Webhook boundary

Webhook security and debugging

Trestle refuses destinations that resolve to loopback, private, unspecified or link-local addresses and refuses redirects.

Targets must use HTTPS. DNS is resolved again at delivery time to reduce rebinding risk. Responses are drained only to a 64 KiB bound, delivery has a finite timeout, and provider errors are truncated in job state.

Secrets

Signing secrets are shown once and encrypted at rest with an owner-only key beneath the Trestle data directory. They are never returned by list or diagnostic endpoints.

Debugging

Inspect the corresponding job for attempts and the bounded last error. A dead job should be repaired before retry. Disable a target to stop new deliveries; already queued work rechecks enabled state before sending.