Skip to content

Match existing Gateway metadata through protected identities - #155

Merged
Pigbibi merged 1 commit into
mainfrom
codex/gateway-ip-match-readonly-20261001
Sep 30, 2026
Merged

Pigbibi merged 1 commit into
mainfrom
codex/gateway-ip-match-readonly-20261001

Conversation

@Pigbibi

@Pigbibi Pigbibi commented Sep 30, 2026

Copy link
Copy Markdown
Collaborator

Scope

Extend the existing read-only metadata diagnostic with an opt-in check of four existing Gateway targets, each using its existing target-specific WIF identity.

Changes

  • Read the matching inventory and expected private host only from protected repository Secrets.
  • Use index-only jobs, one at a time, fail fast; make one metadata query per target without connecting to the Gateway.
  • Return fixed match/no-match/unknown classifications and the generic index. A complete, unique result must be checked separately before using a mapping.
  • Preserve the existing single-target diagnostic and its variable configuration.
  • Reuse the sanitized failure classifier; do not add IAM, login, broker calls, deployment or trading operations.

Validation

  • Five matcher tests, including eleven payload subcases, passed.
  • Existing diagnostic/shared configuration shell checks and the failure classifier test passed.
  • Actionlint and diff check passed.
  • Independent review passed after limiting legacy configuration to the default mode and restoring sanitized failure classification.

Actual metadata access and unique matching remain separately unverified. Private IP ranges may overlap across projects; multiple or incomplete matches cannot identify an account or prove health.

@Pigbibi
Pigbibi merged commit 3fbcfc0 into main Sep 30, 2026
2 checks passed
@Pigbibi
Pigbibi deleted the codex/gateway-ip-match-readonly-20261001 branch September 30, 2026 19:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant