globalExtends from an internal host can't be granted via hostRules, and ignores internalHostAccess #46630
Unanswered
lindeskar
asked this question in
Request Help
Replies: 1 comment 1 reply
|
Interesting! (And good to see another use-case for how folks use Yes, we'd be happy with a fix to make it so |
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
How are you running Renovate?
Self-hosted Renovate CLI
Which platform you running Renovate on?
GitHub.com
Which version of Renovate are you using?
44.127.1 (first seen on 44.103.0)
Please tell us more about your question or problem
globalExtendspresets from an internal host can't be granted withhostRules/allowInternal, andinternalHostAccessisn't applied to them either. It looks like they're fetched before either is set up.We serve our global preset from a sidecar on
http://localhost:8088, mainly so the earlyglobalExtendsfetch doesn't use GitHub's anonymous rate limit. Since 44.10x every run logs the "internal host whose response becomes configuration" warning for it, and we can't find any config that clears it:hostRules: [{ matchHost: 'http://localhost:8088', allowInternal: true }], still warns;internalHostAccess: 'block'also only warns, and the preset is still fetched and merged;internalHostAccess: 'allow'also still warns.So once the default becomes
block, I think anyglobalExtendsfrom an internal host will be refused whatever the admin configures.Code checked with Claude Code:
getGlobalConfig()→parseConfigs()resolvesglobalExtendsbeforeGlobalConfig.set({ internalHostAccess, … })and beforeglobalInitialize()registershostRules(lib/workers/global/index.ts, lib/workers/global/config/parse/index.ts). The fetch is therefore judged against the built-inwarndefault, with no grants. The comment at theGlobalConfig.setcall shows the same problem was already handled for the platform's own init requests, so maybeglobalExtendsjust needs the same treatment? E.g. applyinternalHostAccessand the file/envhostRulesbeforeresolveGlobalExtends().Minimal reproduction
config.js:Serve
default.json({ "labels": ["from-global-extends"] }) on localhost, then run against any local git repo:Expected: no warning, since the host has a scoped
allowInternalgrant. UnderinternalHostAccess: 'block'with no grant, the request should be refused.Actual: one WARN as below, and the preset is fetched and merged (
from-global-extendsends up in the resolved config), with the grant or without it, underblock,warnandallowalike.Logs (if relevant)
Logs
Investigation and reproduction done with help from Claude.
All reactions