docs(zed-fim-proxy): source-IP allowlist stays OFF by design (Zed roams WG 10.0.0.0/8)

This commit is contained in:
vh
2026-07-27 22:58:22 -07:00
parent a300cdcd26
commit 792aa2852c
3 changed files with 13 additions and 10 deletions
+6 -5
View File
@@ -26,11 +26,12 @@ safe if it can't be pivoted:
(`POST /key/generate {"models":["coder-fast"]}`). Even if guards 1–2 were
bypassed, the key reaches nothing else (verified: 403 on `gen`). **This is the
real blast-radius bound.**
4. **Best-effort source-IP allowlist** (`ZED_ALLOWED_IPS`) — only enforceable if
the proxy sees the real client IP (hence `network_mode: host`; docker
port-publish would NAT it away). A site-to-site NAT may still mask the Mac's
`10.0.10.83` — verify against `docker logs zed-fim-proxy` and tighten. Internal
network only; no public exposure.
4. **Source-IP allowlist** (`ZED_ALLOWED_IPS`) — **intentionally left OFF**
(operator direction 2026-07-27): Zed roams the operator's WireGuard
`10.0.0.0/8`, so a single-IP pin would break it. **Do NOT tighten.** The
keyless route is bounded by guards 1–3 (coder-fast-only, `/v1/completions`-only,
scoped key) and is internal-network only. (The proxy matches exact IPs; a
`10.0.0.0/8` CIDR would need CIDR support — deliberately not added.)
## Deploy