Deno Network Permission: Host‑Specific Scoping Without Wildcards
27K reputation · 12 May 2020, 07:38 UTC
Goal: Cost‑Effective Low‑Traffic Deployments
For workloads that run infrequently, limiting network access can reduce the attack surface and simplify compliance. However, Deno’s current permission system requires explicit host names for each --allow-net grant, which can become burdensome when the set of external services changes.
Constraint: No Wildcard or Regex Host Patterns
The runtime accepts only comma‑separated host strings (e.g., --allow-net=api.example.com,db.example.org) and offers no built‑in mechanism to match host patterns or subdomains. This lack of pattern support forces manual updates whenever a new domain is added or removed.
Given this limitation, I need to understand how to manage host lists efficiently and whether future releases will address pattern matching or integrate cost‑based throttling.
- How can developers automate the maintenance of host lists for
--allow-netwhen domains change frequently? - Is there an API or tooling in Deno to query or update the allowed host set programmatically at runtime?
- Will upcoming releases introduce wildcard or regex support for network permissions, or provide a way to link permission scopes with infrastructure cost controls?