Slackbot
06/20/2022, 10:01 AMAugustin Lafanechere (Airbyte)
06/20/2022, 12:23 PMAugustin Lafanechere (Airbyte)
06/20/2022, 12:23 PMEugene Krall
06/20/2022, 12:31 PMAugustin Lafanechere (Airbyte)
06/20/2022, 12:32 PMEugene Krall
06/20/2022, 12:33 PMAugustin Lafanechere (Airbyte)
06/20/2022, 12:34 PMEugene Krall
06/20/2022, 12:37 PMAugustin Lafanechere (Airbyte)
06/20/2022, 12:39 PMit's impossible for airbyte to created new VM instances so I can get it off the equationAirbyte itself does not provision any infrastructure. This why I asked for your deployment method, a badly configured K8S cluster could lead to unlimited node creation, but again this is not something managed by Airbyte.
Augustin Lafanechere (Airbyte)
06/20/2022, 12:45 PMEugene Krall
06/20/2022, 12:46 PMEugene Krall
06/20/2022, 12:47 PMAugustin Lafanechere (Airbyte)
06/20/2022, 12:50 PMEugene Krall
06/20/2022, 12:53 PMAugustin Lafanechere (Airbyte)
06/20/2022, 12:57 PMpod
occurrences in your screenshotEugene Krall
06/20/2022, 1:09 PMEugene Krall
06/20/2022, 1:11 PMAugustin Lafanechere (Airbyte)
06/20/2022, 1:35 PMAugustin Lafanechere (Airbyte)
06/20/2022, 1:36 PMWe are running Airbyte version on our own servers and we deployed it using Docker.Yes sorry the pod probably refer to internal Google namespace.
Augustin Lafanechere (Airbyte)
06/20/2022, 1:42 PMEugene Krall
06/20/2022, 1:47 PMEugene Krall
06/20/2022, 1:51 PMAugustin Lafanechere (Airbyte)
06/20/2022, 1:56 PMEugene Krall
06/20/2022, 2:00 PMAugustin Lafanechere (Airbyte)
06/20/2022, 2:10 PMjudging by the activity name it's somehow connected with data insertionThe activity you see in the screenshot is not data insertion but bulk creation of GCP instances. As far as I know it's not something required in Airbyte realm, neither by Airbyte platform itself or the source and destination connector you are using. I wrote to our technical team to make sure that my assertions are correct. From my standpoint I'm under the impression that the GCP instances on which you run Airbyte got compromised and someone was able to run this bulk creation of instances for malicious activity. I can't be 💯 sure of this if you don't get more details about what is (or was) running on the new GCP instances.
Eugene Krall
06/20/2022, 2:12 PMAugustin Lafanechere (Airbyte)
06/20/2022, 2:14 PMsendpulse-backend
service account is not a default service account that GCP provisions for a new VM. Did you assign this existing sendpulse-backend
service account to your Airbyte VM ?Eugene Krall
06/20/2022, 2:19 PMEugene Krall
06/20/2022, 2:19 PMMarcos Marx (Airbyte)
06/20/2022, 2:25 PMEugene Krall
06/20/2022, 3:28 PMAugustin Lafanechere (Airbyte)
06/20/2022, 3:30 PMAugustin Lafanechere (Airbyte)
06/20/2022, 4:15 PMEugene Krall
06/20/2022, 4:17 PMAugustin Lafanechere (Airbyte)
06/20/2022, 4:18 PMAugustin Lafanechere (Airbyte)
06/20/2022, 4:25 PMEven though it's not accessible to the outside world and runs locally on our servers with access through a private VPNIf you are confident about your networking set up you should double check the service account file did not leak. You might have committed it on a public repo?
Augustin Lafanechere (Airbyte)
06/20/2022, 4:32 PM