From 840e677b1388f4b1d6b485e9bf293c677d1f5521 Mon Sep 17 00:00:00 2001 From: Miguel Martinez Trivino Date: Mon, 31 Aug 2026 18:45:01 +0200 Subject: [PATCH] chore(devel): allow download.chainloop.dev egress in the sandbox kit Add the vanity EE CLI download host to the traced sandbox kit's network allowlist so the CLI installer can fetch binaries through it in addition to the azurefd origin. Assisted-by: Claude Code Signed-off-by: Miguel Martinez Trivino Chainloop-Trace-Sessions: 0f5545f7-2d2a-42b6-ac77-2761b445a17a, e4e8a764-7ec9-4a9f-98ac-f8fe7c21b9f2 --- devel/sandbox-kit/spec.yaml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/devel/sandbox-kit/spec.yaml b/devel/sandbox-kit/spec.yaml index 2780c2d9f..acaa1de70 100644 --- a/devel/sandbox-kit/spec.yaml +++ b/devel/sandbox-kit/spec.yaml @@ -369,7 +369,9 @@ permissions: # v1: `network.allowedDomains:` # used during attestation signing; host comes from the # control plane's signing options - "dl.chainloop.dev:443" # EE CLI installer - - "chainloop-baafegchfnekdcde.z02.azurefd.net:443" # EE CLI download CDN + - "download.chainloop.dev:443" # EE CLI download CDN (vanity host in front of the + # azurefd origin below; newer installers use it) + - "chainloop-baafegchfnekdcde.z02.azurefd.net:443" # EE CLI download CDN (azurefd origin) - "github.com:443" # git push over HTTPS in persistent mode - the # pre-push attestation egresses on push. Other # forges/self-hosted: add your own host here.