State what the default blocklist covers (closes #244) #339

Open
clawbot wants to merge 1 commits from issue-244-default-blocklist-scope into next
2 changed files with 17 additions and 0 deletions
+11
View File
@@ -162,6 +162,17 @@ public cloud metadata addresses: currently only `168.63.129.16`, Azure's
WireServer, which serves an Azure VM its credentials. Because it is a
public address, listing it in `ALLOWED_EGRESS_CIDRS` reopens it.
That is all the default blocklist covers: the IPv4 private and reserved
ranges; of IPv6, only loopback (`::1`), unique local addresses
(`fc00::/7`) and link-local addresses (`fe80::/10`); and public
addresses that serve cloud credentials. A cloud provider's other
services on public addresses are not refused. IBM Cloud, for example,
serves its DNS resolvers, package mirrors, time servers and object
storage on `161.26.0.0/16`, and the private endpoints of its own cloud
services on `166.8.0.0/14`. They serve no credentials, reaching them
can be a legitimate delivery, and every cloud has some, so a partial
list would promise coverage it does not give.
That default is also inconvenient for the thing webhooker is mostly
for: taking a public webhook and forwarding it to something on your own
network. A container on the same Docker network, a box on `10.x`, a
+6
View File
@@ -43,6 +43,12 @@ var (
// permit specific blocks out of this set with
// ALLOWED_EGRESS_CIDRS; see Guard.
//
// A public address belongs here only if it serves cloud
// credentials; a provider's other services on public addresses,
// such as its DNS resolvers or package mirrors, stay out, since
// reaching them can be legitimate and no list of them could be
// complete.
//
//nolint:gochecknoglobals // package-level network list is appropriate here
var blockedNetworks []*net.IPNet