Skip to content

Traefik, Docmost, Coder, Kaneo, Miniflux, Tandoor, Pocket ID: close exposed services - #374

Open
jackspiering wants to merge 1 commit into
mainfrom
stack-network-exposure
Open

jackspiering wants to merge 1 commit into
mainfrom
stack-network-exposure

Conversation

@jackspiering

Copy link
Copy Markdown
Collaborator

Description

Closes network exposure in seven stacks.

  • Traefik:
    • --api.insecure=true becomes --api.dashboard=true, and --ping=true stays for the health check.
    • The unauthenticated mydashboard router is removed. Before this change, any LAN host sending Host: traefik.domain.local to port 80 got the dashboard and API.
    • The unused geoblock plugin flags are removed, and the README gains the docker socket warning and a recipe for a basic-auth dashboard router.
  • Docmost Redis: binds to localhost. It had no password and listened on the Tailscale IP.
  • PostgreSQL in Coder, Docmost, Kaneo, Miniflux and Tandoor: listen_addresses=localhost. The READMEs no longer say the database listens on the Tailscale IP, and each has an "Upgrading" note.
  • Pocket ID: ENCRYPTION_KEY is now required in compose.yaml. It reached the app only through env_file, so Compose passed with it empty and the app crash-looped.

Related Issues

  • None.

Verification

Each stack was run from a scratch copy in /tmp, once on the original files and once on the new ones, one stack at a time. The Tailscale service was a busybox stub, so no Tailnet node was created.

  • Traefik (3.7.14): the health check passes and /ping answers. The dashboard and API return 404 on ports 80 and 8080. Before, port 80 returned 200 without credentials. The documented basic-auth recipe returns 401 without credentials and 200 with them.
  • PostgreSQL and Redis: before, they listened on 0.0.0.0 and accepted connections at the namespace address. After, they listen only on 127.0.0.1 and ::1, and the namespace address refuses connections. Each one initialised a fresh data directory.
  • Apps: Miniflux, Docmost, Kaneo, Tandoor, Coder and Pocket ID reached healthy.
  • Pocket ID without ENCRYPTION_KEY crash-loops with ENCRYPTION_KEY must be at least 16 bytes long.
  • docker compose config --quiet passes in all seven directories with dummy values. rumdl check --config .markdownlint.yml . (0.2.78) and git diff --check origin/main are clean. Images and volumes were removed after each stack.

Not tested: upgrading over an existing data directory (only a command: line changed), LAN access through the published port 80, Pocket ID's ENCRYPTION_KEY_FILE, and a bcrypt hash in the dashboard recipe (an openssl passwd -apr1 hash was used).

Checklist

  • I have performed a self-review of my code and followed the templates structure.
  • I have added verification that the stack works as expected.
  • I have updated necessary documentation (e.g. frontpage README.md ).
  • I have selected the correct label(s) for this PR.

Additional Context

From an external review of the repository (section 3.1). I removed the Traefik dashboard router instead of requiring a new TRAEFIK_DASHBOARD_USERS, because a required variable would stop docker compose up for every existing user.

@jackspiering
jackspiering requested a review from crypt0rr October 10, 2026 13:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant