The ALLOWED_EGRESS_CIDRS startup warning no longer calls the listed blocks private/reserved, and says a public cloud metadata address such as 168.63.129.16 is reachable once it, or a block covering it, is listed. The README, the AllowedEgressCIDRs field comment and the checkIP doc comment now say the allowlist cannot open metadata endpoints at non-public addresses, not every metadata endpoint. Model: opus-5-5
This commit is contained in:
@@ -323,7 +323,7 @@ func (g *Guard) allows(ip net.IP) bool {
|
||||
//
|
||||
// 1. alwaysBlockedNetworks is refused before the allowlist is
|
||||
// consulted, so no configured CIDR reaches link-local or a
|
||||
// cloud instance metadata endpoint.
|
||||
// cloud metadata endpoint at a non-public address.
|
||||
// 2. The allowlist is consulted next, so a listed private
|
||||
// network becomes reachable.
|
||||
// 3. Everything else keeps the default blocklist's answer.
|
||||
|
||||
Reference in New Issue
Block a user