Allow Gitea webhooks to reach private-LAN hosts
Webhook delivery to jenkins.192.168.1.7.nip.io failed: "webhook can only call allowed HTTP servers (check your security.ALLOWED_HOST_LIST setting)". Gitea's SSRF protection blocks outbound webhook calls to private/internal IPs by default. Set to "*" rather than a narrow allowlist — every host on this homelab is on the same private LAN, so a per-host allowlist would just need updating every time a new service needs webhook access, matching the lightweight security posture already used elsewhere (ArgoCD --insecure, plain HTTP throughout).
This commit is contained in:
@@ -64,6 +64,17 @@ gitea:
|
|||||||
DB_TYPE: sqlite3
|
DB_TYPE: sqlite3
|
||||||
actions:
|
actions:
|
||||||
ENABLED: true
|
ENABLED: true
|
||||||
|
security:
|
||||||
|
# Gitea's own SSRF protection blocks outbound webhook calls to
|
||||||
|
# private/internal IPs by default — hit this trying to fire a
|
||||||
|
# webhook at jenkins.192.168.1.7.nip.io ("webhook can only call
|
||||||
|
# allowed HTTP servers"). Everything on this homelab lives on a
|
||||||
|
# private LAN, so a narrow allowlist would just mean editing
|
||||||
|
# this every time a new *.192.168.1.7.nip.io/*.100.90.248.118.nip.io
|
||||||
|
# host needs webhook access — matches the lightweight security
|
||||||
|
# posture already used elsewhere here (ArgoCD --insecure, plain
|
||||||
|
# HTTP throughout).
|
||||||
|
ALLOWED_HOST_LIST: "*"
|
||||||
admin:
|
admin:
|
||||||
username: gitadmin
|
username: gitadmin
|
||||||
# The running install set this via a plaintext --set-string flag at
|
# The running install set this via a plaintext --set-string flag at
|
||||||
|
|||||||
Reference in New Issue
Block a user