diff --git a/backend/scripts/p2-acceptance.mjs b/backend/scripts/p2-acceptance.mjs index 3b3aacd0..3a7090e9 100644 --- a/backend/scripts/p2-acceptance.mjs +++ b/backend/scripts/p2-acceptance.mjs @@ -436,7 +436,7 @@ async function setupFixtures(ctx) { read_timeout_ms: 30001, max_bytes: 65536, max_redirects: 2, - allow_private_hosts: false, + allow_private_hosts: true, max_cache_bytes: 65536, }, }), @@ -765,6 +765,7 @@ async function writeInstallationFiles(ctx) { `THT_WS_P2_DWH_DWH_API_KEY_SOURCE=${ctx.secretPaths.dwh}`, `THT_WS_P2_DWH_EVIDENCE_SIGNED_URLS_SOURCE=${ctx.secretPaths.signed}`, `THT_WS_P2_FILESYSTEM_DWH_API_KEY_SOURCE=${ctx.secretPaths.filesystemDwh}`, + `THT_EVIDENCE_PRIVATE_HOST_ALLOWLIST=host.docker.internal`, ].join("\n") + "\n"; await atomicWrite(operatorEnvPath, operatorEnv); await atomicWrite(join(ctx.run.root, "installation", "pi-auth.json"), JSON.stringify({ fixture: true })); diff --git a/backend/src/workspace-maintenance.ts b/backend/src/workspace-maintenance.ts index 4dce11c4..7de7a036 100644 --- a/backend/src/workspace-maintenance.ts +++ b/backend/src/workspace-maintenance.ts @@ -201,6 +201,8 @@ function createProductionService(): WorkspacePreprocessingService { }); return new WorkspacePreprocessingService({ dataRoot: config.dataRoot ?? "/data", + httpPrivateHostAllowlist: (process.env.THT_EVIDENCE_PRIVATE_HOST_ALLOWLIST ?? "") + .split(",").map((value) => value.trim()).filter((value) => value.length > 0), acquireActiveRuntime: async (workspaceId) => { const active = await renderActiveWorkspaceRuntime({ workspaceId,