Narrow the egress claims to non-public metadata addresses
check / check (push) Successful in 3m56s

The ALLOWED_EGRESS_CIDRS startup warning no longer calls the listed
blocks private/reserved, and says a public cloud metadata address such
as 168.63.129.16 is reachable once it, or a block covering it, is
listed. The README, the AllowedEgressCIDRs field comment and the
checkIP doc comment now say the allowlist cannot open metadata
endpoints at non-public addresses, not every metadata endpoint.

Model: opus-5-5
This commit is contained in:
2026-09-29 07:54:14 +00:00
parent e5d245fbc8
commit 1a642844ac
4 changed files with 30 additions and 25 deletions
+7 -6
View File
@@ -834,12 +834,13 @@ func TestEgressAllowlistWarning(t *testing.T) {
// to be able to read back which networks are open.
assert.Contains(t, logged, "10.0.0.0/8")
assert.Contains(t, logged, "127.0.0.0/8")
// What stays shut. Asserted on the clause naming the
// wider set rather than on "Link-local" alone, so the
// string cannot narrow back to link-local only while
// the always-blocked set covers ULA, CGNAT and two
// public metadata addresses as well.
assert.Contains(t, logged, "metadata endpoints outside it")
// What stays shut is the whole unconditional set, not
// link-local alone; a public metadata address is not in
// it, so a listed block covering it opens it.
assert.Contains(t, logged, "blocked unconditionally")
assert.Contains(t, logged, "168.63.129.16 is reachable")
// The listed blocks need not be private or reserved.
assert.NotContains(t, logged, "private/reserved")
})
}
}