Webhook boundary
Webhook security and debugging
Trestle refuses destinations that resolve to loopback, private, unspecified or link-local addresses and refuses redirects.
Targets must use HTTPS. DNS is resolved again at delivery time to reduce rebinding risk. Responses are drained only to a 64 KiB bound, delivery has a finite timeout, and provider errors are truncated in job state.
Secrets
Signing secrets are shown once and encrypted at rest with an owner-only key beneath the Trestle data directory. They are never returned by list or diagnostic endpoints.
Debugging
Inspect the corresponding job for attempts and the bounded last error. A dead job should be repaired before retry. Disable a target to stop new deliveries; already queued work rechecks enabled state before sending.