diff --git a/nix/host-modules/swarm-nats.nix b/nix/host-modules/swarm-nats.nix index 9acd2e56..84b9e930 100644 --- a/nix/host-modules/swarm-nats.nix +++ b/nix/host-modules/swarm-nats.nix @@ -347,8 +347,9 @@ in callout approval — it is the one that answers auth requests, so it cannot wait for itself. **That exemption is exactly why it needs a credential of its own**: without one the escape hatch is - an open door, and on a container sharing the host netns it is an - open door reachable from every agent container. + an open door, and it stands open to everything that can reach the + queue — every process on the host serving it, and every remote + hive in a multi-host swarm. An nkey rather than a password for the same reason `calloutIssuerPublicKey` is: only the public half appears here, @@ -569,13 +570,17 @@ in # Journal files on the host, not inside the container: nixpkgs hardcodes # --link-journal=try-guest, and EXTRA_NSPAWN_FLAGS expands after it. extraFlags = [ "--link-journal=host" ]; - # Shared host netns, like every sibling container. + # Shared host netns, like every sibling swarm container. # # ⚠️ Which is exactly why the server below must refuse everyone - # until the callout responder exists: on this netns the queue is - # reachable from every agent container on the hive, so an - # unauthenticated interim state would be a hole rather than a - # rough edge. + # until the callout responder exists: the queue is on the host's + # own loopback, in reach of every process there and every sibling + # on this netns, and each remote hive in a multi-host swarm dials + # it directly. An unauthenticated interim state would be a hole + # rather than a rough edge. + # + # Not agent containers, though: they have a netns of their own and + # the bridge firewall does not open this port. privateNetwork = false; # Binds only the public trust bundle, read-only. Empty when the gateway # is not self-signed, so the whole trust path drops out cleanly. diff --git a/nix/host-modules/swarm-victorialogs.nix b/nix/host-modules/swarm-victorialogs.nix index ddead0d2..ca91ea12 100644 --- a/nix/host-modules/swarm-victorialogs.nix +++ b/nix/host-modules/swarm-victorialogs.nix @@ -264,9 +264,10 @@ in # ⚠️ PINNED TO LOOPBACK for the same reason the metrics store is, # and it matters more here: upstream's default listens on every - # interface, and this endpoint accepts writes as well as reads - # with no authentication of its own. The bind address is the - # boundary. + # interface, and this endpoint accepts writes as well as reads. + # Nothing authenticates it either — upstream offers one basic-auth + # pair (`-httpAuth.username` / `-httpAuth.password`) and this + # module sets neither. The bind address is the boundary. listenAddress = "127.0.0.1:${toString cfg.port}"; extraOptions = [ "-retentionPeriod=${deployCfg.victorialogs.retentionPeriod}" ];