hermes: dashboard auth gate + container firewall port #27
Loading…
Reference in a new issue
No description provided.
Delete branch "hermes-dashboard-auth"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Problem
https://hermes.in.freun.devtimed out after the 2026-09-28 01:36 deploy. Two independent causes:non-loopback address (
10.69.0.10) unless an auth provider is registered. Thecredentials that worked before lived only in the runtime
config.yaml/.env, which the module rebuilds from scratch on every activation — so theywere wiped, and
hermes-backendcrash-looped with exit 1.networking.firewall.enable = truein the container with an emptyallowedTCPPorts, so the host nginx vhost's proxied connections to10.69.0.10:9119were dropped (TLS handshake completes, response hangs).Fix
modules.secrets.hermes.envgainsHERMES_DASHBOARD_BASIC_AUTH_PASSWORDandHERMES_DASHBOARD_BASIC_AUTH_SECRET— the dashboard auth plugin readsHERMES_DASHBOARD_BASIC_AUTH_*env vars with precedence over config, and theyflow through the existing
sops.templates."hermes-env"→environmentFiles→ merged.envpath.HERMES_DASHBOARD_BASIC_AUTH_USERNAME = "hermes"is a non-secret and goes inthe plain
environmentblock.cfg.dashboardPortfor the host vhost.The Host-header middleware accepts
hermes.in.freun.devalready (it matchessettings.dashboard.public_url), so no proxy-header changes are needed.⚠️ Rekey needed BEFORE deploying this
sops secrets/hermes.yaml(YubiKey; creation rule already exists) and add:Both values are in the Vaultwarden org item
hermes dashboard (freun-dev)(password field = login password; signing secret is in the notes). Until the
rekey lands,
sops-install-secretson freun-dev will fail on the missing keysand the container won't rebuild.
Verification
nix evalgreen for the toplevel drv, container firewall ports[9119], andthe username env var.
(bind gate satisfied, correct password → 200 + session cookie, wrong password
→ 401).
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.