bitcoin: drop the stray UDP 3051 firewall rule

allowedUDPPorts was set to [ 3051 ] alongside allowedTCPPorts, which looks
like it was copied from the line above. Caddy serves Ride The Lightning
over TCP on 3051; nothing listens for UDP there, so the rule only opened a
port for no reason.

The comment above the pair also said "Hub management port"; 3051 is RTL.

Evaluated with nix eval, UDP firewall ports per role: Server + Desktop
80 443 3051 5353 -> 80 443 5353, Bitcoin Node Only 3051 5353 -> 5353,
Desktop Only 5353. (80 and 443 are Caddy's; 5353 is mDNS.)
This commit is contained in:
Security Fix
2026-10-02 02:24:29 -05:00
committed by naturallaw777
parent 6987d9bf2c
commit 3694ea6489
+4 -2
View File
@@ -105,9 +105,11 @@ in {
'';
};
# ── 5. Firewall — Hub management port ──────────────────────────
# ── 5. Firewall — RTL ──────────────────────────────────────────
# RTL is a web app served by Caddy over TCP on 3051. The matching UDP rule
# that used to sit here was carried over from the TCP line and opened a port
# nothing listens on.
networking.firewall.allowedTCPPorts = lib.mkIf cfg.services.bitcoin [ 3051 ];
networking.firewall.allowedUDPPorts = lib.mkIf cfg.services.bitcoin [ 3051 ];
# ── 6. NWC / LNURL — Sovran Hub integration ───────────────────
# Sovran_Bitcoin's albyhub.nix and lnurl.nix handle the base services.