fix(forgejo): webhook deliveries to the PR-loop's LAN targets are refused (ALLOWED_HOST_LIST defaults to external) #57
Labels
No labels
needs-info
needs-triage
ready-for-agent
ready-for-human
wontfix
needs-info
needs-triage
ready-for-agent
ready-for-human
review/merge-ready
review/needs-fix
review/needs-human
review/needs-review
wayfinder:grilling
wayfinder:map
wayfinder:prototype
wayfinder:research
wayfinder:task
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
olympus/infra-forge#57
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What happens
The Forgejo PR review+fix loop (homelab-blueprint#7) needs Forgejo to POST events to two LAN consumers: the n8n Guest, which takes the Forgejo events, and the Hermes host, which takes n8n's dispatch. Every delivery fails before it leaves the instance: the webhook's delivery record shows
Evidence (not inferred)
[webhook]section is absent fromansible/roles/forgejo/templates/app.ini.j2, soALLOWED_HOST_LISTsits at its Gitea/Forgejo default,external, which since 1.16 denies RFC1918 targets by design.nft,iptablesandufwall empty). The delivery never reached the network.Suggested fix
Add to
ansible/roles/forgejo/templates/app.ini.j2, ideally driven by a new var next to the existing ones inansible/group_vars/forgejo/vars.yml(forgejo_webhook_allowed_host_list), so Prod and PRE stay in step:privatecovers all of RFC1918; a narrower list of the two consumer hosts is equally valid and tighter — worth deciding deliberately, since this setting governs every webhook on the instance, not only the loop's.How to verify
After apply + restart: point a webhook at any listener on the LAN, hit Test delivery, and expect a
2xx. The delivery record on the webhook page shows the outcome; a green one there is the acceptance test. The loop's own end-to-end check is a throwaway Test delivery from the PR-loop hook, which should appear in n8n as an execution that answers200 ignored.Refs: homelab-blueprint#7 (spec), homelab-blueprint#8 (prototype).