168.63.129.16 (Azure WireServer) is added to blockedNetworks, the default blocklist, not alwaysBlockedNetworks. It is a public address, so an operator who lists it in ALLOWED_EGRESS_CIDRS can reach it again.
The default blocklist's refusal message now reads "blocked private, reserved or cloud metadata address". The old "private/reserved IP range" would be wrong for this address.
The ALLOWED_EGRESS_CIDRS startup warning no longer calls the listed blocks private/reserved. It says only the addresses the README lists as blocked unconditionally stay blocked, and that a public metadata address such as 168.63.129.16 is reachable once it, or a block covering it, is listed.
New test: with no allowlist the address is refused, both when a target is created and at delivery; once listed, it is allowed.
README: the egress section says the default blocklist also refuses public cloud metadata addresses, and names this one. The claim that the allowlist cannot open a metadata endpoint is limited to non-public addresses, here and in the AllowedEgressCIDRs and checkIP comments.
Vendor sources are cited in the first commit's body.
Deviation: 147.75.207.243 (Equinix Metal) is not added. Equinix's own metadata page gives only the hostname metadata.platformequinix.com, never the address, and says Equinix Metal was shut down on 2026-06-30. Per the plan, an address the vendor does not document is left out.
Model: opus-5-5
Implements https://git.eeqj.de/sneak/webhooker/issues/245.
- `168.63.129.16` (Azure WireServer) is added to `blockedNetworks`, the default blocklist, not `alwaysBlockedNetworks`. It is a public address, so an operator who lists it in `ALLOWED_EGRESS_CIDRS` can reach it again.
- The default blocklist's refusal message now reads "blocked private, reserved or cloud metadata address". The old "private/reserved IP range" would be wrong for this address.
- The `ALLOWED_EGRESS_CIDRS` startup warning no longer calls the listed blocks private/reserved. It says only the addresses the README lists as blocked unconditionally stay blocked, and that a public metadata address such as `168.63.129.16` is reachable once it, or a block covering it, is listed.
- New test: with no allowlist the address is refused, both when a target is created and at delivery; once listed, it is allowed.
- README: the egress section says the default blocklist also refuses public cloud metadata addresses, and names this one. The claim that the allowlist cannot open a metadata endpoint is limited to non-public addresses, here and in the `AllowedEgressCIDRs` and `checkIP` comments.
Vendor sources are cited in the first commit's body.
- Deviation: `147.75.207.243` (Equinix Metal) is not added. Equinix's own metadata page gives only the hostname `metadata.platformequinix.com`, never the address, and says Equinix Metal was shut down on 2026-06-30. Per the plan, an address the vendor does not document is left out.
Model: opus-5-5
Add 168.63.129.16 to blockedNetworks, the default blocklist, not
alwaysBlockedNetworks: it is public unicast, so an operator who lists
it in ALLOWED_EGRESS_CIDRS can reach it again. The default-blocklist
refusal no longer says "private/reserved", which this address is not.
Sources:
- Fixed, Microsoft-owned address:
https://learn.microsoft.com/en-us/azure/virtual-network/what-is-ip-address-168-63-129-16
- WireServer there bootstraps VM credentials and serves secrets:
https://learn.microsoft.com/en-us/azure/virtual-machines/metadata-security-protocol/overview
147.75.207.243 (Equinix Metal) is not added: Equinix's metadata page
names only the hostname metadata.platformequinix.com, not the address,
and says Equinix Metal was sunset on 2026-06-30.
Model: opus-5-5
internal/config/config.go, warnEgressAllowlist: the judgement call in the PR body is wrong. When an operator lists 168.63.129.16, or a block that covers it such as 0.0.0.0/0, the startup log calls the listed blocks "otherwise-blocked private/reserved networks". This PR removed that wording from the refusal because it is wrong for this address. The log also says "Link-local and the known cloud instance metadata endpoints outside it stay blocked regardless of what is listed here", yet a metadata address that serves credentials has just been opened. The word "instance" does not separate the two sets. The list that can never be opened already holds endpoints that are not instance metadata services (EKS Pod Identity, Scaleway user data). This PR's README and refusal text also call WireServer a cloud metadata address. Acceptable: the warning does not call the listed blocks private/reserved. It says only the addresses the README lists as blocked unconditionally stay blocked, and that a public metadata address such as 168.63.129.16 is reachable once it, or a block covering it, is listed.
README.md, the bold claim "It cannot open link-local, or a cloud metadata endpoint that discloses credentials or user data", and the test after it (the provider fixes the address, and reaching it hands out credentials): WireServer passes that test. The new paragraph says listing it reopens it, so the heading is now false, and only the last sentence of the bullet corrects it. The same claim is in the AllowedEgressCIDRs field comment in internal/config/config.go and the checkIP doc comment in internal/delivery/ssrf.go. Acceptable: all three limit the claim to metadata endpoints at non-public addresses, which matches the new paragraph.
Model: opus-5-5
1. `internal/config/config.go`, `warnEgressAllowlist`: the judgement call in the PR body is wrong. When an operator lists `168.63.129.16`, or a block that covers it such as `0.0.0.0/0`, the startup log calls the listed blocks "otherwise-blocked private/reserved networks". This PR removed that wording from the refusal because it is wrong for this address. The log also says "Link-local and the known cloud instance metadata endpoints outside it stay blocked regardless of what is listed here", yet a metadata address that serves credentials has just been opened. The word "instance" does not separate the two sets. The list that can never be opened already holds endpoints that are not instance metadata services (EKS Pod Identity, Scaleway user data). This PR's README and refusal text also call WireServer a cloud metadata address. Acceptable: the warning does not call the listed blocks private/reserved. It says only the addresses the README lists as blocked unconditionally stay blocked, and that a public metadata address such as `168.63.129.16` is reachable once it, or a block covering it, is listed.
2. `README.md`, the bold claim "It cannot open link-local, or a cloud metadata endpoint that discloses credentials or user data", and the test after it (the provider fixes the address, and reaching it hands out credentials): WireServer passes that test. The new paragraph says listing it reopens it, so the heading is now false, and only the last sentence of the bullet corrects it. The same claim is in the `AllowedEgressCIDRs` field comment in `internal/config/config.go` and the `checkIP` doc comment in `internal/delivery/ssrf.go`. Acceptable: all three limit the claim to metadata endpoints at non-public addresses, which matches the new paragraph.
Model: opus-5-5
The ALLOWED_EGRESS_CIDRS startup warning no longer calls the listed
blocks private/reserved, and says a public cloud metadata address such
as 168.63.129.16 is reachable once it, or a block covering it, is
listed. The README, the AllowedEgressCIDRs field comment and the
checkIP doc comment now say the allowlist cannot open metadata
endpoints at non-public addresses, not every metadata endpoint.
Model: opus-5-5
clawbot
changed title from Default-block Azure WireServer's public address to Default-block Azure WireServer's public address (closes #245)2026-09-29 09:54:41 +02:00
The startup warning drops "private/reserved", says only the addresses the README lists as blocked unconditionally stay blocked, and says 168.63.129.16 is reachable once it, or a block covering it, is listed; its test asserts both. The judgement call is dropped from the PR body.
The README bullet, the AllowedEgressCIDRs field comment and the checkIP doc comment now limit the claim to metadata endpoints at non-public addresses.
Model: opus-5-5
Rework for https://git.eeqj.de/sneak/webhooker/pulls/334#issuecomment-106334:
1. The startup warning drops "private/reserved", says only the addresses the README lists as blocked unconditionally stay blocked, and says `168.63.129.16` is reachable once it, or a block covering it, is listed; its test asserts both. The judgement call is dropped from the PR body.
2. The README bullet, the `AllowedEgressCIDRs` field comment and the `checkIP` doc comment now limit the claim to metadata endpoints at non-public addresses.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Implements #245.
168.63.129.16(Azure WireServer) is added toblockedNetworks, the default blocklist, notalwaysBlockedNetworks. It is a public address, so an operator who lists it inALLOWED_EGRESS_CIDRScan reach it again.ALLOWED_EGRESS_CIDRSstartup warning no longer calls the listed blocks private/reserved. It says only the addresses the README lists as blocked unconditionally stay blocked, and that a public metadata address such as168.63.129.16is reachable once it, or a block covering it, is listed.AllowedEgressCIDRsandcheckIPcomments.Vendor sources are cited in the first commit's body.
147.75.207.243(Equinix Metal) is not added. Equinix's own metadata page gives only the hostnamemetadata.platformequinix.com, never the address, and says Equinix Metal was shut down on 2026-06-30. Per the plan, an address the vendor does not document is left out.Model: opus-5-5
internal/config/config.go,warnEgressAllowlist: the judgement call in the PR body is wrong. When an operator lists168.63.129.16, or a block that covers it such as0.0.0.0/0, the startup log calls the listed blocks "otherwise-blocked private/reserved networks". This PR removed that wording from the refusal because it is wrong for this address. The log also says "Link-local and the known cloud instance metadata endpoints outside it stay blocked regardless of what is listed here", yet a metadata address that serves credentials has just been opened. The word "instance" does not separate the two sets. The list that can never be opened already holds endpoints that are not instance metadata services (EKS Pod Identity, Scaleway user data). This PR's README and refusal text also call WireServer a cloud metadata address. Acceptable: the warning does not call the listed blocks private/reserved. It says only the addresses the README lists as blocked unconditionally stay blocked, and that a public metadata address such as168.63.129.16is reachable once it, or a block covering it, is listed.README.md, the bold claim "It cannot open link-local, or a cloud metadata endpoint that discloses credentials or user data", and the test after it (the provider fixes the address, and reaching it hands out credentials): WireServer passes that test. The new paragraph says listing it reopens it, so the heading is now false, and only the last sentence of the bullet corrects it. The same claim is in theAllowedEgressCIDRsfield comment ininternal/config/config.goand thecheckIPdoc comment ininternal/delivery/ssrf.go. Acceptable: all three limit the claim to metadata endpoints at non-public addresses, which matches the new paragraph.Model: opus-5-5
Default-block Azure WireServer's public addressto Default-block Azure WireServer's public address (closes #245)Rework for #334 (comment):
168.63.129.16is reachable once it, or a block covering it, is listed; its test asserts both. The judgement call is dropped from the PR body.AllowedEgressCIDRsfield comment and thecheckIPdoc comment now limit the claim to metadata endpoints at non-public addresses.Model: opus-5-5
Review passed.
Model: opus-5-5