Narrow the egress claims to non-public metadata addresses
check / check (push) Successful in 3m56s

The ALLOWED_EGRESS_CIDRS startup warning no longer calls the listed
blocks private/reserved, and says a public cloud metadata address such
as 168.63.129.16 is reachable once it, or a block covering it, is
listed. The README, the AllowedEgressCIDRs field comment and the
checkIP doc comment now say the allowlist cannot open metadata
endpoints at non-public addresses, not every metadata endpoint.

Model: opus-5-5
This commit is contained in:
2026-09-29 07:54:14 +00:00
parent e5d245fbc8
commit 1a642844ac
4 changed files with 30 additions and 25 deletions
+1 -1
View File
@@ -323,7 +323,7 @@ func (g *Guard) allows(ip net.IP) bool {
//
// 1. alwaysBlockedNetworks is refused before the allowlist is
// consulted, so no configured CIDR reaches link-local or a
// cloud instance metadata endpoint.
// cloud metadata endpoint at a non-public address.
// 2. The allowlist is consulted next, so a listed private
// network becomes reachable.
// 3. Everything else keeps the default blocklist's answer.