Yandex Builds Secure KVM Access for BareMetal Servers with IPMI Proxy and Network Isolation
Yandex BareMetal engineers have published a detailed account of how they enabled external customers to use KVM over IPMI without exposing the management network to the kinds of attacks that previously compromised an internal cloud of 25,000 hosts.
The service must deliver two critical capabilities: installation of custom operating systems and recovery when network settings are misconfigured. Both require remote console and virtual media access that legacy BMC firmware only provides through proprietary protocols, often Java Web Start applications signed with outdated hashes such as md4.
To unify access, the team created IPMI Proxy. Each user session launches a lightweight Docker container containing only the components required for a given hardware platform: an XWindow system, a VNC server, a legacy Java runtime with relaxed security settings, Firefox for HTML5 KVM, and optional Java applications for ISO mounting. The container converts the vendor-specific protocol into standard VNC, which noVNC then renders inside the Yandex Cloud console.
Because many BMCs speak only IPv4 while Yandex infrastructure uses IPv6, the team deployed IPMI Router servers running the jool kernel module for stateless NAT64 translation. Each IPv4 address is mapped to a predictable IPv6 address by preserving the last three octets, allowing DHCP to remain stateless and eliminating the need to synchronize lease databases during VRRP failover.
Security controls were added at every layer. Switch ACLs forward frames only toward IPMI Router MAC addresses. 802.1X authentication prevents MAC spoofing. An eBPF program on the routers drops any packet whose IPv4 address does not match the expected MAC, blocking ARP poisoning. Inside the proxy containers, network rules enforced by ip6tables restrict outbound connections to the single authorized BMC.
ISO images stored in S3 are mounted from outside the container as volumes rather than granting the container direct S3 access. Permission checks performed every ten seconds through the Yandex Cloud IAM model ensure that only users with current server-management rights can maintain an active KVM session.
The resulting architecture normalizes KVM and virtual media across heterogeneous hardware while keeping the IPMI fabric isolated from both external attackers and compromised neighboring servers.
Related articles
Yandex Disk Files Become Partially Inaccessible After Sasovo Data Center Incident
A detailed user report reveals that approximately one percent of files stored on Yandex Disk are currently unavailable for download following reported incidents at the Sasovo data center. The problems manifest in three distinct states: missing thumbnails with downloadable originals, visible thumbnails with inaccessible originals returning 504 Gateway Time-out errors, and cases where both thumbnails and originals fail to load. Technical analysis using curl requests traced the failures to specific storage nodes such as s418klg.storage.yandex.net, indicating that some data shards may reside in affected infrastructure while others remain operational. Yandex support requested original files for diagnosis but closed the ticket without providing an official explanation or confirming data integrity. The author emphasizes that the issue affects files across both the Photos and Files sections and recommends maintaining offline backups due to the lack of guaranteed availability during data center failures.
Keurig K-Supreme Smart Coffee Maker Generates Nearly 1 TB of Outbound Traffic in Ten Days
A Keurig K-Supreme Smart coffee maker unexpectedly produced around 1008 GB of outgoing traffic over ten days, overwhelming a home UniFi access point while generating only 9.94 GB of inbound data. The device had been placed on a separate network segment, yet the traffic remained largely internal to the home LAN rather than traversing the internet connection. The anomaly was discovered by user Nomad while assisting family members with network maintenance through the UniFi dashboard. After the coffee maker was powered off, the issue could not be reproduced in subsequent testing, and no packet captures were available to determine the content or root cause of the traffic. The model requires internet connectivity for remote control, scheduling, capsule recognition, and automatic reordering of coffee supplies. No similar incidents have been reported by other users, and the manufacturer has not issued any statement regarding the event.
Hash Functions Part 1: Core Properties, Security Requirements and Practical Applications
The article provides a detailed introduction to hash functions, explaining how they map arbitrary-length input to fixed-length output while satisfying three fundamental security properties. It covers preimage resistance, second preimage resistance, and collision resistance, along with the avalanche effect that makes even minor input changes produce unrecognizable output. The text explains why a 256-bit digest is required to achieve 128-bit collision resistance, referencing the birthday paradox and its implications for MD5 and SHA-1. Practical guidance includes using OpenSSL for hashing, applying hashes in commitment schemes, enforcing subresource integrity on web pages, and securely storing passwords with Argon2 and bcrypt. The post emphasizes that hash functions alone do not guarantee integrity without proper transmission of the digest and announces a follow-up on SHA-2 and SHA-3 internals.
Digital Twins Enable Pre-Deployment Testing and Post-Change Control in Complex Multi-Vendor Networks
UserGate and Hadal Project experts presented a joint approach at Saint HighLoad++ that combines physical labs, emulation, and simulation into a single lifecycle for validating network changes. The method addresses recurring failures such as IPsec tunnel outages after routine software updates that pass vendor checks yet break branch connectivity. Three complexity sources—multi-vendor environments, historical configuration debt, and continuous dynamic updates—are mitigated by maintaining an always-current network model. Physical laboratories provide hardware-level accuracy for critical devices, while uInfraTwin emulation allows rapid, repeatable testing of configuration scenarios with traffic generators. Simulation tools including Batfish, Hadal, Forward Networks, and IP Fabric deliver end-to-end reachability analysis across tens of thousands of nodes without sending test traffic on production networks. The integrated digital twin continuously updates from live infrastructure, feeds selected segments into safe test environments, and verifies policy compliance after deployment.