Repository navigation
fix: cut tailnet-wide exposure, narrow crowdsec allowlists, tighten secret handling - #387
Merged
Merged
Conversation
- authelia 9091: loopback only; caddy is the sole entry point - gluetun 8081 (HTTP proxy): loopback only - upsnap: --network=host is kept for LAN scanning, but the web UI now binds 127.0.0.1 via UPSNAP_HTTP_LISTEN (the publish map is ignored under host networking); drops stray SLSKD_REMOTE_CONFIGURATION env - unifi: device/portal ports bound to the LAN IP (192.168.0.85) instead of 0.0.0.0 — APs already target that IP, and tailscale0 is a trusted interface, so a wildcard bind exposed every port tailnet-wide - haproxy stats: loopback-only bind instead of *:8404 (scraped by the local host-networked gatus; remote access via ssh -L)
The LAPI allowlist and parser whitelist blanket-allowed all of RFC1918, CGNAT 100.64.0.0/10 and ULA, so LAN-originated attacks on the public vhosts (hairpin dual-A record) and compromised tailnet nodes could never be banned. Allowlist only loopback/link-local and the two tailnet infra IPs (eclair 100.99.168.34, sorbet 100.120.32.9).
The app-only token was rendered world-readable (0444). Give the secret to a system user matching the container's uid 1000 and render it 0400.
The key was passed through an ssh command-line argument (world-readable in /proc, remote shell history) with StrictHostKeyChecking=no. Use the README's stdin pattern and let the first connect pin the host key.
frostplexx
enabled auto-merge
October 6, 2026 06:57
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to the security audit. Six fixes plus the gluetun image-name fix that was stranded on the
ci/deploy-cadencebranch after #385 merged.Port exposure (all previously published on 0.0.0.0, reachable tailnet-wide via the trusted
tailscale0interface)9091→127.0.0.1:9091— caddy (host) is the sole entry point8081→127.0.0.1:8081— no consumer in the repo--network=host(LAN device scanning withNET_RAW), but the web UI now binds127.0.0.1:8090viaUPSNAP_HTTP_LISTEN(the publish map is ignored under host networking, so a prefix alone can't fix this one). Also drops a straySLSKD_REMOTE_CONFIGURATIONcopy-paste var192.168.0.85instead of0.0.0.0. Devices already target that IP (see theset-informnote), so adoption is unaffected — but they are no longer tailnet-wide. Not127.0.0.1because that would break device inform*:8404→127.0.0.1:8404(scraped by the local host-networked gatus; remote viewing viassh -L 8404:127.0.0.1:8404 eclair). Deliberately not bound to the tailnet IP: haproxy would fail at boot when tailscale brings the address up after haproxy starts. The now-dead tailscale0 firewall rule removedCrowdSec
100.64.0.0/10/ ULA — only loopback, link-local and the two tailnet infra IPs (100.99.168.34eclair,100.120.32.9sorbet). A compromised LAN device (hairpin dual-A record) or tailnet node can now be bannedSecrets
0444→0400, owned by a new system user matching the container'suid 1000/proc),StrictHostKeyChecking=noremovedHousekeeping
ghcr.io/qdm12/gluetun(same digest;qmcgaw/gluetunis the deprecated docker-hub mirror)Both toplevels build against this branch. Merging does not deploy anything directly — the daily 07:00 UTC change-guarded deploy picks it up.
Not touched (flagged, didn't want to guess intent): gluetun's published
47594/tcp + udp(no consumer in the repo — say the word if it should be loopback/LAN too), andtrustedInterfaces = ["tailscale0"]itself.