Golden 0.286.1 baked + vouched (record); 01 §5 visitor addresses + §7 cloudflared in the guest (R-754); register: R-753/754/772/773 closed, R-775 narrowed, R-776..R-782 opened (410 → 417); live evidence (demo-hp real tunnel, 9202)
gates / gates (push) Successful in 31s

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-01 22:05:24 +02:00
parent b50289074d
commit 09ae93db05
54 changed files with 5577 additions and 9 deletions
@@ -124,6 +124,21 @@ a trust boundary too: a default password, or a "first visitor creates the admin"
household acts. Rule and per-app status: `09` §3 decision 45 and `app-catalog-felhom.eu/FIRST-ADMIN.md` (the audit
of all 53 apps, 2026-09-28).
**Who is the visitor — the address (recorded 2026-10-01, R-753, `09` §3 decision 63, controller ≥ 0.286.0).** Rule:
*never believe an address a client can write.* Through the tunnel every visitor used to reach traefik as cloudflared's
one docker-assigned address, so every per-address guard (the dashboard's login counter, an app's lock) was an
"everyone" guard a stranger could aim at the household. Now cloudflared has a fixed address and traefik trusts forwarded
headers from that one address only: an app receives `X-Forwarded-For: <client-written…>, <real visitor>, 172.16.253.2`
(Cloudflare APPENDS to a client's own chain — measured), a LAN visitor arrives as itself, and every other peer's chain is
dropped. traefik's entrypoint middleware `felhom-forwarded` removes every header a client could write a host, a path or
an address into (`X-Forwarded-Host`, `Forwarded`, `True-Client-Ip`, …) and fixes `X-Forwarded-Port: 443`. **Readers take
the visitor from the RIGHT.** The controller (`clientaddr.go`) believes the chain only from traefik, takes the hop
traefik saw, and for the tunnel's hop reads `CF-Connecting-IP` (the edge refuses a client-sent one). Catalog apps that
read the LEFTMOST entry have the chain removed on their router. Design and measurements:
`audits/visitors-2026-10-01/A/DESIGN.md`. A permanent household gate with family accounts in front of an app (Grimmory,
MeTube) was SPIKED on this base and passed (`audits/permanent-gate-2026-10-01/VERDICT.md`); it is not built — the
operator decides.
**Who may reach an app, and through what (recorded 2026-09-29 — no document said it before; spike finding F1).**
Every app is reached only through the box's traefik (no catalog app publishes a host port except crafty-controller's
game ports; none uses host networking — read from the catalog 2026-09-29). traefik routes by host name: the tunnel's
@@ -182,10 +197,15 @@ the same way.
on Cloudflare) is register row R-494, P3, not blocking. Measured reason this was ruled now: the
2026-09-14 first-hour drill used a `*.felhom.eu` customer domain with no tunnel, and the dashboard link
in the setup-code mail did not resolve.
- **Tunnel placement: host** (resolved, Part 3 §3/§5). `cloudflared` runs on the Proxmox host
as its own **agent-managed systemd service** — not inside the guest — so the data path
survives control-plane death by construction. Geo-restriction WAF is **hub-enforced** (the
hub holds the CF API token; the controller only reports geo desired-state).
- **Tunnel placement: INSIDE the guest** (corrected 2026-10-01, R-754 — the operator's brief of that evening: the build is
right, correct the document). `cloudflared` is a container the CONTROLLER renders and keeps up (`internal/infra`,
`EnsureBaseStack`, a protected stack), with the tunnel token from `controller.yaml`. *This page used to say it ran on
the Proxmox host as an agent-managed systemd service; no box has ever been built that way* (read: the controller's
template; seen running in demo-hp's guest 9201 and in R-505's VM 331). Consequence, stated: the data path is NOT
independent of the guest — a dead guest is an unreachable box, and the controller (not the agent) restarts the
tunnel. Since controller v0.286.0 it sits ALONE on the `felhom-tunnel` network at the fixed address `172.16.253.2`
(traefik at `.3`), so traefik can believe forwarded headers from it and from nothing else (§5). Geo-restriction WAF
is **hub-enforced** (the hub holds the CF API token; the controller only reports geo desired-state).
---