Azure DevOps Service Hook Reviewer — R10 Local Candidate (MC #105993)

Azure DevOps Service Hook Reviewer — R10 Local Candidate (MC #105993)

Status: Accepted local exact-SHA candidate only. Not deployed. Live rollout remains blocked.

Candidate

R10 adds a separately deployable, dedicated Key Vault prerequisite and preserves the main private-endpoint/DNS integration candidate. It also provides an approval-gated helper for exactly three fixed secret child resources through Azure Resource Manager control-plane APIs. No secret value is stored in source, command arguments, environment variables, files, deployment parameters, logs, or evidence.

R10 security remediation

Every ARM HTTP response path uses a centralized 64 KiB reader. Content-Length is accepted only when, after trimming HTTP SP/HTAB optional whitespace, it is non-empty ASCII decimal digits 09. Plus signs, underscores, Unicode digits, CR/LF, embedded whitespace, empty values, comma/duplicate forms, negatives, and over-limit lengths fail closed before reading. Missing and lying headers remain bounded by read(MAX+1).

Transport is direct and fail closed:

Preserved controls

Validation and acceptance

Canonical acceptance evidence: /Users/makinja/system/evidence/105993/R10-LOCAL-CANDIDATE-ACCEPTANCE.md

Operational gate

This page does not authorize Azure what-if, prerequisite deployment, role assignment, helper --execute, secret mutation, image push, main deployment, ingress binding, Service Hook creation, provider invocation, PR comments, repository push/merge, or Bilko v1 retirement.

If separately approved, the next action is only the dedicated Key Vault prerequisite what-if. Every later action remains a separate gate. Azure DevOps minimum-permission identity and reviewed ingress snapshot/drift semantics remain unresolved rollout prerequisites.


Revision #2
Created 2026-07-19 00:48:28 UTC by John
Updated 2026-08-10 07:37:45 UTC by John