Add OCI and changelog release notes registries to egress allowlist - #280
Merged
v-abhishekbhaskar merged 1 commit intoSep 30, 2026
Merged
Conversation
honeyankit
approved these changes
Sep 30, 2026
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Several exact changelog hosts lack child probes that prevent unsafe suffix widening.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Expands the egress allowlist for public OCI registries, ecosystem mirrors, and release-note hosts.
Changes:
- Adds OCI registries, redirect targets, and public mirrors.
- Broadens Quay matching to provider-controlled subdomains.
- Adds allow/block regression coverage.
| File | Description |
|---|---|
internal/handlers/egress_allowlist_defaults.yaml |
Adds and documents allowlisted domains. |
internal/handlers/egress_allowlist_test.go |
Tests new hosts and matching boundaries. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+1134
to
+1140
| // Exact entries must not widen to children or lookalike parents. | ||
| "https://evil.docs.pytest.org/payload", | ||
| "https://docs.pytest.org.attacker.com/payload", | ||
| "https://pytest.org/payload", | ||
| "https://evil.developer.android.com/payload", | ||
| "https://android.com/payload", | ||
| "https://apache.org/payload", |
v-abhishekbhaskar
deleted the
abhishekbhaskar/add-oci-public-registries-allowlist
branch
September 30, 2026 06:49
This was referenced Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

What are you trying to accomplish?
Restores three classes of legitimate traffic that the egress allowlist is blocking in production.
1. Public OCI registries
registry.access.redhat.comandcgr.dev(Chainguard) are anonymous public registries that were never allowlisted. Tracing their pull chains surfaced two things the issues do not mention:9236a389bd48b984df91adc1bc924620.r2.cloudflarestorage.com, so allowlistingcgr.devalone still fails on blob fetch.quay.iowas allowlisted as an exact host, but Quay 302s blob downloads tocdn01.quay.io. Tag discovery therefore succeeded while every blob pull was blocked — a latent bug affecting all Quay-hosted images, not just Red Hat's (Red Hat blobs also land oncdn01.quay.io). This is changed to.quay.io.2. Public registries and mirrors :
maven-central-eu.storage-download.googleapis.com,maven.vaadin.com,libraries.minecraft.net,versions.backstage.io.3. Changelog/release-note hosts. Dependabot follows
project_urlsfrom PyPI metadata and<url>from POMs to render release notes in pull requests. These were blocked, which silently degrades PR bodies without breaking resolution.Anything you want to highlight for special attention from reviewers?
The changelog hosts are a new precedent. Until now the allowlist held only package infrastructure. These are documentation sites, so they widen egress for PR-body quality rather than for update correctness.
.quay.iois the only non-exact entry added. A leading dot is safe here specifically because Quay tenancy is path-based (quay.io/<org>/<repo>), so no subdomain is user-creatable — the same rationale as the existing.gcr.ioand.pkg.dev. Every other entry is exact.anyio.readthedocs.iois the head of a long tail. Read the Docs subdomains are project-creatable, so.readthedocs.iowould be an exfiltration channel and must never be used. The entry is exact, withreadthedocs.ioandevil.readthedocs.ioprobes and a YAML comment to stop a later "simplification". Expect more one-off Python docs hosts to surface.Two hosts redirect across origins, so both ends of each chain are required:
docs.pydantic.dev301s topydantic.dev, andpsycopg.org302s towww.psycopg.org. Allowlisting only the recorded host would break mid-chain — the same shape as the existingpackages.atlassian.comentry.Three high-volume hosts were deliberately excluded and have tests asserting they stay blocked:
cs.android.com,docs.aws.amazon.comandissues.apache.org. None carries a changelog Dependabot renders, so allowlisting them would widen egress for no functional gain.How will you know you've accomplished your goal?
Every added host was verified on the wire before being added — anonymous fetch of a real artifact, with the full redirect chain traced:
libraries.minecraft.net— 200, real 77 KBbrigadierjarmaven.vaadin.com— 200, realmaven-metadata.xmlmaven-central-eu.storage-download.googleapis.com— 200, real slf4j POMversions.backstage.io— 200, 20 KB manifestregistry.access.redhat.com—/v2/returns 200 with no auth challenge; blobs 302 tocdn01.quay.iocgr.dev—/v2/401 with token realm on the same host; blobs 307 to the Cloudflare R2 hostTest coverage:
TestEgressAllowlist_PublicVendorOCIRegistriesAllowed— extended for Red Hat and Chainguard, including blob redirect targetsTestEgressAllowlist_QuayCDNSubdomainsAllowed— new; coverscdn01–cdn99, and assertsquay.io.attacker.comandregistry.redhat.iostay blockedTestEgressAllowlist_PublicEcosystemMirrorsAllowed— extended with the four public registries plus child/lookalike probesTestEgressAllowlist_ChangelogHostsAllowed— new; 10 allowed, 12 blocked, covering the readthedocs namespace, the three excluded hosts, and lookalike parentsTestEgressDefaults_NoRedundantEntries— caught a real duplicate during development (a secondquay.ioleft in the helm list, now removed)Every new guard was mutation-tested: 17 mutations in total (dropping each entry, and widening each to a leading dot or glob). Each mutation was confirmed to have actually modified the YAML before its result was trusted, and every one produced the expected failures.
Checklist