limit exceeded detection (CRE-2025-0120)

Detects NGINX Ingress Controller failures when ConfigMap exceeds Kubernetes' 1MB limit. Progressive accumulation of server blocks from Ingress resources causes configuration to breach size threshold, preventing new services from being routed and causing silent production outages.

/claim #96
closes #96

X post Post

Reproduction setup with k3s + ConfigMap generator
Reproducible test setup (Maintainers invited): nginx-configmap-size-limit

Live CRE Link: CRE PLAYGROUND LINK

# Run test
./reproduce.sh

@daveads
Copy link
Contributor Author

daveads commented Jul 8, 2025

Screen.Recording.2025-07-08.at.8.58.38.AM.mov

@tonymeehan tonymeehan merged commit 746b94d into prequel-dev:main Jul 9, 2025
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Multiple Winners] Ingress-nginx: Reproduce A High-Severity Failure & Write a Detection Rule [Submit by July 6 11:59 pm ET]

2 participants