diff --git a/README.md b/README.md index 5729606..90b3614 100644 --- a/README.md +++ b/README.md @@ -162,6 +162,14 @@ public cloud metadata addresses: currently only `168.63.129.16`, Azure's WireServer, which serves an Azure VM its credentials. Because it is a public address, listing it in `ALLOWED_EGRESS_CIDRS` reopens it. +That is all the default blocklist covers: private and reserved space, +plus public addresses that serve cloud credentials. A cloud provider's +other services on public addresses are not refused — IBM Cloud's +`161.26.0.0/16` and `166.8.0.0/14`, for example, which carry its DNS +resolvers, time servers and package mirrors. They serve no credentials, +reaching them can be a legitimate delivery, and every cloud has some, so +a partial list would promise coverage it does not give. + That default is also inconvenient for the thing webhooker is mostly for: taking a public webhook and forwarding it to something on your own network. A container on the same Docker network, a box on `10.x`, a diff --git a/internal/delivery/ssrf.go b/internal/delivery/ssrf.go index 0fa73b3..9970dd7 100644 --- a/internal/delivery/ssrf.go +++ b/internal/delivery/ssrf.go @@ -43,6 +43,12 @@ var ( // permit specific blocks out of this set with // ALLOWED_EGRESS_CIDRS; see Guard. // +// A public address belongs here only if it serves cloud +// credentials; a provider's other services on public addresses, +// such as its DNS resolvers or package mirrors, stay out, since +// reaching them can be legitimate and no list of them could be +// complete. +// //nolint:gochecknoglobals // package-level network list is appropriate here var blockedNetworks []*net.IPNet