nix: openFirewall defaults false across forge/gateway/matrix (#651)

mara on #651: "Dont default openFirewall to true."

Flip the `openFirewall` default from `true` to `false` for all three
modules that expose host-side ports:

- `services.hyperhive.forge.openFirewall` (httpPort 3000 + sshPort 2222)
- `services.hyperhive.gateway.openFirewall` (port 80)
- `services.hyperhive.matrix.openFirewall` (httpPort 8008)

Rationale: secure-by-default. With shared host netns, the host +
every agent container reach these services via `localhost` regardless
of the firewall — the open only matters for access from outside the
host. Operators who want external reach now flip the bool explicitly:

    services.hyperhive.gateway.openFirewall = true;

Each description updated to explain the new default + when to flip
it (operator's browser, external git clients, federation announcement,
etc.). Behind a host-level reverse proxy that handles TLS, leave off.

Verified via `nix eval` on a clean stub config:
- forge openFirewall = false
- gateway openFirewall = false
- matrix openFirewall = false
- networking.firewall.allowedTCPPorts = [] (was: [80 2222 3000 8008])

Note: c0re's direct ports (7000/8000/8100-8999) are gated separately
via #621 on `gateway.enable` — that gate stays; this PR only touches
the per-module `openFirewall` knobs.

Closes #651.
This commit is contained in:
atlas 2026-05-30 19:25:28 +02:00
commit 7feef4cc5d
3 changed files with 29 additions and 14 deletions

View file

@ -87,12 +87,17 @@ in
openFirewall = lib.mkOption {
type = lib.types.bool;
default = true;
default = false;
example = true;
description = ''
Open `httpPort` + `sshPort` in the host firewall. Off when
the forge should only be reachable from inside the host.
(The container shares host netns, so this is the only
firewall layer that matters.)
Open `httpPort` + `sshPort` in the host firewall. Off by
default (#651, secure-by-default): the forge is reachable
from the host + every agent container via `localhost` either
way (shared netns), so the firewall opens only matter for
access from outside the host. Flip to `true` when you want
the operator's browser / external git clients to hit the
forge directly. (The container shares host netns, so this
is the only firewall layer that matters.)
'';
};
};

View file

@ -82,11 +82,17 @@ in
openFirewall = lib.mkOption {
type = lib.types.bool;
default = true;
default = false;
example = true;
description = ''
Open `port` in the host firewall. Off when the gateway should
only be reachable from inside the host (e.g. behind another
reverse proxy that handles TLS termination).
Open `port` in the host firewall. Off by default (#651,
secure-by-default). Flip to `true` to expose the gateway to
the operator's browser / external clients required for any
out-of-host reach, since the agents themselves talk to
hive-c0re via the per-agent unix sockets and don't need the
nginx vhost. Leave off when running behind another reverse
proxy (e.g. caddy / traefik on the host) that handles TLS
termination + forwards to `port`.
'';
};

View file

@ -98,12 +98,16 @@ in
openFirewall = lib.mkOption {
type = lib.types.bool;
default = true;
default = false;
example = true;
description = ''
Open `httpPort` in the host firewall. Off when the
homeserver should only be reachable from inside the host
(e.g. while bringing the integration up before announcing
it to other hives).
Open `httpPort` in the host firewall. Off by default (#651,
secure-by-default): the homeserver is reachable from the
host + every agent container via `localhost` either way
(shared netns), so the firewall open only matters for
access from outside the host. Flip to `true` when announcing
the homeserver to other hives or when an external matrix
client needs to reach the client-server API directly.
Note: federation (the matrix-spec well-known port 8448) is
intentionally not opened here. tuwunel serves the federation