Compare commits

..
3 changed files with 14 additions and 45 deletions

View file

@ -87,22 +87,12 @@ in
openFirewall = lib.mkOption {
type = lib.types.bool;
default = false;
example = true;
default = true;
description = ''
Open `httpPort` + `sshPort` in the host firewall. Off by
default (#651, secure-by-default): the forge is reachable
from the host + every agent container via `localhost` either
way (shared netns), so the firewall opens only matter for
access from outside the host. Flip to `true` when you want
the operator's browser / external git clients to hit the
forge directly. (The container shares host netns, so this
is the only firewall layer that matters.)
**Breaking change as of #651**: this used to default to
`true`. If you relied on the old default for external
reach, add `services.hyperhive.forge.openFirewall = true;`
to your host config before rebuilding.
Open `httpPort` + `sshPort` in the host firewall. Off when
the forge should only be reachable from inside the host.
(The container shares host netns, so this is the only
firewall layer that matters.)
'';
};
};

View file

@ -82,23 +82,11 @@ in
openFirewall = lib.mkOption {
type = lib.types.bool;
default = false;
example = true;
default = true;
description = ''
Open `port` in the host firewall. Off by default (#651,
secure-by-default). Flip to `true` to expose the gateway to
the operator's browser / external clients required for any
out-of-host reach, since the agents themselves talk to
hive-c0re via the per-agent unix sockets and don't need the
nginx vhost. Leave off when running behind another reverse
proxy (e.g. caddy / traefik on the host) that handles TLS
termination + forwards to `port`.
**Breaking change as of #651**: this used to default to
`true`. If you relied on the old default for external reach
(the common case the gateway is the operator's primary
entry point), add `services.hyperhive.gateway.openFirewall = true;`
to your host config before rebuilding.
Open `port` in the host firewall. Off when the gateway should
only be reachable from inside the host (e.g. behind another
reverse proxy that handles TLS termination).
'';
};

View file

@ -98,21 +98,12 @@ in
openFirewall = lib.mkOption {
type = lib.types.bool;
default = false;
example = true;
default = true;
description = ''
Open `httpPort` in the host firewall. Off by default (#651,
secure-by-default): the homeserver is reachable from the
host + every agent container via `localhost` either way
(shared netns), so the firewall open only matters for
access from outside the host. Flip to `true` when announcing
the homeserver to other hives or when an external matrix
client needs to reach the client-server API directly.
**Breaking change as of #651**: this used to default to
`true`. If you relied on the old default for external reach,
add `services.hyperhive.matrix.openFirewall = true;` to
your host config before rebuilding.
Open `httpPort` in the host firewall. Off when the
homeserver should only be reachable from inside the host
(e.g. while bringing the integration up before announcing
it to other hives).
Note: federation (the matrix-spec well-known port 8448) is
intentionally not opened here. tuwunel serves the federation