diff --git a/CHANGELOG.md b/CHANGELOG.md index 1256175..953a86e 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,3 +1,17 @@ +## 2026-10-06 (morning) — four apps see each visitor behind the tunnel; nextcloud's probe needs a finished install (R-776, R-613) — proven on 9202 first + +**What runs on a box changed:** one environment line in four composes (kimai, zipline, vikunja, nextcloud) and one probe +line in nextcloud's `.felhom.yml`. No image, version or ladder changed. Proven on scratch 9202 through the simulated tunnel, +each with a control (the line removed): felhom.eu `documentation/audits/morning-after-2026-10-06/live-9202/`. + +- **R-776:** kimai `TRUSTED_PROXIES=127.0.0.1,172.16.0.0/12`, zipline `CORE_TRUST_PROXY=true` + `CORE_TRUSTED_PROXIES=172.16.0.0/12`, + vikunja `VIKUNJA_SERVICE_IPEXTRACTIONMETHOD=xff`, nextcloud `TRUSTED_PROXIES=172.16.0.0/12`. Measured: each app now + throttles the stranger and lets the household in (vikunja/zipline 200, kimai ok, nextcloud counts the visitor's own + address); the stranger cannot escape by forging the leftmost `X-Forwarded-For`; in every control the household is + throttled too (or, nextcloud, the visitor is not counted). +- **R-613:** nextcloud's probe asks for `"installed":true` — `"installed"` alone matched an install that never finished. + Measured: `status.php` reads `{"installed":true,…}` and the controller reads the app `running`. + ## 2026-10-06 (night) — the burn-down night: decoy suites for three gates; image-pins could be fooled three ways (R-426) No template, image, version or healthcheck changed (scripts only). diff --git a/templates/kimai/docker-compose.yml b/templates/kimai/docker-compose.yml index e8a5ac5..c767585 100644 --- a/templates/kimai/docker-compose.yml +++ b/templates/kimai/docker-compose.yml @@ -25,7 +25,7 @@ services: # R-776 (R-753, controller >= 0.286.0): trust the docker networks as proxies (the image default is # nginx,localhost,127.0.0.1, so traefik was not trusted and every login/reset limiter keyed on traefik's one address # — a stranger's tries throttled the household too). Symfony then walks X-Forwarded-For from the RIGHT: the tunnel's - # real visitor, or the LAN client. The bookstack shape (APP_PROXIES); 9202 re-measure owed (checklist 3.6). + # real visitor, or the LAN client. The bookstack shape (APP_PROXIES); measured on 9202 2026-10-06 with a control (checklist 3.6; felhom.eu audits/morning-after-2026-10-06/live-9202/). - TRUSTED_PROXIES=127.0.0.1,172.16.0.0/12 volumes: - kimai_var:/opt/kimai/var diff --git a/templates/nextcloud/docker-compose.yml b/templates/nextcloud/docker-compose.yml index 3c28816..fe141b4 100644 --- a/templates/nextcloud/docker-compose.yml +++ b/templates/nextcloud/docker-compose.yml @@ -34,7 +34,7 @@ services: - OVERWRITEHOST=${SUBDOMAIN}.${DOMAIN} # R-776 (R-753, controller >= 0.286.0): the image's reverse-proxy.config.php turns this into trusted_proxies; Nextcloud # then reads X-Forwarded-For from the RIGHT, so its brute-force throttle keys on each VISITOR instead of one bucket - # for the whole tunnel. 9202 re-measure owed (checklist 3.6). + # for the whole tunnel. measured on 9202 2026-10-06 with a control (checklist 3.6; felhom.eu audits/morning-after-2026-10-06/live-9202/). - TRUSTED_PROXIES=172.16.0.0/12 - REDIS_HOST=nextcloud-redis # App-email (managed relay). Injected by the controller only when app-email is on (global + per-app); diff --git a/templates/vikunja/docker-compose.yml b/templates/vikunja/docker-compose.yml index 9d2f329..be4591e 100644 --- a/templates/vikunja/docker-compose.yml +++ b/templates/vikunja/docker-compose.yml @@ -22,7 +22,7 @@ services: # R-776 (R-753, controller >= 0.286.0): the default `direct` reads the TCP peer (traefik) — one address for every # visitor, so a stranger trips the login floor (10/min per address) for the household. `xff` walks X-Forwarded-For # from the RIGHT skipping private addresses (echo's default trust): the tunnel's real visitor, or the LAN client. - # 9202 re-measure owed (checklist 3.6). + # measured on 9202 2026-10-06 with a control (checklist 3.6; felhom.eu audits/morning-after-2026-10-06/live-9202/). - VIKUNJA_SERVICE_IPEXTRACTIONMETHOD=xff volumes: - vikunja_data:/app/vikunja/files diff --git a/templates/zipline/docker-compose.yml b/templates/zipline/docker-compose.yml index 7a81c84..7e1ef61 100644 --- a/templates/zipline/docker-compose.yml +++ b/templates/zipline/docker-compose.yml @@ -22,7 +22,7 @@ services: # R-776 (R-753, controller >= 0.286.0): Fastify's trustProxy with a CIDR list walks X-Forwarded-For from the RIGHT, # skipping the docker networks — so the login limiter (7 / 10 s per address) keys on each VISITOR, not on traefik's # one address for everybody. Never trustProxy=true without the list (that is the leftmost, client-written entry). - # 9202 re-measure owed (checklist 3.6). + # measured on 9202 2026-10-06 with a control (checklist 3.6; felhom.eu audits/morning-after-2026-10-06/live-9202/). - CORE_TRUST_PROXY=true - CORE_TRUSTED_PROXIES=172.16.0.0/12 # FIGYELEM: a v4 óta a DB változó neve DATABASE_URL (prefix NÉLKÜL), míg a