Artifact reads blocked by your network allowlist now retry through the session gateway instead of failing.
tengu_cobalt_plinth_sorrel Off by default, switched on for this accountThe shipped code defaults this off, and the flag server returned on for the one account this site reads on this version. That is the reading that makes the entry above worth a second look, and it still says nothing about your account.
This account: on · anonymous baseline: on · compiled default in v2.1.236: off
Read once, for one account on one subscription tier, against v2.1.236. It isn't a statement about your account. What a flag value here can and cannot tell you
What's wrong with this entry?
Reading a published artifact used to fail outright when the environment's network allowlist blocked the artifact content host. Token-bearing (non-public) reads are now retried through the session gateway before giving up. The retry needs gate tengu_cobalt_plinth_sorrel, whose built-in fallback is true, so it is active absent server config.
- Public, tokenless artifacts are explicitly not relayed.
- Relay attempts and refusals are recorded, along with a per-host decline window so a failing relay is not hammered.
- When the relay cannot serve the read either, the failure says so rather than repeating the egress-blocked message.
artifact reads through the session gateway are not enabled for this session, or the artifact service no longer serves this version, asset_egress_relayed
Strings lifted out of the shipped bundle, so the claim above can be checked against them.