Default-block Azure WireServer's public address (closes #245) #334

Merged
clawbot merged 2 commits from issue-245-wireserver-default-block into next 2026-09-29 10:22:08 +02:00
2 Commits
Author SHA1 Message Date
clawbot 1a642844ac Narrow the egress claims to non-public metadata addresses
check / check (push) Successful in 3m56s
The ALLOWED_EGRESS_CIDRS startup warning no longer calls the listed
blocks private/reserved, and says a public cloud metadata address such
as 168.63.129.16 is reachable once it, or a block covering it, is
listed. The README, the AllowedEgressCIDRs field comment and the
checkIP doc comment now say the allowlist cannot open metadata
endpoints at non-public addresses, not every metadata endpoint.

Model: opus-5-5
2026-09-29 07:54:14 +00:00
clawbot e5d245fbc8 Default-block Azure WireServer's public address (closes #245)
check / check (push) Successful in 4m54s
Add 168.63.129.16 to blockedNetworks, the default blocklist, not
alwaysBlockedNetworks: it is public unicast, so an operator who lists
it in ALLOWED_EGRESS_CIDRS can reach it again. The default-blocklist
refusal no longer says "private/reserved", which this address is not.

Sources:
- Fixed, Microsoft-owned address:
  https://learn.microsoft.com/en-us/azure/virtual-network/what-is-ip-address-168-63-129-16
- WireServer there bootstraps VM credentials and serves secrets:
  https://learn.microsoft.com/en-us/azure/virtual-machines/metadata-security-protocol/overview

147.75.207.243 (Equinix Metal) is not added: Equinix's metadata page
names only the hostname metadata.platformequinix.com, not the address,
and says Equinix Metal was sunset on 2026-06-30.

Model: opus-5-5
2026-09-29 07:16:45 +00:00