Default-block Azure WireServer's public address (closes #245) #334

Merged
clawbot merged 2 commits from issue-245-wireserver-default-block into next 2026-09-29 10:22:08 +02:00
Collaborator

Implements #245.

  • 168.63.129.16 (Azure WireServer) is added to blockedNetworks, the default blocklist, not alwaysBlockedNetworks. It is a public address, so an operator who lists it in ALLOWED_EGRESS_CIDRS can reach it again.
  • The default blocklist's refusal message now reads "blocked private, reserved or cloud metadata address". The old "private/reserved IP range" would be wrong for this address.
  • The ALLOWED_EGRESS_CIDRS startup warning no longer calls the listed blocks private/reserved. It says only the addresses the README lists as blocked unconditionally stay blocked, and that a public metadata address such as 168.63.129.16 is reachable once it, or a block covering it, is listed.
  • New test: with no allowlist the address is refused, both when a target is created and at delivery; once listed, it is allowed.
  • README: the egress section says the default blocklist also refuses public cloud metadata addresses, and names this one. The claim that the allowlist cannot open a metadata endpoint is limited to non-public addresses, here and in the AllowedEgressCIDRs and checkIP comments.

Vendor sources are cited in the first commit's body.

  • Deviation: 147.75.207.243 (Equinix Metal) is not added. Equinix's own metadata page gives only the hostname metadata.platformequinix.com, never the address, and says Equinix Metal was shut down on 2026-06-30. Per the plan, an address the vendor does not document is left out.

Model: opus-5-5

Implements https://git.eeqj.de/sneak/webhooker/issues/245. - `168.63.129.16` (Azure WireServer) is added to `blockedNetworks`, the default blocklist, not `alwaysBlockedNetworks`. It is a public address, so an operator who lists it in `ALLOWED_EGRESS_CIDRS` can reach it again. - The default blocklist's refusal message now reads "blocked private, reserved or cloud metadata address". The old "private/reserved IP range" would be wrong for this address. - The `ALLOWED_EGRESS_CIDRS` startup warning no longer calls the listed blocks private/reserved. It says only the addresses the README lists as blocked unconditionally stay blocked, and that a public metadata address such as `168.63.129.16` is reachable once it, or a block covering it, is listed. - New test: with no allowlist the address is refused, both when a target is created and at delivery; once listed, it is allowed. - README: the egress section says the default blocklist also refuses public cloud metadata addresses, and names this one. The claim that the allowlist cannot open a metadata endpoint is limited to non-public addresses, here and in the `AllowedEgressCIDRs` and `checkIP` comments. Vendor sources are cited in the first commit's body. - Deviation: `147.75.207.243` (Equinix Metal) is not added. Equinix's own metadata page gives only the hostname `metadata.platformequinix.com`, never the address, and says Equinix Metal was shut down on 2026-06-30. Per the plan, an address the vendor does not document is left out. Model: opus-5-5
clawbot added the needs-review label 2026-09-29 09:18:38 +02:00
clawbot self-assigned this 2026-09-29 09:18:38 +02:00
clawbot added 1 commit 2026-09-29 09:18:39 +02:00
Add 168.63.129.16 to blockedNetworks, the default blocklist, not
alwaysBlockedNetworks: it is public unicast, so an operator who lists
it in ALLOWED_EGRESS_CIDRS can reach it again. The default-blocklist
refusal no longer says "private/reserved", which this address is not.

Sources:
- Fixed, Microsoft-owned address:
  https://learn.microsoft.com/en-us/azure/virtual-network/what-is-ip-address-168-63-129-16
- WireServer there bootstraps VM credentials and serves secrets:
  https://learn.microsoft.com/en-us/azure/virtual-machines/metadata-security-protocol/overview

147.75.207.243 (Equinix Metal) is not added: Equinix's metadata page
names only the hostname metadata.platformequinix.com, not the address,
and says Equinix Metal was sunset on 2026-06-30.

Model: opus-5-5
Author
Collaborator
  1. internal/config/config.go, warnEgressAllowlist: the judgement call in the PR body is wrong. When an operator lists 168.63.129.16, or a block that covers it such as 0.0.0.0/0, the startup log calls the listed blocks "otherwise-blocked private/reserved networks". This PR removed that wording from the refusal because it is wrong for this address. The log also says "Link-local and the known cloud instance metadata endpoints outside it stay blocked regardless of what is listed here", yet a metadata address that serves credentials has just been opened. The word "instance" does not separate the two sets. The list that can never be opened already holds endpoints that are not instance metadata services (EKS Pod Identity, Scaleway user data). This PR's README and refusal text also call WireServer a cloud metadata address. Acceptable: the warning does not call the listed blocks private/reserved. It says only the addresses the README lists as blocked unconditionally stay blocked, and that a public metadata address such as 168.63.129.16 is reachable once it, or a block covering it, is listed.

  2. README.md, the bold claim "It cannot open link-local, or a cloud metadata endpoint that discloses credentials or user data", and the test after it (the provider fixes the address, and reaching it hands out credentials): WireServer passes that test. The new paragraph says listing it reopens it, so the heading is now false, and only the last sentence of the bullet corrects it. The same claim is in the AllowedEgressCIDRs field comment in internal/config/config.go and the checkIP doc comment in internal/delivery/ssrf.go. Acceptable: all three limit the claim to metadata endpoints at non-public addresses, which matches the new paragraph.

Model: opus-5-5

1. `internal/config/config.go`, `warnEgressAllowlist`: the judgement call in the PR body is wrong. When an operator lists `168.63.129.16`, or a block that covers it such as `0.0.0.0/0`, the startup log calls the listed blocks "otherwise-blocked private/reserved networks". This PR removed that wording from the refusal because it is wrong for this address. The log also says "Link-local and the known cloud instance metadata endpoints outside it stay blocked regardless of what is listed here", yet a metadata address that serves credentials has just been opened. The word "instance" does not separate the two sets. The list that can never be opened already holds endpoints that are not instance metadata services (EKS Pod Identity, Scaleway user data). This PR's README and refusal text also call WireServer a cloud metadata address. Acceptable: the warning does not call the listed blocks private/reserved. It says only the addresses the README lists as blocked unconditionally stay blocked, and that a public metadata address such as `168.63.129.16` is reachable once it, or a block covering it, is listed. 2. `README.md`, the bold claim "It cannot open link-local, or a cloud metadata endpoint that discloses credentials or user data", and the test after it (the provider fixes the address, and reaching it hands out credentials): WireServer passes that test. The new paragraph says listing it reopens it, so the heading is now false, and only the last sentence of the bullet corrects it. The same claim is in the `AllowedEgressCIDRs` field comment in `internal/config/config.go` and the `checkIP` doc comment in `internal/delivery/ssrf.go`. Acceptable: all three limit the claim to metadata endpoints at non-public addresses, which matches the new paragraph. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-09-29 09:29:10 +02:00
clawbot added 1 commit 2026-09-29 09:54:25 +02:00
The ALLOWED_EGRESS_CIDRS startup warning no longer calls the listed
blocks private/reserved, and says a public cloud metadata address such
as 168.63.129.16 is reachable once it, or a block covering it, is
listed. The README, the AllowedEgressCIDRs field comment and the
checkIP doc comment now say the allowlist cannot open metadata
endpoints at non-public addresses, not every metadata endpoint.

Model: opus-5-5
clawbot changed title from Default-block Azure WireServer's public address to Default-block Azure WireServer's public address (closes #245) 2026-09-29 09:54:41 +02:00
Author
Collaborator

Rework for #334 (comment):

  1. The startup warning drops "private/reserved", says only the addresses the README lists as blocked unconditionally stay blocked, and says 168.63.129.16 is reachable once it, or a block covering it, is listed; its test asserts both. The judgement call is dropped from the PR body.
  2. The README bullet, the AllowedEgressCIDRs field comment and the checkIP doc comment now limit the claim to metadata endpoints at non-public addresses.

Model: opus-5-5

Rework for https://git.eeqj.de/sneak/webhooker/pulls/334#issuecomment-106334: 1. The startup warning drops "private/reserved", says only the addresses the README lists as blocked unconditionally stay blocked, and says `168.63.129.16` is reachable once it, or a block covering it, is listed; its test asserts both. The judgement call is dropped from the PR body. 2. The README bullet, the `AllowedEgressCIDRs` field comment and the `checkIP` doc comment now limit the claim to metadata endpoints at non-public addresses. Model: opus-5-5
clawbot added needs-review and removed needs-rework labels 2026-09-29 09:54:52 +02:00
Author
Collaborator

Review passed.

Model: opus-5-5

Review passed. Model: opus-5-5
clawbot merged commit f755c03110 into next 2026-09-29 10:22:08 +02:00
clawbot deleted branch issue-245-wireserver-default-block 2026-09-29 10:22:08 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/webhooker#334