Documentation
¶
Index ¶
Constants ¶
This section is empty.
Variables ¶
var ( DefaultHttpClient *http.Client ProxyHttpClient *http.Client )
var ErrBlocked = errors.New("proxy: refused to dial a non-public address")
ErrBlocked reports a URL that resolved to an address this package refuses to dial. It is distinguishable from a site that was merely down, because a log line that cannot tell the two apart makes an attack look like an outage.
var Public = &http.Client{ Timeout: publicTimeout, Transport: guarded(), CheckRedirect: func(req *http.Request, via []*http.Request) error { if len(via) >= maxRedirects { return fmt.Errorf("proxy: stopped after %d redirects", maxRedirects) } if s := req.URL.Scheme; s != "http" && s != "https" { return fmt.Errorf("%w: redirect to scheme %q", ErrBlocked, s) } return nil }, }
Public is the client for a URL chosen by whoever wrote the request. This process runs inside the cluster, where in-namespace service names resolve and 169.254.169.254 hands out credentials to anyone who asks, so an unrestricted GET on a caller-supplied URL is a credential read, not a fetch.
The address check is in the DIALER. A hostname checked before the request is resolved again by the transport, and a name that answers differently the second time walks through the gap between the two lookups; dialing is the one moment the real destination is known. Redirects re-enter the same dialer, so a public URL that redirects to 169.254.169.254 is refused at the hop that matters.
Functions ¶
func GetHttpClient ¶
GetHttpClient answers the client a URL should be fetched with, and always answers one.
The two package clients are filled by InitHttpClient at boot, so anything running before that line got nil and dereferenced it — a panic rather than a request. Three tests already worked around it by calling InitHttpClient themselves, which is the ordering problem stated out loud.
The fallback is http.DefaultClient, which is what the non-proxy path resolves to anyway; a deployment that configured a proxy still gets it, because by then InitHttpClient has run.
func InitHttpClient ¶
func InitHttpClient()
func Local ¶ added in v1.833.53
Local returns the client to use for a base URL, or nil to take the verifying default. A non-nil result accepts any certificate and is returned ONLY for this machine, where a model server's certificate is self-signed because nobody issues one for 127.0.0.1. Anything that does not clearly name this machine — a look-alike host, an unparseable URL — is remote and verifies.
Types ¶
This section is empty.