Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
7b09802967 |
@@ -162,6 +162,14 @@ public cloud metadata addresses: currently only `168.63.129.16`, Azure's
|
|||||||
WireServer, which serves an Azure VM its credentials. Because it is a
|
WireServer, which serves an Azure VM its credentials. Because it is a
|
||||||
public address, listing it in `ALLOWED_EGRESS_CIDRS` reopens it.
|
public address, listing it in `ALLOWED_EGRESS_CIDRS` reopens it.
|
||||||
|
|
||||||
|
That is all the default blocklist covers: private and reserved space,
|
||||||
|
plus public addresses that serve cloud credentials. A cloud provider's
|
||||||
|
other services on public addresses are not refused — IBM Cloud's
|
||||||
|
`161.26.0.0/16` and `166.8.0.0/14`, for example, which carry its DNS
|
||||||
|
resolvers, time servers and package mirrors. They serve no credentials,
|
||||||
|
reaching them can be a legitimate delivery, and every cloud has some, so
|
||||||
|
a partial list would promise coverage it does not give.
|
||||||
|
|
||||||
That default is also inconvenient for the thing webhooker is mostly
|
That default is also inconvenient for the thing webhooker is mostly
|
||||||
for: taking a public webhook and forwarding it to something on your own
|
for: taking a public webhook and forwarding it to something on your own
|
||||||
network. A container on the same Docker network, a box on `10.x`, a
|
network. A container on the same Docker network, a box on `10.x`, a
|
||||||
|
|||||||
@@ -43,6 +43,12 @@ var (
|
|||||||
// permit specific blocks out of this set with
|
// permit specific blocks out of this set with
|
||||||
// ALLOWED_EGRESS_CIDRS; see Guard.
|
// ALLOWED_EGRESS_CIDRS; see Guard.
|
||||||
//
|
//
|
||||||
|
// A public address belongs here only if it serves cloud
|
||||||
|
// credentials; a provider's other services on public addresses,
|
||||||
|
// such as its DNS resolvers or package mirrors, stay out, since
|
||||||
|
// reaching them can be legitimate and no list of them could be
|
||||||
|
// complete.
|
||||||
|
//
|
||||||
//nolint:gochecknoglobals // package-level network list is appropriate here
|
//nolint:gochecknoglobals // package-level network list is appropriate here
|
||||||
var blockedNetworks []*net.IPNet
|
var blockedNetworks []*net.IPNet
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user