IP whitelisting
Authorising a proxy by the address you connect from, instead of sending a username and password.
IP whitelisting authorises use of a proxy based on the address your requests originate from. You register your server’s public address with the provider, and requests from it are accepted without credentials.
#Why it is used
- No credentials in configuration files, environment variables or logs.
- Slightly lower overhead, since there is no authentication exchange.
- Convenient for fixed infrastructure with a stable address.
#Where it breaks
- Dynamic addresses. A home connection or an autoscaling instance changes address and access stops without warning.
- Shared addresses. Anyone else behind the same NAT can use your allocation.
- Slow propagation. Whitelist changes are not always instant, which is painful during an incident.
#Choosing between the two
For fixed servers, whitelisting is clean. For anything that moves, scales or runs on a laptop, credential authentication is more robust. Some providers allow both at once, which is usually the pragmatic answer.
#When it is the better choice
An allow-list beats credentials in exactly one situation: the traffic comes from a fixed, known address that you control. A server in a datacentre qualifies. A laptop on hotel wifi does not.
- Nothing secret travels with the request, so there is no credential to leak into a log.
- An attacker who steals your configuration cannot use it without also originating from your address.
- The client stays simpler, which matters for tools that handle proxy authentication badly.
#The failure mode to design for
An allow-list fails silently and confusingly. Your address changes, and every request is refused with no message that names the cause. Because nothing in the response says “your address is not listed”, the symptom looks like a broken proxy, an expired plan or a network fault.
Two habits prevent the wasted hour:
- Record which address you registered, in the same place as the rest of the configuration.
- Check the current address first whenever a working setup stops working:
curl -s https://api.ipify.org.
On a dynamic connection, prefer credentials. They travel with the request, so they survive an address change.