Mirror URLs are checked against private, loopback and link-local addresses when saved (internal/control/mirrorcmd.go, via webhook.ValidateURL), but git makes the connection later with no re-check. A hostname that resolves publicly when saved and privately when the mirror runs reaches internal addresses. Webhooks re-check at connect time; mirrors do not.
- Resolve and check the host immediately before each sync and pass git a pinned address, or run mirror git through a proxy that enforces the same rule.
referenced in commit 4e0958a163 by cmc: plans: open issues from the architecture and UX reviews
2026-09-28 05:43 UTC