A Squid Forward Proxy That Refuses Loopback And Metadata

The stock squid.conf allows localhost before it denies loopback destinations, so a local client can proxy into loopback services. This role puts every deny first and binds loopback. The live test fetches a page through it, then sees squid itself refuse loopback, 169.254.169.254, an unsafe port, CONNECT to 25 and a non-loopback client. Original role, live-tested on Rocky Linux 10.

ansibleNetworking & VPC

Verification

Live-tested

Really deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.

Conformance

  • Static validation (yamllint · ansible-lint)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-10-02 · podman 4.9.3 · ansible 2.21.4 · how we verify

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: live-tested](https://www.iac-bazaar.com/api/artifacts/ansible-squid/badge)](https://www.iac-bazaar.com/catalog/ansible-squid?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Ansible role 1.0.0, live-tested on IaC Bazaar: [A Squid Forward Proxy That Refuses Loopback And Metadata](https://www.iac-bazaar.com/catalog/ansible-squid?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```yaml
# A Squid Forward Proxy That Refuses Loopback And Metadata: https://www.iac-bazaar.com/catalog/ansible-squid (download from your IaC Bazaar account)
```

Preview:IaC Bazaar: live-tested

Documentation

squid

Squid from the distribution's own package, configured as a forward proxy on loopback for the clients you list, with every refusal ahead of the one allow: no client can reach a loopback service or a link-local address (the cloud metadata service) through it. Original role for EL 10, live-tested with podman on Rocky Linux 10.

No download, and no version to pin. EL 10 packages squid, so the role installs it by name and takes what the distribution ships: a security update arrives through dnf, not through a new release of this role. What the role owns is the configuration and the proof that the service works.

The distribution's unit, our configuration. The role installs squid, writes the configuration the package leaves open, and enables the unit the package ships: systemctl cat squid shows the distribution's own unit, not one this role invented. The listener is 127.0.0.1:3128 by default, for a proxy that authenticates or a client on the same host; the live test reads the listening sockets and expects loopback only.

The distribution's file lets a local client into loopback. EL 10's squid.conf puts http_access allow localhost before deny to_localhost and deny to_linklocal, and squid takes the first rule that matches - so those two denies never apply to a local client. Measured before this role existed: a request through the stock proxy for http://127.0.0.1:8080/ came back 200, and the stock listener is every interface (*:3128). The role writes the denies first, binds 127.0.0.1:3128, and takes clients from squid_allowed_clients.

Every refusal is tested, and attributed. The live test serves a page on the host's non-loopback address and fetches it through the proxy (squid's Via header on the answer), then sees squid refuse a loopback destination, 169.254.169.254, a port outside Safe_ports, a CONNECT to port 25, and a request from a local process that dials the loopback listener from a non-loopback source address. The access log must hold squid's own TCP_DENIED/403 line for each, so a refusal cannot be passed off as a connection that merely failed.

Set, but not asserted by the live test: forwarded_for delete (no X-Forwarded-For header carries the client's address to the origin) and httpd_suppress_version_string on (error pages do not name the release). Both are plain configuration lines; the test proves the access rules, not these two.

License

Commercial - IaC Bazaar EULA. (c) IaC Bazaar.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Variables
  • Test

Related modules