State what the default blocklist covers (closes #244)
check / check (push) Successful in 5m21s

The default blocklist covers the IPv4 private and reserved ranges, IPv6
loopback, unique local and link-local addresses, and public addresses
that serve cloud credentials. A provider's other services on public
addresses, such as 161.26.0.0/16 and 166.8.0.0/14, are deliberately not
on it: they serve no credentials, reaching them can be legitimate, and
every cloud has some, so a partial list would promise coverage it does
not give.

The README's egress section and the comment above blockedNetworks now
state this rule, so nobody infers wider coverage and a future candidate
can be accepted or refused against it. No list change.

Model: opus-5-5
This commit is contained in:
2026-10-01 18:47:23 +00:00
committed by sneak
parent b79e4649a1
commit 1f22ab2b65
2 changed files with 17 additions and 0 deletions
+11
View File
@@ -162,6 +162,17 @@ public cloud metadata addresses: currently only `168.63.129.16`, Azure's
WireServer, which serves an Azure VM its credentials. Because it is a WireServer, which serves an Azure VM its credentials. Because it is a
public address, listing it in `ALLOWED_EGRESS_CIDRS` reopens it. public address, listing it in `ALLOWED_EGRESS_CIDRS` reopens it.
That is all the default blocklist covers: the IPv4 private and reserved
ranges; of IPv6, only loopback (`::1`), unique local addresses
(`fc00::/7`) and link-local addresses (`fe80::/10`); and public
addresses that serve cloud credentials. A cloud provider's other
services on public addresses are not refused. IBM Cloud, for example,
serves its DNS resolvers, package mirrors, time servers and object
storage on `161.26.0.0/16`, and the private endpoints of its own cloud
services on `166.8.0.0/14`. They serve no credentials, reaching them
can be a legitimate delivery, and every cloud has some, so a partial
list would promise coverage it does not give.
That default is also inconvenient for the thing webhooker is mostly That default is also inconvenient for the thing webhooker is mostly
for: taking a public webhook and forwarding it to something on your own for: taking a public webhook and forwarding it to something on your own
network. A container on the same Docker network, a box on `10.x`, a network. A container on the same Docker network, a box on `10.x`, a
+6
View File
@@ -43,6 +43,12 @@ var (
// permit specific blocks out of this set with // permit specific blocks out of this set with
// ALLOWED_EGRESS_CIDRS; see Guard. // ALLOWED_EGRESS_CIDRS; see Guard.
// //
// A public address belongs here only if it serves cloud
// credentials; a provider's other services on public addresses,
// such as its DNS resolvers or package mirrors, stay out, since
// reaching them can be legitimate and no list of them could be
// complete.
//
//nolint:gochecknoglobals // package-level network list is appropriate here //nolint:gochecknoglobals // package-level network list is appropriate here
var blockedNetworks []*net.IPNet var blockedNetworks []*net.IPNet