docs, hub, installer: say Server + Desktop makes the home IP public

Server + Desktop publishes services under the operator's own domain, and
the DNS record for that domain points at the home connection, so anyone
can look up the home IP address. None of the places that offer Server +
Desktop said so.

- README: new section "Server + Desktop and your home IP address" (what
  becomes public, what does not, the alternatives, and what happens
  technically), plus a note on the role table and in the security
  overview.
- SECURITY.md: a matching section, the consequence noted next to "Public
  web services exposed only when enabled by the operator", and the
  supported versions row no longer pins 1.0.x.
- ISO installer: the Server + Desktop role card ends with the warning.
- Hub: the domain setup text (onboarding, feature setup and domain
  reconfiguration share renderDomainNeedsHtml) and the upgrade dialog
  carry the same notice.
- Add tests/test_exposure_guards.py. It fails if one of these places
  loses the notice or the README anchor stops resolving.
This commit is contained in:
Arena.ai Agent
2026-10-01 21:43:47 -05:00
committed by naturallaw777
parent 2d777450e1
commit 34cfba4282
6 changed files with 162 additions and 5 deletions
+64 -2
View File
@@ -202,7 +202,7 @@ Bitcoin and self-hosting infrastructure runs on the machine.
|---|---|---|
| **Desktop** | Everyday users and computers with modest hardware | Sparrow, Bisq, and Bisq 2 for self-custody and peer-to-peer Bitcoin use |
| **Node** | People ready to verify and operate their own Bitcoin infrastructure | Everything in Desktop, plus the full Bitcoin stack: Bitcoin Core, Electrs, LND, Ride The Lightning, BTCPay Server, and wallet-to-node connections |
| **Server + Desktop** | Bitcoiners who want the same sovereignty over their communications, cloud, passwords, and web services | The complete Node stack, plus the private self-hosted services |
| **Server + Desktop** | Bitcoiners who want the same sovereignty over their communications, cloud, passwords, and web services | The complete Node stack, plus the private self-hosted services. **Makes your home IP address public:** [read this first](#server--desktop-and-your-home-ip-address) |
**Desktop: start with your keys.** Desktop is not a reduced or Bitcoin-free
edition. It is a complete, private everyday computer with a clean GNOME
@@ -237,6 +237,66 @@ communications, identity, and services.
> provider allows port forwarding. Most home routers and providers already
> support this. If you are unsure, a quick search for your router model and
> "port forwarding" will usually turn up a step-by-step guide.
>
> **This mode also makes your home IP address public.** Read
> [what that means](#server--desktop-and-your-home-ip-address) before you
> choose it.
### Server + Desktop and your home IP address
> **⚠️ Server + Desktop makes your home IP address public.**
> Public services need a domain name that points at your home internet
> connection. When you finish the guided domain setup, Sovran_SystemsOS puts
> your home's public IP address in a Dynamic DNS record at
> [Njal.la](https://njal.la) and keeps it up to date, and you forward ports 80
> and 443 on your router to this computer. From then on:
>
> - **Anyone can look up your domain and see your home IP address.** An IP
> address typically reveals your internet provider and your approximate
> location, and it ties everything you publish on that domain to your home
> connection.
> - **Domain privacy does not hide it.** Registrar privacy protects the
> registrant's identity, not the IP address in your DNS records.
> - **Your connection is open to the whole internet on those ports.** Scanners
> and bots constantly probe public IP addresses, so expect automated probing
> and login attempts against every service you publish.
> - **Your service names are discoverable.** Public HTTPS certificates are
> listed in public Certificate Transparency logs, so hostnames such as
> `vault.yourdomain.com` can be found, and then resolved to your IP address,
> even if you never share them.
Nothing is published until you finish domain setup and port forwarding, but that
setup is the point of this mode, so assume your IP address will be public.
**Desktop** publishes nothing. **Node** publishes nothing unless you turn on a
feature that needs a domain: *Put BTCPay Server Online* or *Lightning Wallet
Connections*.
**If you do not want your home IP address to be public,** choose Desktop or
Node. Advanced users can put a VPS, reverse proxy, or tunnel in front of their
services so DNS points there instead of at their home. Sovran_SystemsOS does not
set this up for you, and the Hub's domain checks currently expect DNS to point
at your home IP address.
<details>
<summary><strong>What happens technically</strong></summary>
- You create a **Dynamic** DNS record at Njal.la and paste its update command
into the Hub. The Hub only accepts `njal.la` update URLs.
- The `sovran-ddns-update` timer asks Njal.la to point your record at the
address the request came from. It does this right after you save a domain,
two minutes after boot, and then every 15 minutes.
- Njal.la reports that address back, and Sovran_SystemsOS keeps it for Element
calling and the Hub. Nothing else looks up your public IP address: no STUN
server, public DNS resolver, or "what is my IP" service is involved. See
`modules/core/njalla.nix`.
- Once a service that needs a domain is turned on, the firewall opens TCP and
UDP ports 80 and 443 for Caddy, which requests public HTTPS certificates for
the domains you configure. See `modules/core/caddy.nix`.
- Optional features can need more ports. Element calling, for example, needs
TCP 7881 and UDP 3478, 7882, and 40000–40099. The Hub lists the ports each
feature needs.
</details>
---
@@ -730,7 +790,9 @@ Sovran_SystemsOS uses layered controls:
- Separate service users, systemd sandboxing, and loopback bindings where practical
- Tor enforcement for supported Bitcoin services
- Restricted, time-limited support access with scoped `sudo`
- Operator-controlled public service exposure
- Operator-controlled public service exposure (Server + Desktop
[makes your home IP address public](#server--desktop-and-your-home-ip-address)
once you set up a domain)
See [`SECURITY.md`](SECURITY.md) for the threat model, limitations, reporting,
and operator guidance. No operating system can protect funds after recovery