Skip to content

[Forwarder]: Remove allowlist check - #206

Merged
Vaughan-Temporal merged 3 commits into
mainfrom
vaughan/forwarder-drop-allowlist
Oct 7, 2026
Merged

Vaughan-Temporal merged 3 commits into
mainfrom
vaughan/forwarder-drop-allowlist

Conversation

@Vaughan-Temporal

Copy link
Copy Markdown
Contributor

The forwarder's allowlist check is redundant. With the per-upstream socket removed in #205, the gateway's router.Handler is the forwarder's only caller, and it already rejects services outside the allowlist before routing. This removes the check and the forwarder's allowlist dependency.

pseudomuto and others added 2 commits October 6, 2026 14:43
Since #198 the gateway hands each accepted stream straight to the
upstream's Forwarder.Handle, so nothing in the proxy dials the
per-upstream socket any more. It was kept for local workers dialing it
directly, but that is not a supported access path: workers only ever
connect through the gateway, and the socket's path was a hash under the
temp dir that nothing exposed.

This removes the socket and everything that existed to serve it:
internal/transport/socket, proxy.Server, and Dataplane.SocketPath.
Start now opens the static upstream connections and binds the gateway.
Stop drains only the gateway, so the concurrent per-upstream drain and
its deadline arithmetic go with it.
The gateway's router.Handler rejects services outside the allowlist before routing, and with the per-upstream socket gone it is the forwarder's only caller, so the forwarder's own check can never fire. Forwarder no longer takes an allowlist.
@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@Vaughan-Temporal
Vaughan-Temporal marked this pull request as ready for review October 6, 2026 22:59
@Vaughan-Temporal
Vaughan-Temporal requested review from a team and pseudomuto as code owners October 6, 2026 22:59
@Vaughan-Temporal Vaughan-Temporal changed the title Vaughan/forwarder drop allowlist [Forwarder]: Remove allowlist check Oct 6, 2026
@Vaughan-Temporal
Vaughan-Temporal merged commit 869c1e9 into main Oct 7, 2026
6 checks passed
@Vaughan-Temporal
Vaughan-Temporal deleted the vaughan/forwarder-drop-allowlist branch October 7, 2026 18:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants