[security-observability] Daily Security Observability Report — 2026-06-11 #38686
Replies: 2 comments
-
|
Smoke test ping from run 27369048194: discussion query + comment path exercised. Warning Firewall blocked 6 domainsThe following domains were blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "safebrowsingohttpgateway.googleapis.com"
- "www.google.com"See Network Configuration for more information.
|
Beta Was this translation helpful? Give feedback.
-
|
Me bonk drum. Smoke run live on PR #38684. Fire still good. Warning Firewall blocked 6 domainsThe following domains were blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "accounts.google.com"
- "android.clients.google.com"
- "clients2.google.com"
- "contentautofill.googleapis.com"
- "safebrowsingohttpgateway.googleapis.com"
- "www.google.com"See Network Configuration for more information.
|
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Executive Summary
The daily security observability analysis for 2026-06-11 covers 45 firewall-enabled workflow runs across 28 distinct workflows. The firewall intercepted 197 blocked requests out of 2,225 total (8.9% block rate), with all blocked traffic originating from Smoke test workflows whose browser automation components attempt connections to Google services and Playwright CDN endpoints not on the allowlist. No DIFC integrity-filtered events were recorded in the last 7 days, indicating clean information-flow control across all agentic runs.
The dominant firewall pressure comes from browser-based smoke tests (Smoke Copilot, Smoke Claude, Smoke Codex, Smoke Copilot AOAI) which collectively account for 182 of the 197 blocked requests — driven by Chrome/Chromium telemetry and content-autofill calls to Google. The
Smoke Antigravityworkflow had a 100% block rate (10/10 requests blocked), as it targets domains not in the allowlist. These patterns are expected for smoke-test workflows and represent opportunities for targeted allowlist tuning.🔥 Firewall Analysis
Key Firewall Metrics
📈 Firewall Request Trends
Firewall activity shows variability over the tracked window. The spike on May 20 (735 blocked / 2,560 allowed) reflects a period of higher smoke-test volume. June 8–10 saw minimal blocking (3–4 requests), while today (Jun 11) returned to elevated blocking at 197 — driven by browser automation in smoke tests hitting restricted Google and Playwright endpoints.
Top Blocked Domains
The vast majority of blocked requests target Google content and auth services consistently intercepted in browser-based smoke tests. The
Smoke Antigravityworkflow uniquely drives blocks againstantigravity-unleash.googand three Playwright CDN endpoints, confirming it needs dedicated allowlist entries.Most Frequently Blocked Domains
View Detailed Request Patterns by Workflow
View Complete Blocked Domains List (Alphabetical)
🔒 Firewall Security Recommendations
--disable-background-networking --disable-syncflags to eliminate the 183 Google-domain blocks, rather than allowlisting Google auth/telemetry endpoints.playwright.azureedge.net,playwright-akamai.azureedge.net,playwright-verizon.azureedge.netto theSmoke Antigravityworkflow policy if browser binary download is required.antigravity-unleash.googintent: If the Smoke Antigravity workflow requires this feature-flag domain, add it to the allowlist. Document the expected 100% block rate if not.Smoke Geminilocalhost:8080 probe: A local port 8080 probe was blocked — likely a misconfigured service dependency. Confirm whether a local proxy is expected.proxy.golang.orgblock in Smoke Pi: The Go module proxy is on the global allowlist but was blocked once in Smoke Pi. Verify the workflow's network policy configuration.🔒 DIFC Integrity Analysis
Key DIFC Metrics
💡 DIFC Tuning Recommendations
Generated by the Daily Security Observability workflow (consolidated from Daily Firewall Reporter + Daily DIFC Analyzer)
Analysis window: Last 7 days | Repository: github/gh-aw
Run: §27363842764
Beta Was this translation helpful? Give feedback.
All reactions