Skip to content

Never charge an uptime monitor, and add Oracle's ranges - #365

Merged
ralyodio merged 1 commit into
masterfrom
cloud-gate-monitors-oracle
Sep 24, 2026
Merged

ralyodio merged 1 commit into
masterfrom
cloud-gate-monitors-oracle

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

Two things found by watching the gate run in production, not by reading it.

Uptime monitors would have paged us

A monitor counts 200-399 as up — CrawlProof's own checkHttp does exactly that — so answering one 402 does not bill it, it reports the site as down. Ours runs on Railway, i.e. from a cloud address, so the range check alone would have caught it. We would have built ourselves a false-alarm generator and then been woken by it.

Exempted by user agent: ours plus the common third parties (UptimeRobot, Pingdom, StatusCake, Better Uptime, Checkly, updown.io, …).

Oracle was missing

It publishes ap-singapore-1 and ap-singapore-2 in a clean official file — exactly the shape of host this gate exists for. With it: 13,724 prefixes merging to 1,671 ranges.

The control HTTP probes could not give us

Every request from the dev box arrives from a DigitalOcean address, so no forged X-Forwarded-For can simulate a residential visitor — which is why my earlier prod probes all showed 402 and looked alarming. Verified at the matcher against the live files instead:

3.0.0.1         AWS                  matched
140.238.1.1     Oracle Singapore     matched
67.205.189.229  our own DO box       matched
86.1.2.3        UK residential       NOT matched
24.60.1.2       US Comcast           NOT matched

Real users are not matched. That was the open question after #364 went live.

Still uncovered, and the source now says so

Azure's range file URL carries a date and rotates weekly; Alibaba publishes nothing and would need its ASNs resolved through BGP data. Both matter for Singapore, where Alibaba is a common host for this exact traffic — so a miss here does not establish that an address is residential, and UNCOVERED_PROVIDERS documents it rather than leaving it to be rediscovered.

Testing

61 tests across cloud-gate, footprint and proxy.runtime; tsc --noEmit clean.

🤖 Generated with Claude Code

Two things found by watching the gate run in production rather than by
reading it.

**Uptime monitors would have paged us.** A monitor counts 200-399 as up —
CrawlProof's own checkHttp does exactly that — so answering one 402 does not
bill it, it reports THE SITE AS DOWN. Ours runs on Railway, which is to say
from a cloud address, so the range check alone would have caught it and we
would have built ourselves a false alarm generator and then been woken by it.
Exempted by user agent, ours and the common third parties.

**Oracle was missing.** It publishes ap-singapore-1 and ap-singapore-2 in a
clean official file, which is exactly the shape of host this gate exists for.
With it the list is 13,724 prefixes merging to 1,671 ranges.

Verified against the live files, including the control that HTTP probes could
not give us — every request from this machine arrives from a DigitalOcean
address, so no forged X-Forwarded-For can simulate a residential visitor:

  3.0.0.1        AWS                  matched
  140.238.1.1    Oracle Singapore     matched
  67.205.189.229 our own DO box       matched
  86.1.2.3       UK residential       NOT matched
  24.60.1.2      US Comcast           NOT matched

Azure and Alibaba are still uncovered and now say so in the source. Azure's
file URL carries a date and rotates weekly; Alibaba publishes nothing and
would need its ASNs resolved through BGP data. Both matter for Singapore,
where Alibaba is a common host for this exact traffic — so a miss here does
NOT establish that an address is residential, and the comment says so.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

ThreatCrush Security Scan

331 finding(s)

HIGH/CRITICAL: 33 | MEDIUM: 40 | LOW: 258

Severity Rule Location
HIGH secret-private-key .env.example:236
HIGH secret-generic-api-key docs/API.md:430
HIGH secret-generic-api-key docs/API.md:585
HIGH secret-generic-credential docs/FIX_VERIFY_SIGNATURE.md:156
HIGH secret-generic-credential docs/integration-examples/nodejs-bot.md:225
HIGH secret-generic-api-key docs/sdk/getting-started.md:36
HIGH secret-generic-api-key docs/sdk/getting-started.md:318
HIGH secret-generic-credential packages/extension/scripts/make-screenshots.mjs:283
HIGH secret-generic-api-key packages/sdk/README.md:99
HIGH secret-generic-credential packages/sdk/README.md:122
HIGH secret-generic-credential packages/sdk/README.md:848
HIGH sh-remote-script-execution public/install.sh:167
HIGH sh-remote-script-execution public/install.sh:407
HIGH sh-remote-script-execution public/install.sh:412
HIGH sh-remote-script-execution public/install.sh:416
HIGH sh-remote-script-execution public/install.sh:761
HIGH sh-remote-script-execution public/install.sh:762
HIGH sh-remote-script-execution public/install.sh:802
HIGH sh-remote-script-execution public/install.sh:803
HIGH sh-remote-script-execution public/install.sh:804
HIGH secret-generic-credential scripts/setup-droplet.sh:609
HIGH secret-generic-api-key src/app/docs/sdk/page.tsx:135
HIGH secret-generic-api-key src/app/docs/sdk/page.tsx:214
HIGH secret-generic-credential src/app/docs/sdk/page.tsx:1001
HIGH secret-generic-credential src/app/docs/sdk/page.tsx:1022
HIGH secret-generic-api-key src/app/docs/sdk/page.tsx:1401
HIGH secret-generic-credential src/app/docs/sdk/page.tsx:1482
HIGH secret-generic-credential src/app/docs/sdk/page.tsx:1491
HIGH secret-generic-api-key src/app/docs/sdk/page.tsx:1533
HIGH secret-generic-credential src/components/docs/AuthenticationDocs.tsx:37
HIGH secret-generic-credential src/components/docs/OAuthDocs.tsx:262
HIGH secret-generic-credential supabase/config.toml:255
HIGH secret-generic-credential supabase/config.toml:287
MEDIUM manifest-install-lifecycle-script package.json:28
MEDIUM js-dynamic-code-execution packages/extension/scripts/make-screenshots.mjs:256
MEDIUM js-dynamic-code-execution packages/extension/scripts/make-screenshots.mjs:265
MEDIUM js-shell-exec-interpolation packages/sdk/bin/coinpay.js:49
MEDIUM js-shell-exec-interpolation packages/sdk/test/cli-issuer.test.js:23
MEDIUM js-shell-exec-interpolation packages/sdk/test/cli-reputation.test.js:23
MEDIUM js-shell-exec-interpolation packages/sdk/test/cli-subscription.test.js:22
MEDIUM js-shell-exec-interpolation packages/sdk/test/cli-subscription.test.js:33
MEDIUM js-shell-exec-interpolation packages/sdk/test/cli-subscription.test.js:48
MEDIUM js-shell-exec-interpolation packages/sdk/test/cli-subscription.test.js:63
MEDIUM js-shell-exec-interpolation packages/sdk/test/cli-subscription.test.js:78
MEDIUM js-shell-exec-interpolation packages/sdk/test/wallet-backup.test.js:82
MEDIUM js-shell-exec-interpolation packages/sdk/test/wallet.test.js:249
MEDIUM js-shell-exec-interpolation packages/sdk/test/wallet.test.js:280
MEDIUM insecure-temp-file public/install.sh:108
MEDIUM sh-unquoted-expansion-destructive public/install.sh:718
MEDIUM js-unescaped-html-sink public/payments.js:93

…and 281 more. Full results in the Security tab.

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit 33acd68 into master Sep 24, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant