Repository navigation
docs(onprem): list the built-in NO_PROXY names and where each component reads extra CAs - #16238
Conversation
…nt reads extra CAs Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Adversarial review: CHANGES REQUESTEDReviewed head What I verified
Not verified
Findings
Break attempts
|
…XY and egress-rule caveats Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Thanks for the review. Every finding is addressed in bca8865:
Not verified: the sensei-engine CA row. I could not confirm from the engine's source whether Build check: 🤖 Generated with Claude Code |
Re-review: CHANGES REQUESTEDRe-reviewed head First-pass findings
Still open (both in
|
…n unusable proxy fails closed Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Thanks for the re-review. Both open items are fixed in 9d2c383. The paragraph under the variables table now reads:
🤖 Generated with Claude Code |
Re-review: APPROVE WITH NITSRe-reviewed head Last pass's items
Nit"a short name such as
Both requests then dialed the proxy. Suggest moving "is refused" into the Python-services sentence, or saying "may be refused". The advice to always write the scheme is right either way. The Go SOCKS5 pointThis came from the reply, not the page. In go1.26.5, Go's standard transport accepts Gates
Merge together with the paired application change. |
… services Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Thanks for the review. The nit is fixed in 0011a16. The "is refused" clause now sits inside the Python-services sentence, so the page no longer reads as describing the whole stack. The paragraph is now:
🤖 Generated with Claude Code |
Re-review: APPROVERe-reviewed head The rewritten paragraph, checked against the code
Gates
Merge together with the paired application change. That change still needs a merge with its base branch and a full CI run before it can land. |
Description
Updates the "Running DefectDojo Behind a Forward HTTPS Proxy" page for the self-hosted Docker Compose changes in the paired Pro release (3.4.100):
dojo,dojo-import-scan,celeryworker,celerybeat,init,ddorch-workers,connectors,integrators), and the five that gain them in 3.4.100 (nginx,ddorch,mcp-server,webhook-gateway,sensei-engine). The old text named auwsgicontainer, which the bundle does not have.HTTPS_PROXY,HTTP_PROXYandNO_PROXYfrom 3.4.100; earlier releases fetched feeds directly.dd-netnetwork the bundle now always puts at the start ofNO_PROXY, explains that an operator'sNO_PROXYis appended rather than replacing it, and documentsDD_INTERNAL_NO_PROXYfor replacing the built-in part.dojo-ca-bundle.crtfor the application containers, now includingcelerybeatandinit;connectors-ca-bundle.crt;DD_MCP_CA_BUNDLE;SENSEI_SSL_CERT_FILE; the webhook gateway's internal CA), with the host and container paths.English only (this page has no translations). The paired Pro change ships in the same release; merge the two together.
Test results
Docs only.
hugo --minify --gcindocs/builds with no warnings or errors, and the rendered page carries the new#trusting-the-proxys-caand NO_PROXY section anchors that the in-page links point to.🤖 Generated with Claude Code