Default-block Azure WireServer's public address (closes #245)
check / check (push) Successful in 4m34s
check / check (push) Successful in 4m34s
Add 168.63.129.16 (Azure WireServer) to blockedNetworks, the default blocklist, not alwaysBlockedNetworks: it is public unicast, so an operator who lists it in ALLOWED_EGRESS_CIDRS can reach it again. The refusal message, the allowlist startup warning, the README and the comments no longer call every blocked address private/reserved, and no longer claim the allowlist cannot open any metadata endpoint. Sources: - https://learn.microsoft.com/en-us/azure/virtual-network/what-is-ip-address-168-63-129-16 - https://learn.microsoft.com/en-us/azure/virtual-machines/metadata-security-protocol/overview Deviation: 147.75.207.243 (Equinix Metal) is not added; Equinix documents only a hostname, and the service was sunset on 2026-06-30. Model: opus-5-5
This commit was merged in pull request #334.
This commit is contained in:
@@ -834,12 +834,13 @@ func TestEgressAllowlistWarning(t *testing.T) {
|
||||
// to be able to read back which networks are open.
|
||||
assert.Contains(t, logged, "10.0.0.0/8")
|
||||
assert.Contains(t, logged, "127.0.0.0/8")
|
||||
// What stays shut. Asserted on the clause naming the
|
||||
// wider set rather than on "Link-local" alone, so the
|
||||
// string cannot narrow back to link-local only while
|
||||
// the always-blocked set covers ULA, CGNAT and two
|
||||
// public metadata addresses as well.
|
||||
assert.Contains(t, logged, "metadata endpoints outside it")
|
||||
// What stays shut is the whole unconditional set, not
|
||||
// link-local alone; a public metadata address is not in
|
||||
// it, so a listed block covering it opens it.
|
||||
assert.Contains(t, logged, "blocked unconditionally")
|
||||
assert.Contains(t, logged, "168.63.129.16 is reachable")
|
||||
// The listed blocks need not be private or reserved.
|
||||
assert.NotContains(t, logged, "private/reserved")
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user