Skip to content

Add OCI and changelog release notes registries to egress allowlist - #280

Merged
v-abhishekbhaskar merged 1 commit into
mainfrom
abhishekbhaskar/add-oci-public-registries-allowlist
Sep 30, 2026
Merged

v-abhishekbhaskar merged 1 commit into
mainfrom
abhishekbhaskar/add-oci-public-registries-allowlist

Conversation

@v-abhishekbhaskar

Copy link
Copy Markdown
Contributor

What are you trying to accomplish?

Restores three classes of legitimate traffic that the egress allowlist is blocking in production.

1. Public OCI registries

registry.access.redhat.com and cgr.dev (Chainguard) are anonymous public registries that were never allowlisted. Tracing their pull chains surfaced two things the issues do not mention:

  • Chainguard redirects blob downloads to 9236a389bd48b984df91adc1bc924620.r2.cloudflarestorage.com, so allowlisting cgr.dev alone still fails on blob fetch.
  • quay.io was allowlisted as an exact host, but Quay 302s blob downloads to cdn01.quay.io. Tag discovery therefore succeeded while every blob pull was blocked — a latent bug affecting all Quay-hosted images, not just Red Hat's (Red Hat blobs also land on cdn01.quay.io). This is changed to .quay.io.

2. Public registries and mirrors : maven-central-eu.storage-download.googleapis.com, maven.vaadin.com, libraries.minecraft.net, versions.backstage.io.

3. Changelog/release-note hosts. Dependabot follows project_urls from PyPI metadata and <url> from POMs to render release notes in pull requests. These were blocked, which silently degrades PR bodies without breaking resolution.

Anything you want to highlight for special attention from reviewers?

The changelog hosts are a new precedent. Until now the allowlist held only package infrastructure. These are documentation sites, so they widen egress for PR-body quality rather than for update correctness.

.quay.io is the only non-exact entry added. A leading dot is safe here specifically because Quay tenancy is path-based (quay.io/<org>/<repo>), so no subdomain is user-creatable — the same rationale as the existing .gcr.io and .pkg.dev. Every other entry is exact.

anyio.readthedocs.io is the head of a long tail. Read the Docs subdomains are project-creatable, so .readthedocs.io would be an exfiltration channel and must never be used. The entry is exact, with readthedocs.io and evil.readthedocs.io probes and a YAML comment to stop a later "simplification". Expect more one-off Python docs hosts to surface.

Two hosts redirect across origins, so both ends of each chain are required: docs.pydantic.dev 301s to pydantic.dev, and psycopg.org 302s to www.psycopg.org. Allowlisting only the recorded host would break mid-chain — the same shape as the existing packages.atlassian.com entry.

Three high-volume hosts were deliberately excluded and have tests asserting they stay blocked: cs.android.com, docs.aws.amazon.com and issues.apache.org. None carries a changelog Dependabot renders, so allowlisting them would widen egress for no functional gain.

How will you know you've accomplished your goal?

Every added host was verified on the wire before being added — anonymous fetch of a real artifact, with the full redirect chain traced:

  • libraries.minecraft.net — 200, real 77 KB brigadier jar
  • maven.vaadin.com — 200, real maven-metadata.xml
  • maven-central-eu.storage-download.googleapis.com — 200, real slf4j POM
  • versions.backstage.io — 200, 20 KB manifest
  • registry.access.redhat.com — /v2/ returns 200 with no auth challenge; blobs 302 to cdn01.quay.io
  • cgr.dev — /v2/ 401 with token realm on the same host; blobs 307 to the Cloudflare R2 host
  • All eight changelog pages return 200

Test coverage:

  • TestEgressAllowlist_PublicVendorOCIRegistriesAllowed — extended for Red Hat and Chainguard, including blob redirect targets
  • TestEgressAllowlist_QuayCDNSubdomainsAllowed — new; covers cdn01–cdn99, and asserts quay.io.attacker.com and registry.redhat.io stay blocked
  • TestEgressAllowlist_PublicEcosystemMirrorsAllowed — extended with the four public registries plus child/lookalike probes
  • TestEgressAllowlist_ChangelogHostsAllowed — new; 10 allowed, 12 blocked, covering the readthedocs namespace, the three excluded hosts, and lookalike parents
  • TestEgressDefaults_NoRedundantEntries — caught a real duplicate during development (a second quay.io left in the helm list, now removed)

Every new guard was mutation-tested: 17 mutations in total (dropping each entry, and widening each to a leading dot or glob). Each mutation was confirmed to have actually modified the YAML before its result was trusted, and every one produced the expected failures.

Checklist

  • I have run the complete test suite to ensure all tests and linters pass.
  • I have thoroughly tested my code changes to ensure they work as expected, including adding additional tests for new functionality.
  • I have written clear and descriptive commit messages.
  • I have provided a detailed description of the changes in the pull request, including the problem it addresses, how it fixes the problem, and any relevant details about the implementation.
  • I have ensured that the code is well-documented and easy to understand.

@v-abhishekbhaskar v-abhishekbhaskar self-assigned this Sep 30, 2026
Copilot AI balanced review requested due to automatic review settings September 30, 2026 06:40
@v-abhishekbhaskar
v-abhishekbhaskar requested a review from a team as a code owner September 30, 2026 06:40

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Several exact changelog hosts lack child probes that prevent unsafe suffix widening.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Expands the egress allowlist for public OCI registries, ecosystem mirrors, and release-note hosts.

Changes:

  • Adds OCI registries, redirect targets, and public mirrors.
  • Broadens Quay matching to provider-controlled subdomains.
  • Adds allow/block regression coverage.
File Description
internal/​handlers/​egress_allowlist_defaults.yaml Adds and documents allowlisted domains.
internal/​handlers/​egress_allowlist_test.go Tests new hosts and matching boundaries.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +1134 to +1140
// Exact entries must not widen to children or lookalike parents.
"https://evil.docs.pytest.org/payload",
"https://docs.pytest.org.attacker.com/payload",
"https://pytest.org/payload",
"https://evil.developer.android.com/payload",
"https://android.com/payload",
"https://apache.org/payload",
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants