fix(LH-3904): propose exact Gemfury signed-download host admission - #284
Open
michal-larahealth wants to merge 1 commit into
Open
michal-larahealth wants to merge 1 commit into
michal-larahealth wants to merge 1 commit into
Conversation
michal-larahealth
marked this pull request as ready for review
October 1, 2026 09:49
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What are you trying to accomplish?
Propose an exact-host exception for Gemfury's signed Python artifact downloads. Authenticated requests to its documented PyPI endpoint succeed, then redirect package downloads to
gemfury.s3-accelerate.dualstack.amazonaws.com, which the egress proxy blocks. This adds one exact host under the Python anchor shared by pip and uv; it does not configure registry authentication.Reference: Gemfury PyPI endpoint documentation and GitHub blocked-host guidance. Ownership evidence is the HTTPS redirect issued by the provider's authenticated index. No private artifact paths or signed URLs are included.
Anything you want to highlight for special attention from reviewers?
Draft policy-exception proposal; maintainer acceptance is required. The repository's allowlist skill prohibits shared multi-tenant path hosts in static defaults. This exact, existing provider bucket contains customer-uploaded objects. The handler unions defaults for every job; placement under Python does not limit access to Python jobs or to one customer's paths. Exact matching blocks other buckets and child hosts but does not close that path boundary. Please assess whether this exception is acceptable, or prefer a proxy fix for credential-free per-job admission.
A per-job anonymous
python-indexdeclaration is currently not a working alternative: the static Python handler supplies empty Basic authentication. A live signed download returned HTTP 200 without Authorization and HTTP 400 with that empty header. Index credentials were never sent to the download host. The proposal adds no secrets, no arbitrary S3 wildcard, no runner change, and no authentication handler change.How will you know you've accomplished your goal?
Synthetic egress tests admit the exact artifact host and reject its child, a sibling bucket and the S3 apex. A temporary leading-dot mutation failed the negative test and was restored. Hosted deployment must subsequently be verified by a fresh successful package update; a merge alone is not deployment evidence. Rollback removes the exact default entry.
Validation
go build ./...go test ./internal/handlers/ -run TestEgress -count=1go vet ./...gofmt -l internal/handlers/egress_allowlist_test.go(no output)git diff --checkTestEgressAllowlist_NewEntriesDoNotWidenBeyondExactHosts; exact entry restored.script/testDocker race suite, lint and four-platform build matrix in CI.7264725; maintainer policy acceptance and hosted deployment remain pending.Test Cases
Synthetic admission boundaries
Checklist
script/test, lint and the complete smoke matrix).