Populate sirens-deep web fetch egress allowlist #782

Closed
opened 2026-08-14 16:50:42 +00:00 by coilyco-ops-gaming · 1 comment

Kai requested populating the web fetch egress list so sirens-deep can fetch approved external content. Context: sirens-deep has issue-only Forgejo grants and no repo-content tool (see #633), so outbound web fetch is the path to reading sources.

Domains to allow:

  • wikipedia (en.wikipedia.org and related wiki domains)
  • github (github.com)
  • every coilysiren domain (coilysiren.me and its subdomains, e.g. forgejo.coilysiren.me, eco.coilysiren.me)
  • temporal.io
  • example.com
  • a dozen or so other general-purpose domains (exact list left to implementer; suggestions welcome)

Acceptance criteria:

  • Web fetch succeeds for every named domain.
  • Allowlist semantics: unlisted domains stay blocked by default.
  • The egress list location is documented so future requests can extend it.
Kai requested populating the web fetch egress list so sirens-deep can fetch approved external content. Context: sirens-deep has issue-only Forgejo grants and no repo-content tool (see #633), so outbound web fetch is the path to reading sources. Domains to allow: - wikipedia (en.wikipedia.org and related wiki domains) - github (github.com) - every coilysiren domain (coilysiren.me and its subdomains, e.g. forgejo.coilysiren.me, eco.coilysiren.me) - temporal.io - example.com - a dozen or so other general-purpose domains (exact list left to implementer; suggestions welcome) Acceptance criteria: - Web fetch succeeds for every named domain. - Allowlist semantics: unlisted domains stay blocked by default. - The egress list location is documented so future requests can extend it.
Member

Moved to coilyco-bridge/deploy#541 and closing here.

Forgejo has no cross-repo move, so the issue was recreated in the target repo with the body verbatim plus a provenance footer pointing back at this thread. Comments were not copied, so this thread stays the record for anything said here.

One edit to the copy: the bare #633 reference was qualified to coilyco-gaming/sirens-echo#633, because a bare number would have mis-resolved against deploy's own issue numbering.

Note: the Echo twin of this allowlist work stays here as #637.

Relocated by Darren (director seat) during the 2026-08-15 sirens-echo triage pass, acting on the move-to-repo/coilyco-bridge-deploy label. Reversible: reopen this issue and close the copy.

Moved to coilyco-bridge/deploy#541 and closing here. Forgejo has no cross-repo move, so the issue was recreated in the target repo with the body verbatim plus a provenance footer pointing back at this thread. Comments were not copied, so this thread stays the record for anything said here. One edit to the copy: the bare `#633` reference was qualified to `coilyco-gaming/sirens-echo#633`, because a bare number would have mis-resolved against deploy's own issue numbering. Note: the Echo twin of this allowlist work stays here as #637. Relocated by Darren (director seat) during the 2026-08-15 sirens-echo triage pass, acting on the `move-to-repo/coilyco-bridge-deploy` label. Reversible: reopen this issue and close the copy.
Sign in to join this conversation.
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
coilyco-gaming/sirens-echo#782
No description provided.