8dab40c7a7
gates / gates (push) Successful in 27s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
3.4 KiB
3.4 KiB
STATUS — what works, what's broken, what's next
Ready for the first real tester (Tester-2): yes. You confirmed the tunnel route and the connect mails (2026-09-30).
Updated 2026-10-01 (afternoon). Both demo boxes run controller 0.285.0 and host agent 0.138.0. Hub 0.126.0. New installs get golden 0.285.0 with agent 0.138.0.
Tester-2 — read only, from the hub. The customer record exists. Tester-2's box has not registered yet.
Decisions I took myself (you may reverse them)
- wger: a stranger now locks only the name they try, for 5 minutes. Before, ten wrong tries locked out every household member for 30 minutes. Tested: the other member could still log in; the targeted one was back in after 7.5 minutes. Short on purpose: in wger, every try during a lock restarts it, also the household's own.
- BookStack and Grafana: no change. Their locks are already short: 1 minute and 5 minutes, measured.
- mealie stays on the 1-hour lock, as you said.
What I measured
- Behind the tunnel, every visitor looks like the same address to an app. So an app that locks "by address" locks out everyone at once (that was wger). Apps cannot see who is who. I did not change this box-wide: the easy way would let a stranger fake an address. Written down.
- Old controller versions in the registry: no automatic rule removed them. Someone ran a clean-up script by hand on 22–23 August, when the registry disk was full. Nothing runs it on a schedule.
- An installed app takes a new setting at its next restart, update or night backup — not by itself.
What else I found
- wger runs a development web server, not a production one. Written down.
- The design document says the tunnel runs on the host. It runs inside the box. One of the two is wrong. Written down.
Rows. Today (afternoon): 0 closed, 2 narrowed or answered, 3 opened. The list went from 387 to 390 rows.
What needs you
- calibre-web: a stranger can lock the household out for a day (40 wrong tries in 14 minutes). There is no setting
for a shorter lock. Two ways:
- A — a secret login name (recommended): the box makes one at install and shows it on the app page next to the password. Strangers cannot aim at it. Cost: the household types a strange name.
- B — switch the login limit off: no lock at all. Cost: no limit on password guessing in the login form.
If you do nothing: a stranger who knows the name
admincan keep the household out for a day.
- The registry clean-up script: today it keeps only the newest 7 versions, about one day of controller releases,
and it does not protect the versions in use. Two ways:
- A — a written rule (recommended): keep the newest 20 releases, plus every version a golden, the floor or the vouched agent names. Change the script to match.
- B — keep it as it is: run by hand when the disk fills. If you do nothing: the next manual run can delete a version a box or a backup still needs.
- Smaller: should apps see each visitor's real address (a bigger build), or do we keep fixing per app? And which is right for the tunnel: the design document (on the host) or the build (inside the box)? Nothing breaks if you wait.
Standing steps
- Monthly security re-test: last run 2026-10-01, next due ~2026-11-01. (You start it with the standing brief.)
- Weekly: the golden bake (around 8 October).