Golden 0.286.1 baked + vouched (record); 01 §5 visitor addresses + §7 cloudflared in the guest (R-754); register: R-753/754/772/773 closed, R-775 narrowed, R-776..R-782 opened (410 → 417); live evidence (demo-hp real tunnel, 9202)
gates / gates (push) Successful in 31s
gates / gates (push) Successful in 31s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
@@ -124,6 +124,21 @@ a trust boundary too: a default password, or a "first visitor creates the admin"
|
||||
household acts. Rule and per-app status: `09` §3 decision 45 and `app-catalog-felhom.eu/FIRST-ADMIN.md` (the audit
|
||||
of all 53 apps, 2026-09-28).
|
||||
|
||||
**Who is the visitor — the address (recorded 2026-10-01, R-753, `09` §3 decision 63, controller ≥ 0.286.0).** Rule:
|
||||
*never believe an address a client can write.* Through the tunnel every visitor used to reach traefik as cloudflared's
|
||||
one docker-assigned address, so every per-address guard (the dashboard's login counter, an app's lock) was an
|
||||
"everyone" guard a stranger could aim at the household. Now cloudflared has a fixed address and traefik trusts forwarded
|
||||
headers from that one address only: an app receives `X-Forwarded-For: <client-written…>, <real visitor>, 172.16.253.2`
|
||||
(Cloudflare APPENDS to a client's own chain — measured), a LAN visitor arrives as itself, and every other peer's chain is
|
||||
dropped. traefik's entrypoint middleware `felhom-forwarded` removes every header a client could write a host, a path or
|
||||
an address into (`X-Forwarded-Host`, `Forwarded`, `True-Client-Ip`, …) and fixes `X-Forwarded-Port: 443`. **Readers take
|
||||
the visitor from the RIGHT.** The controller (`clientaddr.go`) believes the chain only from traefik, takes the hop
|
||||
traefik saw, and for the tunnel's hop reads `CF-Connecting-IP` (the edge refuses a client-sent one). Catalog apps that
|
||||
read the LEFTMOST entry have the chain removed on their router. Design and measurements:
|
||||
`audits/visitors-2026-10-01/A/DESIGN.md`. A permanent household gate with family accounts in front of an app (Grimmory,
|
||||
MeTube) was SPIKED on this base and passed (`audits/permanent-gate-2026-10-01/VERDICT.md`); it is not built — the
|
||||
operator decides.
|
||||
|
||||
**Who may reach an app, and through what (recorded 2026-09-29 — no document said it before; spike finding F1).**
|
||||
Every app is reached only through the box's traefik (no catalog app publishes a host port except crafty-controller's
|
||||
game ports; none uses host networking — read from the catalog 2026-09-29). traefik routes by host name: the tunnel's
|
||||
@@ -182,10 +197,15 @@ the same way.
|
||||
on Cloudflare) is register row R-494, P3, not blocking. Measured reason this was ruled now: the
|
||||
2026-09-14 first-hour drill used a `*.felhom.eu` customer domain with no tunnel, and the dashboard link
|
||||
in the setup-code mail did not resolve.
|
||||
- **Tunnel placement: host** (resolved, Part 3 §3/§5). `cloudflared` runs on the Proxmox host
|
||||
as its own **agent-managed systemd service** — not inside the guest — so the data path
|
||||
survives control-plane death by construction. Geo-restriction WAF is **hub-enforced** (the
|
||||
hub holds the CF API token; the controller only reports geo desired-state).
|
||||
- **Tunnel placement: INSIDE the guest** (corrected 2026-10-01, R-754 — the operator's brief of that evening: the build is
|
||||
right, correct the document). `cloudflared` is a container the CONTROLLER renders and keeps up (`internal/infra`,
|
||||
`EnsureBaseStack`, a protected stack), with the tunnel token from `controller.yaml`. *This page used to say it ran on
|
||||
the Proxmox host as an agent-managed systemd service; no box has ever been built that way* (read: the controller's
|
||||
template; seen running in demo-hp's guest 9201 and in R-505's VM 331). Consequence, stated: the data path is NOT
|
||||
independent of the guest — a dead guest is an unreachable box, and the controller (not the agent) restarts the
|
||||
tunnel. Since controller v0.286.0 it sits ALONE on the `felhom-tunnel` network at the fixed address `172.16.253.2`
|
||||
(traefik at `.3`), so traefik can believe forwarded headers from it and from nothing else (§5). Geo-restriction WAF
|
||||
is **hub-enforced** (the hub holds the CF API token; the controller only reports geo desired-state).
|
||||
|
||||
---
|
||||
|
||||
|
||||
Reference in New Issue
Block a user