fix(forgejo): webhook deliveries to the PR-loop's LAN targets are refused (ALLOWED_HOST_LIST defaults to external) #57

Closed
opened 2026-10-09 23:41:16 +00:00 by pit · 0 comments
Owner

What happens

The Forgejo PR review+fix loop (homelab-blueprint#7) needs Forgejo to POST events to two LAN consumers: the n8n Guest, which takes the Forgejo events, and the Hermes host, which takes n8n's dispatch. Every delivery fails before it leaves the instance: the webhook's delivery record shows

webhook can only call allowed HTTP servers (check your webhook.ALLOWED_HOST_LIST setting), deny '<target>'

Evidence (not inferred)

  • The [webhook] section is absent from ansible/roles/forgejo/templates/app.ini.j2, so ALLOWED_HOST_LIST sits at its Gitea/Forgejo default, external, which since 1.16 denies RFC1918 targets by design.
  • Test: a throwaway repository webhook was pointed at a listener on the LAN that I control, its Test delivery was fired, and zero requests arrived — while the same listener answers immediately on the loopback interface, and the target host runs no firewall at all (nft, iptables and ufw all empty). The delivery never reached the network.

Suggested fix

Add to ansible/roles/forgejo/templates/app.ini.j2, ideally driven by a new var next to the existing ones in ansible/group_vars/forgejo/vars.yml (forgejo_webhook_allowed_host_list), so Prod and PRE stay in step:

[webhook]
; The review loop's consumers are on the LAN, so the `external` default refuses them.
ALLOWED_HOST_LIST = private

private covers all of RFC1918; a narrower list of the two consumer hosts is equally valid and tighter — worth deciding deliberately, since this setting governs every webhook on the instance, not only the loop's.

How to verify

After apply + restart: point a webhook at any listener on the LAN, hit Test delivery, and expect a 2xx. The delivery record on the webhook page shows the outcome; a green one there is the acceptance test. The loop's own end-to-end check is a throwaway Test delivery from the PR-loop hook, which should appear in n8n as an execution that answers 200 ignored.

Refs: homelab-blueprint#7 (spec), homelab-blueprint#8 (prototype).

## What happens The Forgejo PR review+fix loop (homelab-blueprint#7) needs Forgejo to POST events to two LAN consumers: the n8n Guest, which takes the Forgejo events, and the Hermes host, which takes n8n's dispatch. Every delivery fails before it leaves the instance: the webhook's delivery record shows ``` webhook can only call allowed HTTP servers (check your webhook.ALLOWED_HOST_LIST setting), deny '<target>' ``` ## Evidence (not inferred) - The `[webhook]` section is absent from `ansible/roles/forgejo/templates/app.ini.j2`, so `ALLOWED_HOST_LIST` sits at its Gitea/Forgejo default, `external`, which since 1.16 denies RFC1918 targets by design. - Test: a throwaway repository webhook was pointed at a listener on the LAN that I control, its *Test delivery* was fired, and **zero requests arrived** — while the same listener answers immediately on the loopback interface, and the target host runs no firewall at all (`nft`, `iptables` and `ufw` all empty). The delivery never reached the network. ## Suggested fix Add to `ansible/roles/forgejo/templates/app.ini.j2`, ideally driven by a new var next to the existing ones in `ansible/group_vars/forgejo/vars.yml` (`forgejo_webhook_allowed_host_list`), so Prod and PRE stay in step: ```ini [webhook] ; The review loop's consumers are on the LAN, so the `external` default refuses them. ALLOWED_HOST_LIST = private ``` `private` covers all of RFC1918; a narrower list of the two consumer hosts is equally valid and tighter — worth deciding deliberately, since this setting governs every webhook on the instance, not only the loop's. ## How to verify After apply + restart: point a webhook at any listener on the LAN, hit *Test delivery*, and expect a `2xx`. The delivery record on the webhook page shows the outcome; a green one there is the acceptance test. The loop's own end-to-end check is a throwaway *Test delivery* from the PR-loop hook, which should appear in n8n as an execution that answers `200 ignored`. Refs: homelab-blueprint#7 (spec), homelab-blueprint#8 (prototype).
pit closed this issue 2026-10-10 00:04:19 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
olympus/infra-forge#57
No description provided.