caddy: serve the Hub, RTL and Mempool sites to local clients only

The Hub (sovransystemsos.local), Ride The Lightning (:3051) and Mempool
(:60847) sites are meant for the home network. With ports 80/443
forwarded for public services, Caddy also receives requests from other
clients, so these sites now check the client address as well as the Host
header.

A new snippet, sovran_lan_only, closes the connection unless the client
is on this computer or the local network: private_ranges, 100.64.0.0/10
(Tailscale), 169.254.0.0/16, fe80::/10 and fc00::/7. IPv6 global
addresses (2000::/3) are not filtered: computers on the network often
connect over their own global address, which cannot be told apart from
one on the internet by the address alone. Only the three local sites
import the snippet; the domain sites for public services are unchanged.

Clients with a public IPv4 address on the local network are no longer
served on these sites. The Hub is still available on port 8937.

Checked with Caddy 2.11.4 and the Caddyfile the generator writes: public
IPv4 clients get the connection closed on all three sites, local clients
are served, and the public domain sites answer as before.

Add tests/test_caddy_lan_only.py and a note in SECURITY.md.
This commit is contained in:
Arena.ai Agent
2026-10-01 21:43:47 -05:00
committed by naturallaw777
parent 34cfba4282
commit c33457fff2
3 changed files with 139 additions and 0 deletions
+6
View File
@@ -35,6 +35,12 @@ external networks and are outside a “fully offline” model.
The local Hub currently uses HTTP. Authentication does not encrypt local network The local Hub currently uses HTTP. Authentication does not encrypt local network
traffic, so use a trusted LAN and avoid public or guest Wi-Fi. traffic, so use a trusted LAN and avoid public or guest Wi-Fi.
Caddy serves the Hub (`sovransystemsos.local`), Ride The Lightning (port 3051),
and Mempool (port 60847) only to this computer and to clients on your local
network (private, link-local, and VPN addresses), even when ports 80 and 443 are
forwarded to this computer for public services. Other IPv4 clients get the
connection closed. IPv6 global addresses are not filtered.
### Public services and your home IP address ### Public services and your home IP address
Server + Desktop publishes services under your own domain. The Dynamic DNS Server + Desktop publishes services under your own domain. The Dynamic DNS
+23
View File
@@ -89,6 +89,26 @@ EOF
EOF EOF
''} ''}
# ── LAN-only guard ──────────────────────────────
# The Hub, RTL and Mempool sites below are meant for this home network
# only. Forwarding ports 80/443 on the router also lets other clients
# reach Caddy, so these sites check where a request comes from, not just
# which Host it asks for. Anyone else gets the connection closed.
# private_ranges 10/8, 172.16/12, 192.168/16, 127/8, fd00::/8, ::1
# 100.64.0.0/10 Tailscale and other VPN addresses
# 169.254.0.0/16, fe80::/10, fc00::/7 link-local and unique-local
# 2000::/3 IPv6 global addresses. Computers on this network
# often connect over their own global address, which
# looks the same as one from the internet, so IPv6
# global addresses are not filtered.
cat >> /run/caddy/Caddyfile <<'EOF'
(sovran_lan_only) {
@outside not remote_ip private_ranges 100.64.0.0/10 169.254.0.0/16 fe80::/10 fc00::/7 2000::/3
abort @outside
}
EOF
# ── Matrix ────────────────────────────────────── # ── Matrix ──────────────────────────────────────
if [ -n "$MATRIX" ]; then if [ -n "$MATRIX" ]; then
if [ -f /run/caddy/element-calling.snippet ]; then if [ -f /run/caddy/element-calling.snippet ]; then
@@ -206,6 +226,7 @@ EOF
cat >> /run/caddy/Caddyfile <<EOF cat >> /run/caddy/Caddyfile <<EOF
http://sovransystemsos.local { http://sovransystemsos.local {
import sovran_lan_only
reverse_proxy localhost:8937 reverse_proxy localhost:8937
header { header {
Clear-Site-Data "\"cache\"" Clear-Site-Data "\"cache\""
@@ -220,6 +241,7 @@ EOF
cat >> /run/caddy/Caddyfile <<EOF cat >> /run/caddy/Caddyfile <<EOF
:3051 { :3051 {
import sovran_lan_only
reverse_proxy :3050 reverse_proxy :3050
encode gzip zstd encode gzip zstd
} }
@@ -229,6 +251,7 @@ EOF
cat >> /run/caddy/Caddyfile <<EOF cat >> /run/caddy/Caddyfile <<EOF
:60847 { :60847 {
import sovran_lan_only
reverse_proxy :60845 reverse_proxy :60845
encode gzip zstd encode gzip zstd
} }
+110
View File
@@ -0,0 +1,110 @@
"""Guards for the LAN-only Caddy sites.
The Hub (http://sovransystemsos.local), Ride The Lightning (:3051) and Mempool
(:60847) sites are for the home network. Caddy has to check where a request comes
from because forwarding ports 80/443 on the router lets other clients reach it too.
The domain sites for the operator's own public services must stay public.
These read modules/core/caddy.nix like the nix-file checks in test_security.py:
nothing is run and nothing touches the network.
"""
import ipaddress
import os
import re
import unittest
_ROOT = os.path.normpath(os.path.join(os.path.dirname(__file__), ".."))
# What Caddy's "private_ranges" shortcut expands to (see the remote_ip matcher docs).
_PRIVATE_RANGES = ["192.168.0.0/16", "172.16.0.0/12", "10.0.0.0/8",
"127.0.0.1/8", "fd00::/8", "::1"]
_LAN_SITES = ("http://sovransystemsos.local", ":3051", ":60847")
def _read(*parts):
with open(os.path.join(_ROOT, *parts), encoding="utf-8") as f:
return f.read()
def _site(src, address):
m = re.search(r"^" + re.escape(address) + r" \{\n(.*?)^\}$", src, re.S | re.M)
return m.group(1) if m else None
def _snippet(src):
m = re.search(r"^\(sovran_lan_only\) \{\n(.*?)^\}$", src, re.S | re.M)
return m.group(1) if m else None
def _allowed_networks(snippet):
m = re.search(r"^\s*@outside not remote_ip (.+)$", snippet, re.M)
assert m, "the @outside matcher is missing"
nets = []
for token in m.group(1).split():
for cidr in (_PRIVATE_RANGES if token == "private_ranges" else [token]):
nets.append(ipaddress.ip_network(cidr, strict=False))
return nets
def _is_allowed(nets, address):
ip = ipaddress.ip_address(address)
return any(ip.version == n.version and ip in n for n in nets)
class LanOnlySites(unittest.TestCase):
@classmethod
def setUpClass(cls):
cls.src = _read("modules", "core", "caddy.nix")
def test_lan_sites_use_the_guard_before_they_proxy(self):
for address in _LAN_SITES:
with self.subTest(site=address):
body = _site(self.src, address)
self.assertIsNotNone(body, f"{address} site not found")
self.assertIn("import sovran_lan_only", body)
self.assertLess(body.index("import sovran_lan_only"),
body.index("reverse_proxy"))
def test_only_the_lan_sites_use_the_guard(self):
self.assertEqual(self.src.count("import sovran_lan_only"), len(_LAN_SITES))
public = re.findall(r"^\$[A-Z]+ \{\n(.*?)^\}$", self.src, re.S | re.M)
self.assertGreaterEqual(len(public), 6, "domain sites not found")
for body in public:
self.assertNotIn("sovran_lan_only", body)
# the Matrix site that Element calling writes instead of the plain one
self.assertNotIn("sovran_lan_only", _read("modules", "element-calling.nix"))
def test_guard_closes_the_connection_for_everyone_else(self):
snippet = _snippet(self.src)
self.assertIsNotNone(snippet, "(sovran_lan_only) snippet not found")
self.assertRegex(snippet, r"(?m)^\s*abort @outside\s*$")
# defined before the first site that imports it
self.assertLess(self.src.index("(sovran_lan_only) {"),
self.src.index("import sovran_lan_only"))
def test_guard_ranges(self):
nets = _allowed_networks(_snippet(self.src))
for address in ("127.0.0.1", "::1", "10.0.0.1", "172.16.0.1", "172.31.255.254",
"192.168.1.10", "100.64.0.1", "100.127.255.254", "169.254.1.1",
"fd12:3456::1", "fe80::1", "fc00::1"):
with self.subTest(allowed=address):
self.assertTrue(_is_allowed(nets, address))
for address in ("8.8.8.8", "1.1.1.1", "203.0.113.9", "9.255.255.255", "11.0.0.1",
"172.15.255.255", "172.32.0.1", "192.169.0.1", "100.63.255.255",
"100.128.0.1", "169.253.255.255"):
with self.subTest(refused=address):
self.assertFalse(_is_allowed(nets, address))
def test_ipv6_global_addresses_are_not_filtered(self):
# Computers on the home network often connect over their own global IPv6
# address, which cannot be told apart from the internet's by address alone.
# If this is ever tightened, LAN clients on IPv6 networks lose the Hub.
nets = _allowed_networks(_snippet(self.src))
self.assertTrue(_is_allowed(nets, "2001:db8::5"))
if __name__ == "__main__":
unittest.main()