State what the default blocklist covers (closes #244)
check / check (push) Successful in 4m23s
check / check (push) Successful in 4m23s
The default blocklist covers private and reserved space, plus public addresses that serve cloud credentials. A provider's other services on public addresses, such as IBM Cloud's 161.26.0.0/16 and 166.8.0.0/14, are deliberately not on it: they serve no credentials, reaching them can be legitimate, and every cloud has some, so a partial list would promise coverage it does not give. The README's egress section and the comment above blockedNetworks now state this rule, so nobody infers wider coverage and a future candidate can be accepted or refused against it. No list change. Model: opus-5-5
This commit is contained in:
@@ -162,6 +162,14 @@ public cloud metadata addresses: currently only `168.63.129.16`, Azure's
|
||||
WireServer, which serves an Azure VM its credentials. Because it is a
|
||||
public address, listing it in `ALLOWED_EGRESS_CIDRS` reopens it.
|
||||
|
||||
That is all the default blocklist covers: private and reserved space,
|
||||
plus public addresses that serve cloud credentials. A cloud provider's
|
||||
other services on public addresses are not refused — IBM Cloud's
|
||||
`161.26.0.0/16` and `166.8.0.0/14`, for example, which carry its DNS
|
||||
resolvers, time servers and package mirrors. They serve no credentials,
|
||||
reaching them can be a legitimate delivery, and every cloud has some, so
|
||||
a partial list would promise coverage it does not give.
|
||||
|
||||
That default is also inconvenient for the thing webhooker is mostly
|
||||
for: taking a public webhook and forwarding it to something on your own
|
||||
network. A container on the same Docker network, a box on `10.x`, a
|
||||
|
||||
Reference in New Issue
Block a user