Add missing public infra domains to egress allowlist - #276
Merged
v-abhishekbhaskar merged 1 commit intoSep 29, 2026
Merged
Conversation
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Security-sensitive allowlist expansion, particularly the documented multi-tenant exception, warrants final human validation.
Review effort: Balanced
Findings: None
What changed in this PR
Expands proxy egress support for public package infrastructure while safely deriving private ECR storage redirects.
Changes:
- Adds exact public registry, mirror, CDN, and runtime hosts.
- Derives regional ECR Starport bucket hosts from credentials.
- Adds allow/block boundary tests for all new behavior.
| File | Description |
|---|---|
internal/handlers/egress_dynamic_hosts.go |
Derives ECR redirect hosts. |
internal/handlers/egress_dynamic_hosts_test.go |
Tests safe ECR derivation. |
internal/handlers/egress_allowlist_test.go |
Tests new hosts and isolation boundaries. |
internal/handlers/egress_allowlist_defaults.yaml |
Adds public infrastructure domains. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
honeyankit
approved these changes
Sep 29, 2026
v-abhishekbhaskar
deleted the
abhishekbhaskar/add-missing-public-infra-domains
branch
September 29, 2026 05:58
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What are you trying to accomplish?
Expands the egress allowlist using traffic recorded during the
proxy-egress-enforcerollout, and adds one dynamic-derivation rule so a large class of blocks is handled without static entries.Static hosts added (all anonymous, provider-controlled package infrastructure):
data.nuget.orgmaven-central.storage.googleapis.com,maven-central.storage-download.googleapis.com,repo.osgeo.org,androidx.dev,packages.atlassian.com,maven.artifacts.atlassian.comjulialang-s3.julialang.orgpkg.pr.new,unofficial-builds.nodejs.orgdocker.elastic.co,docker-auth.elastic.co,docker-registry-production.d24a988e385e0074d717b6bdaea58f0d.r2.cloudflarestorage.com,docker.getcollate.iomirrors.huaweicloud.comAlso moves
nodejs.orgfromgo_modulestonpm_and_yarn(organizational only — the handler applies the union), and derives ECRprod-<region>-starport-layer-buckethosts per job from the credential set instead of allowlisting ~30 regional buckets.Fixes #264. Fixes #275. Fixes dependabot/dependabot-core#16413.
Anything you want to highlight for special attention from reviewers?
Redirect chains, not just reported hosts. Both #264 and the Atlassian entry needed a host the issue never mentioned: Elastic's blobs 307 to Cloudflare R2, and
packages.atlassian.com301s tomaven.artifacts.atlassian.com. Allowlisting only the reported host fixes metadata and still fails the download. Egress telemetry only records the first hop, so it systematically under-reports.ECR is derived, not globbed.
prod-*-starport-layer-bucket.s3.*.amazonaws.comis directly exploitable, not just theoretically risky:prod-evil-starport-layer-bucketreturnsNoSuchBuckettoday, so an attacker could claim it. Regions are interpolated from the job's own ECR credentials and matched exactly.One entry was dropped on review.
f.feedz.iowas in the original triage but is structurally identical todl.cloudsmith.io, which this file deliberately excludes: shared host, tenant in the URL path, and the allowlist authorizes hostname only. Added a test pinning Cloudsmith closed so the precedent is enforced rather than only commented.pkg.pr.newis a judgment call. Same shape (namespace in path), but no per-tenant request logs — the specific mechanism the Cloudsmith note relies on. Documented inline; happy to drop it if reviewers disagree.Header amended. The file said virtual-hosted
<bucket>.storage.googleapis.comsubdomains "stay blocked", whichmaven-central.*contradicts. Reworded to "blocked as a class, added one exact registered bucket at a time".data.nuget.org404s on every path. It's decommissioned Microsoft infrastructure (certCN=api.nuget.org) still hit by older clients. Allowlisting converts a hard proxy block into a 404 the client already handles — the same failure mode as the pnpm issue.How will you know you've accomplished your goal?
Every host was verified on the wire before being added — anonymous fetch of a real artifact, following redirects, with ownership confirmed via TLS cert or the
api.github.com/metadomains.packageslist.New tests:
TestEgressAllowlist_PublicEcosystemMirrorsAllowed,TestEgressAllowlist_PublicVendorOCIRegistriesAllowed,TestEgressAllowlist_NodeRuntimeDownloadsAllowed, and threeTestRegistryRedirectHosts_*cases.Each new entry has a child probe (
evil.<host>) and, where a parent namespace is involved, a sibling probe, so the exact-match semantics fail loudly if an entry is ever widened. Mutation-verified: wideningmaven-centralto a leading dot fails two tests; dropping the Atlassian redirect target fails one; re-addingdl.cloudsmith.iofails two.Checklist