Default-block Azure WireServer's public address (closes #245)
check / check (push) Successful in 4m54s

Add 168.63.129.16 to blockedNetworks, the default blocklist, not
alwaysBlockedNetworks: it is public unicast, so an operator who lists
it in ALLOWED_EGRESS_CIDRS can reach it again. The default-blocklist
refusal no longer says "private/reserved", which this address is not.

Sources:
- Fixed, Microsoft-owned address:
  https://learn.microsoft.com/en-us/azure/virtual-network/what-is-ip-address-168-63-129-16
- WireServer there bootstraps VM credentials and serves secrets:
  https://learn.microsoft.com/en-us/azure/virtual-machines/metadata-security-protocol/overview

147.75.207.243 (Equinix Metal) is not added: Equinix's metadata page
names only the hostname metadata.platformequinix.com, not the address,
and says Equinix Metal was sunset on 2026-06-30.

Model: opus-5-5
This commit is contained in:
2026-09-29 07:16:45 +00:00
parent 4a724130ca
commit e5d245fbc8
3 changed files with 51 additions and 7 deletions
+7 -1
View File
@@ -157,6 +157,11 @@ private and reserved ranges — RFC 1918, loopback, CGNAT, link-local and
the rest — are refused, which stops a target from being used to make
webhooker probe the network it sits in.
Besides the private and reserved ranges, the default blocklist refuses
public cloud metadata addresses: currently only `168.63.129.16`, Azure's
WireServer, which serves an Azure VM its credentials. Because it is a
public address, listing it in `ALLOWED_EGRESS_CIDRS` reopens it.
That default is also inconvenient for the thing webhooker is mostly
for: taking a public webhook and forwarding it to something on your own
network. A container on the same Docker network, a box on `10.x`, a
@@ -242,7 +247,8 @@ Two things this setting cannot do:
encodings, which the default blocklist does not match. A publicly
routable metadata address is not listed here, because nothing on this
list can be reopened and blocking one that way would leave you no
escape hatch at all.
escape hatch at all; Azure's `168.63.129.16` is refused by the default
blocklist instead, as described above.
This list is not exhaustive of every cloud's metadata address — if
yours is not here, do not allowlist the block that contains it.