From d1f4f1cb969a5600a03fc2d141d08b2816e57f45 Mon Sep 17 00:00:00 2001 From: Vuong Hoang Date: Mon, 17 Aug 2026 21:14:22 -0700 Subject: [PATCH] docs(homepage): record the ALLOWED_HOSTS fix, .env lockdown, and verification method HOMEPAGE_ALLOWED_HOSTS now carries the IP:port form; direct access to http://10.0.50.45:5100/ returns 200 and the host-validation errors are gone from the container log. The .env was mode 644 holding the Plex and Jellyfin API keys; now 600. It is root-owned, so editing it needs the infra-ops identity -- lkraven has only password-sudo on that host. Also records that Homepage renders client-side, so grepping the served HTML to verify a config change is the wrong instrument (it gave a stale prerender and then an empty page). GET /api/services is the honest check, and config changes need a recreate rather than a restart. --- stacks/homepage/README.md | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/stacks/homepage/README.md b/stacks/homepage/README.md index 043ed89..d7edc21 100644 --- a/stacks/homepage/README.md +++ b/stacks/homepage/README.md @@ -44,8 +44,16 @@ rather than when the group is wrong. - **`HOMEPAGE_ALLOWED_HOSTS` matches host *and port*.** The entry `10.0.50.45` does **not** cover `http://10.0.50.45:5100/` — that combination was being rejected with `Host validation failed` in the container log while the Traefik - hostnames worked fine. Every `host:port` the dashboard is reached by needs - its own entry. See `.env.example`. + hostnames worked fine. **Fixed 2026-08-17**; every `host:port` the dashboard + is reached by needs its own entry. See `.env.example`. +- **The `.env` was mode 644** with the Plex and Jellyfin API keys in it. Now + `600`. It is root-owned, so it needs the `infra-ops` identity to edit — + `lkraven` on this host has password-sudo only. +- **Homepage renders client-side.** Grepping the served HTML to verify a config + change gives false readings — first a stale prerender, then an empty page. + `GET /api/services` is the honest check; it returns the resolved group/service + tree. Config edits also need a **container recreate**, not a restart: a + restart keeps the writable layer and its cached render. - **`:2375` is plaintext and unauthenticated** on all five engines. Fine on a trusted LAN, and unchanged by this commit, but it is real exposure: anything that can reach those ports has full Docker control of that host. `docker.yaml`