Default-block the public-unicast cloud metadata endpoints (Azure WireServer, Equinix Metal) #245

Closed
opened 2026-08-20 10:05:03 +02:00 by clawbot · 2 comments
Collaborator

Split out of #217 by scope ruling. Not milestoned for 1.0.

168.63.129.16 (Azure WireServer) and 147.75.207.243 (Equinix Metal) are cloud metadata endpoints that serve credentials, but unlike 169.254.169.254 they are public unicast — they fall in no private or reserved range, so the SSRF guard currently permits them.

They were added to alwaysBlockedNetworks during the rework of #217 and have been removed again, for two reasons:

  1. alwaysBlockedNetworks is unrecoverable by design — no allowlist entry can restore it. That is correct for link-local metadata, which is never a legitimate delivery destination. It is not correct for public unicast addresses: an operator who genuinely needs to reach one has no escape hatch at all, which is the exact condition #204 exists to remove.
  2. It broke the property that an unset ALLOWED_EGRESS_CIDRS is a provable no-op. That property is what makes the allowlist PR's blast radius zero for every existing deployment, and it is worth more than folding an unrelated blocklist change into the same commit.

Definition of done:

  • Both addresses are added to blockedNetworks (the default blocklist), NOT alwaysBlockedNetworks, so the guard refuses them by default and an operator can deliberately allowlist them back.
  • A test asserts each is refused with ALLOWED_EGRESS_CIDRS unset, and permitted when explicitly allowlisted.
  • README documents that the default blocklist covers public-unicast metadata endpoints in addition to the private and reserved ranges.
  • Vendor sourcing for both addresses is cited in the commit body, so the pinned set has a provenance record.
Split out of https://git.eeqj.de/sneak/webhooker/pulls/217 by scope ruling. Not milestoned for 1.0. `168.63.129.16` (Azure WireServer) and `147.75.207.243` (Equinix Metal) are cloud metadata endpoints that serve credentials, but unlike `169.254.169.254` they are **public unicast** — they fall in no private or reserved range, so the SSRF guard currently permits them. They were added to `alwaysBlockedNetworks` during the rework of https://git.eeqj.de/sneak/webhooker/pulls/217 and have been removed again, for two reasons: 1. `alwaysBlockedNetworks` is unrecoverable by design — no allowlist entry can restore it. That is correct for link-local metadata, which is never a legitimate delivery destination. It is not correct for public unicast addresses: an operator who genuinely needs to reach one has no escape hatch at all, which is the exact condition https://git.eeqj.de/sneak/webhooker/issues/204 exists to remove. 2. It broke the property that an unset `ALLOWED_EGRESS_CIDRS` is a provable no-op. That property is what makes the allowlist PR's blast radius zero for every existing deployment, and it is worth more than folding an unrelated blocklist change into the same commit. Definition of done: - Both addresses are added to `blockedNetworks` (the default blocklist), NOT `alwaysBlockedNetworks`, so the guard refuses them by default and an operator can deliberately allowlist them back. - A test asserts each is refused with `ALLOWED_EGRESS_CIDRS` unset, and permitted when explicitly allowlisted. - README documents that the default blocklist covers public-unicast metadata endpoints in addition to the private and reserved ranges. - Vendor sourcing for both addresses is cited in the commit body, so the pinned set has a provenance record.
Author
Collaborator

Plan. The code the issue names is unchanged on next (4a72413).

  • Where the entries go: in blockedNetworks (internal/delivery/ssrf.go), not alwaysBlockedNetworks, each with a one-line comment naming the provider and what the address serves.
  • Sources: before adding an address, confirm it against the vendor's own current documentation, and cite that page in the commit body. An address the vendor does not document today is not added, and the PR says so in one line; do not add it on a third party's word, as the issue already ruled for the GKE range.
  • Tests:
    • each address is refused with ALLOWED_EGRESS_CIDRS unset;
    • each is allowed when explicitly listed there;
    • the existing tests that an unset allowlist changes nothing still pass.
  • README: say that the default blocklist also covers these public-unicast metadata addresses, and name them. #244 will state the rule for what the default list covers, so only list the addresses here.

Model: opus-5-5

Plan. The code the issue names is unchanged on `next` (`4a72413`). - **Where the entries go:** in `blockedNetworks` (`internal/delivery/ssrf.go`), not `alwaysBlockedNetworks`, each with a one-line comment naming the provider and what the address serves. - **Sources:** before adding an address, confirm it against the vendor's own current documentation, and cite that page in the commit body. An address the vendor does not document today is not added, and the PR says so in one line; do not add it on a third party's word, as the issue already ruled for the GKE range. - **Tests:** - each address is refused with `ALLOWED_EGRESS_CIDRS` unset; - each is allowed when explicitly listed there; - the existing tests that an unset allowlist changes nothing still pass. - **README:** say that the default blocklist also covers these public-unicast metadata addresses, and name them. https://git.eeqj.de/sneak/webhooker/issues/244 will state the rule for what the default list covers, so only list the addresses here. Model: opus-5-5
clawbot self-assigned this 2026-09-29 09:11:53 +02:00
Author
Collaborator

Built in #334. Only Azure WireServer (168.63.129.16) is added to the default blocklist. 147.75.207.243 (Equinix Metal) is not: Equinix's metadata page gives only the hostname, never the address, and Equinix Metal was shut down on 2026-06-30.

Model: opus-5-5

Built in https://git.eeqj.de/sneak/webhooker/pulls/334. Only Azure WireServer (`168.63.129.16`) is added to the default blocklist. `147.75.207.243` (Equinix Metal) is not: Equinix's metadata page gives only the hostname, never the address, and Equinix Metal was shut down on 2026-06-30. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/webhooker#245