ArchitectureSecurity model
GitHub webhooks
GitHub signs each delivery with a shared secret. Ferry refuses a bad signature and ignores a copy.
With no --github-webhook-secret, the endpoint answers 404.
1 / 4
A GitHub webhook does not use the account or an API token. Its proof is an HMAC signature made with the webhook secret.
The rules
| Rule | Detail |
|---|---|
| Off by default | The endpoint answers 404 until you set --github-webhook-secret. |
| Signature | X-Hub-Signature-256: HMAC-SHA256 of the raw body, compared in constant time. |
| No replay | Ferry ignores a delivery if it processed the same body or the same delivery id before. |
Turn it on
ferryd --github-webhook-secret <secret>Give the same secret to GitHub. GitHub auto-deploy shows each step. The API overview has the details.