summaryrefslogtreecommitdiff
path: root/doc/security/webhooks.md
diff options
context:
space:
mode:
authorReuben Pereira <rpereira@gitlab.com>2019-08-08 16:54:52 +0000
committerAchilleas Pipinellis <axil@gitlab.com>2019-08-08 16:54:52 +0000
commit409126c891a40cb104e91d76e6ef99a327602bb4 (patch)
treea74caa0546666856c9940843ec25b7a4244bf35b /doc/security/webhooks.md
parent79bff3ee7a0d2d91faedeadb1965966f7551b62c (diff)
downloadgitlab-ce-409126c891a40cb104e91d76e6ef99a327602bb4.tar.gz
Add docs for local requests whitelist
- Add documentation under security/webhooks since similar docs are present there.
Diffstat (limited to 'doc/security/webhooks.md')
-rw-r--r--doc/security/webhooks.md30
1 files changed, 30 insertions, 0 deletions
diff --git a/doc/security/webhooks.md b/doc/security/webhooks.md
index 7ece9407ac0..e39bc9a9626 100644
--- a/doc/security/webhooks.md
+++ b/doc/security/webhooks.md
@@ -45,6 +45,36 @@ NOTE: **Note:**
set up by administrators. However, you can turn this off by disabling the
**Allow requests to the local network from system hooks** option.
+## Whitelist for local requests
+
+> [Introduced](https://gitlab.com/gitlab-org/gitlab-ce/issues/44496) in GitLab 12.2
+
+You can allow certain domains and IP addresses to be accessible to both *system hooks*
+and *webhooks* even when local requests are not allowed by adding them to the
+whitelist. Navigate to **Admin Area > Settings > Network** (`/admin/application_settings/network`)
+and expand **Outbound requests**:
+
+![Outbound local requests whitelist](img/whitelist.png)
+
+The whilelist entries can be separated by semicolons, commas or whitespaces
+(including newlines) and be in different formats like hostnames, IP addresses and/or
+IP ranges. IPv6 is supported. Hostnames that contain unicode characters should
+use IDNA encoding.
+
+The whitelist can hold a maximum of 1000 entries. Each entry can be a maximum of
+255 characters.
+
+Example:
+
+```text
+example.com;gitlab.example.com
+127.0.0.1,1:0:0:0:0:0:0:1
+127.0.0.0/8 1:0:0:0:0:0:0:0/124
+```
+
+NOTE: **Note:**
+Wildcards (`*.example.com`) and ports (`127.0.0.1:3000`) are not currently supported.
+
<!-- ## Troubleshooting
Include any troubleshooting steps that you can foresee. If you know beforehand what issues