Problem
gh-aw's compiler only emits AWF's --allow-host-ports/--enable-host-access flags in legacy-security mode, and even then the port list is hardcoded to 80,443,<mcp-gateway-port>. There is no way for a strict-security workflow to reach a GitHub Actions services: container port (e.g. Postgres 5432) from inside the AWF sandbox.
Context
Original report: github/gh-aw#51433 (follow-up to gh-aw#22939, previously addressed on the AWF side by #1436)
Root Cause
AWF already supports arbitrary --allow-host-ports values (added for #1436), so the capability exists. The gap is entirely on the gh-aw compiler side (pkg/workflow/awf_command_builder.go) which never derives ports from services: and never emits the flag outside legacy mode — not an AWF defect, but AWF should confirm/document that a strict-security-compatible port allowlist (without --enable-host-access) is fully supported and low-risk.
Proposed Solution
- Confirm AWF's
--allow-host-ports works standalone without --enable-host-access (per the linked issue's runtime finding that host-access alone was insufficient).
- Document this combination explicitly in AWF's docs/awf-config-spec.md so gh-aw's compiler fix (deriving ports from
services:) can rely on it without requiring full host access.
- No AWF code change expected; primarily a documentation/confirmation task and a note to gh-aw maintainers.
Generated by Firewall Issue Dispatcher · auto · 32.5 AIC · ⊞ 8.9K · ◷
Problem
gh-aw's compiler only emits AWF's
--allow-host-ports/--enable-host-accessflags in legacy-security mode, and even then the port list is hardcoded to80,443,<mcp-gateway-port>. There is no way for a strict-security workflow to reach a GitHub Actionsservices:container port (e.g. Postgres 5432) from inside the AWF sandbox.Context
Original report: github/gh-aw#51433 (follow-up to gh-aw#22939, previously addressed on the AWF side by #1436)
Root Cause
AWF already supports arbitrary
--allow-host-portsvalues (added for #1436), so the capability exists. The gap is entirely on the gh-aw compiler side (pkg/workflow/awf_command_builder.go) which never derives ports fromservices:and never emits the flag outside legacy mode — not an AWF defect, but AWF should confirm/document that a strict-security-compatible port allowlist (without--enable-host-access) is fully supported and low-risk.Proposed Solution
--allow-host-portsworks standalone without--enable-host-access(per the linked issue's runtime finding that host-access alone was insufficient).services:) can rely on it without requiring full host access.