fix(cli): let veryfront eval reach an operator-set private Veryfront API - #4506
Conversation
`veryfront eval` against staging failed every record with "Outbound network egress blocked for host: api.veryfront.org", and gateway billing finalization was skipped the same way. Staging is reachable only over the tailnet, so its public DNS answer is a private address, and the host egress guard rejects that as request forgery for both the Veryfront Cloud gateway fetch and billing finalization. `veryfront eval` now seals the origins of VERYFRONT_API_URL and VERYFRONT_API_BASE_URL from the process environment before it loads project config or agent modules. The Veryfront Cloud gateway and billing transport lets exactly those origins resolve to a private address. - Values copied from a project .env file, veryfront.json endpoints, scoped request contexts, and server-returned URLs are not trusted. - The set is sealed on first use, so later environment writes cannot widen it. - Only the Veryfront API transport consults it. Provider, OIDC, remote tool, and project-configured transports keep the private-address block. - Redirects stay rejected and other destination origins stay unauthorized. - Hosted runtimes and `veryfront serve` never seal the set, so pods where VERYFRONT_API_URL names a cluster-internal service are unchanged. Refs veryfront/veryfront-issue-inbox#1444
|
Warning Review limit reachedNext included review available in 18 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Repository UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (8)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
📦 Client bundle boundary
A server module in a client graph aborts hydration in the browser. New leaks fail CI; known leaks are tracked in |
|
You have reached your Codex usage limits for security reviews. Please try again later. |
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
|
@codex review |
|
Codex Review: Didn't find any major issues. Swish! Reviewed commit: ℹ️ About Codex in GitHubCodex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback". |
Codecov Report❌ Patch coverage is
📢 Thoughts on this report? Let us know! |
…unit boundary Two new tests stubbed only the plain transport. Node and Bun take the pinned path for every guarded request, so they opened a real socket to the private test address and timed out. Every stub transport now supplies pinnedFetch. The Veryfront Cloud fetch test mutated process environment in shared.test.ts, which the semantic unit-boundary audit classifies as network-only. It moves to provider.test.ts, which already owns process state. The private-DNS helper no longer passes an init argument its stub ignores. Refs veryfront/veryfront-issue-inbox#1444
|
You have reached your Codex usage limits for security reviews. Please try again later. |
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
|
@codex review |
|
Codex Review: Didn't find any major issues. 🎉 Reviewed commit: ℹ️ About Codex in GitHubCodex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback". |
|



Description
veryfront evalagainst the staging Veryfront API failed every record withOutbound network egress blocked for host: <host>, and gateway billing finalization was skipped the same way. The staging API is reachable only over the tailnet, so its public DNS answer is a private address. The host egress guard rejects that as request forgery for both the Veryfront Cloud gateway fetch and billing finalization.Root cause:
src/security/sandbox/worker-egress-guard.ts(resolveWorkerHostEgressAddresses) throwsWorker network egress blocked for hostfor a private DNS answer.src/security/http/outbound-fetch.ts(fetchWithBoundaryErrors) rethrows it asOutboundRequestBlockedError.src/provider/veryfront-cloud/shared.ts(createVeryfrontCloudFetch) andcli/commands/eval/command.ts(finalizeGatewayBillingGroup) both usecreateOriginBoundOutboundFetch(apiBaseUrl). The only exemptions wereVERYFRONT_HOST_ALLOWED_INTERNAL_PROVIDER_ORIGINSandVERYFRONT_HOST_ALLOW_INTERNAL_EGRESS.Fix:
evalCommandcallstrustOperatorConfiguredVeryfrontApiOrigins()before it loads project config or agent modules. The call seals the origins ofVERYFRONT_API_URLandVERYFRONT_API_BASE_URLfrom the process environment, read throughgetHostEnvExcludingEnvFile.createVeryfrontApiOriginBoundOutboundFetch()lets exactly those origins resolve to a private address. The Veryfront Cloud gateway fetch and billing finalization use it.Security reasoning:
.envfile,veryfront.jsonendpoints, scoped request contexts, and server-returned URLs are ignored. This matches the CLI's existing rule that repository-steered API hosts need shell confirmation.veryfront servenever seal the set. TheirVERYFRONT_API_URLnames a cluster-internal service, so this change does not loosen them.Verified against staging from a tailnet machine with a placeholder token:
Outbound network egress blocked for host: <staging API host>for the model request and billing finalization.Related Issue(s)
Refs https://github.com/veryfront/veryfront-issue-inbox/issues/1444
The eval classification for a blocked model request is stacked on #4505 in a separate PR.
Type of Change
Checklist
Verification:
deno task test:fileforsrc/security/http/,src/security/sandbox/,src/security/application-auth/,src/provider/veryfront-cloud/,cli/commands/eval/,src/sandbox/,src/embedding/,src/provider/model-registry.test.ts, andsrc/platform/adapters/veryfront-api-transport.test.ts: all passdeno task typecheck,deno task lint,deno task fmt:check,deno task lint:test-typecheck, anddeno task docs:public:check: passlint:module-boundaries,lint:dependency-boundaries,lint:ban-test-only,lint:cli-boundary,lint:check-awaits,lint:anti-slop,lint:secret-scanning-config, andlint:testing-front-door: pass