feat(security): bind Bitcoin RPC/ZMQ publishes to loopback + archy-net gateway (§C)
USER DECISION 2026-07-08: accept breaking external wallets pointed at nodeIP:8332. The 0.0.0.0 publish exposed auth-only RPC (and unauthenticated ZMQ 28332/28333 on the legacy path) to the whole LAN. - New `bind` field on manifest port mappings (validated as an IP; the same host port may repeat with distinct binds). Rendered as PublishPort=<ip>:<host>:<container> in quadlet units and host_ip in the podman API create — unbound ports render byte-identical to before, so no fleet-wide false-drift wave. - bitcoin-knots/-core manifests publish 8332 on 127.0.0.1 + 10.89.0.1 only. In-node consumers (lnd, fedimint-gateway, btcpay/nbxplorer) are unaffected: they dial host.archipelago / host.containers.internal, which the orchestrator pins to the archy-net gateway 10.89.0.1. P2P 8333 stays public. - Legacy config.rs port strings get the same treatment incl. ZMQ. Tests: new quadlet bind-render + manifest bind-validation tests; container:: suite 167/167, archipelago-container 63/63. DEPLOY NOTE: PublishPort strings change for bitcoin containers → one planned recreate per node; restart lnd afterwards (it caches the backend IP — see the backend-recreate cascade tracker item). Catalog manifests for bitcoin apps must be regenerated + re-signed for catalog-covered nodes. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5
parent
81743874a1
commit
dd61a20413
@@ -299,11 +299,15 @@ impl PodmanClient {
|
||||
"sctp" => "sctp",
|
||||
_ => "tcp",
|
||||
};
|
||||
port_mappings.push(serde_json::json!({
|
||||
let mut mapping = serde_json::json!({
|
||||
"container_port": port.container,
|
||||
"host_port": port.host,
|
||||
"protocol": protocol,
|
||||
}));
|
||||
});
|
||||
if !port.bind.is_empty() {
|
||||
mapping["host_ip"] = serde_json::json!(port.bind);
|
||||
}
|
||||
port_mappings.push(mapping);
|
||||
}
|
||||
|
||||
let mut mounts = Vec::new();
|
||||
|
||||
Reference in New Issue
Block a user