fix(forgejo): admit the PR loop's LAN webhooks (ALLOWED_HOST_LIST = private) #58
No reviewers
Labels
No labels
needs-info
needs-triage
ready-for-agent
ready-for-human
wontfix
needs-info
needs-triage
ready-for-agent
ready-for-human
review/merge-ready
review/needs-fix
review/needs-human
review/needs-review
wayfinder:grilling
wayfinder:map
wayfinder:prototype
wayfinder:research
wayfinder:task
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
olympus/infra-forge!58
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "hermes/57-fix-local-webhooks"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
The
[webhook]section was absent from the templatedapp.ini, soALLOWED_HOST_LISTsat at its effectiveexternaldefault — which admits no RFC 1918 address — and the PR loop's deliveries to the n8n Guest and the Hermes host were refused before they left the instance. Template it from one shared variable:ansible/group_vars/forgejo/vars.yml—forgejo_webhook_allowed_host_list: private. One value, so PROD and PRE stay in step: the loop's consumers are the same on both.docs/adr/0006-webhook-lan-delivery.md— the deliberate decision the issue asked for:private(the LAN as a network class) over naming the two consumer hosts, with the rejected alternative and what it costs.Evidence
Rehearsed on PRE (
make pre, PLAY RECAPok=43 changed=29 failed=0). A throwaway repo webhook pointed at a listener on the LAN, Test delivery fired — the instance's own delivery record and the listener agree:external, same hook and same listener —is_succeed=f, responseDelivery: Post "http://10.12.0.214:8080/": ... webhook can only call allowed HTTP servers (check your webhook.ALLOWED_HOST_LIST setting), deny '10.12.0.214(10.12.0.214:8080)'— the delivery never left the instance.After:
private—is_succeed=t, response{"status":200,"body":"ignored\n"}, and the listener loggedPOST / event=push len=6153.Negative control — the allowlist is still a fence, not an open door: a target of
http://8.8.8.8/is refuseddeny '8.8.8.8(8.8.8.8:80)'.ansible-playbook --syntax-check site.ymlandmake fmtare clean.Not rehearsed: the loop's own end-to-end check (a throwaway delivery appearing in n8n as an execution answering
200 ignored) — the n8n Guest and homelab-blueprint are not reachable from here, so the generic LAN-listener variant stands in for it.Merge Danger
Door: two-way
The service config is templated, so the previous commit is the previous state:
git revertthis commit and re-run the service playbook, and the effective default returns.Blast Radius: instance-wide
ALLOWED_HOST_LISTgoverns every webhook on the instance, not only the loop's, so any webhook may now POST to any RFC 1918 / RFC 4193 / RFC 6598 address. The counterpart: public-internet targets are now refused —privatereplaces the effectiveexternaldefault rather than adding to it, so a future webhook to a public host must nameexternalexplicitly. Reasoning and costs in ADR 0006.Closes #57