hermes: dashboard auth gate + container firewall port #27

Open
hermes wants to merge 1 commit from hermes-dashboard-auth into main
Collaborator

Problem

https://hermes.in.freun.dev timed out after the 2026-09-28 01:36 deploy. Two independent causes:

  1. Auth gate: the current hermes-agent build refuses to bind the dashboard to a
    non-loopback address (10.69.0.10) unless an auth provider is registered. The
    credentials that worked before lived only in the runtime config.yaml /
    .env, which the module rebuilds from scratch on every activation — so they
    were wiped, and hermes-backend crash-looped with exit 1.
  2. Firewall: networking.firewall.enable = true in the container with an empty
    allowedTCPPorts, so the host nginx vhost's proxied connections to
    10.69.0.10:9119 were dropped (TLS handshake completes, response hangs).

Fix

  • modules.secrets.hermes.env gains HERMES_DASHBOARD_BASIC_AUTH_PASSWORD and
    HERMES_DASHBOARD_BASIC_AUTH_SECRET — the dashboard auth plugin reads
    HERMES_DASHBOARD_BASIC_AUTH_* env vars with precedence over config, and they
    flow through the existing sops.templates."hermes-env" →
    environmentFiles → merged .env path.
  • HERMES_DASHBOARD_BASIC_AUTH_USERNAME = "hermes" is a non-secret and goes in
    the plain environment block.
  • Container firewall opens cfg.dashboardPort for the host vhost.

The Host-header middleware accepts hermes.in.freun.dev already (it matches
settings.dashboard.public_url), so no proxy-header changes are needed.

⚠️ Rekey needed BEFORE deploying this

sops secrets/hermes.yaml (YubiKey; creation rule already exists) and add:

HERMES_DASHBOARD_BASIC_AUTH_PASSWORD: <vault>
HERMES_DASHBOARD_BASIC_AUTH_SECRET: <vault>

Both values are in the Vaultwarden org item hermes dashboard (freun-dev)
(password field = login password; signing secret is in the notes). Until the
rekey lands, sops-install-secrets on freun-dev will fail on the missing keys
and the container won't rebuild.

Verification

  • nix eval green for the toplevel drv, container firewall ports [9119], and
    the username env var.
  • The plugin's env-var path was exercised end-to-end against the live backend
    (bind gate satisfied, correct password → 200 + session cookie, wrong password
    → 401).
## Problem `https://hermes.in.freun.dev` timed out after the 2026-09-28 01:36 deploy. Two independent causes: 1. **Auth gate**: the current hermes-agent build refuses to bind the dashboard to a non-loopback address (`10.69.0.10`) unless an auth provider is registered. The credentials that worked before lived only in the runtime `config.yaml` / `.env`, which the module rebuilds from scratch on every activation — so they were wiped, and `hermes-backend` crash-looped with exit 1. 2. **Firewall**: `networking.firewall.enable = true` in the container with an empty `allowedTCPPorts`, so the host nginx vhost's proxied connections to `10.69.0.10:9119` were dropped (TLS handshake completes, response hangs). ## Fix - `modules.secrets.hermes.env` gains `HERMES_DASHBOARD_BASIC_AUTH_PASSWORD` and `HERMES_DASHBOARD_BASIC_AUTH_SECRET` — the dashboard auth plugin reads `HERMES_DASHBOARD_BASIC_AUTH_*` env vars with precedence over config, and they flow through the existing `sops.templates."hermes-env"` → `environmentFiles` → merged `.env` path. - `HERMES_DASHBOARD_BASIC_AUTH_USERNAME = "hermes"` is a non-secret and goes in the plain `environment` block. - Container firewall opens `cfg.dashboardPort` for the host vhost. The Host-header middleware accepts `hermes.in.freun.dev` already (it matches `settings.dashboard.public_url`), so no proxy-header changes are needed. ## ⚠️ Rekey needed BEFORE deploying this `sops secrets/hermes.yaml` (YubiKey; creation rule already exists) and add: ``` HERMES_DASHBOARD_BASIC_AUTH_PASSWORD: <vault> HERMES_DASHBOARD_BASIC_AUTH_SECRET: <vault> ``` Both values are in the Vaultwarden org item **`hermes dashboard (freun-dev)`** (password field = login password; signing secret is in the notes). Until the rekey lands, `sops-install-secrets` on freun-dev will fail on the missing keys and the container won't rebuild. ## Verification - `nix eval` green for the toplevel drv, container firewall ports `[9119]`, and the username env var. - The plugin's env-var path was exercised end-to-end against the live backend (bind gate satisfied, correct password → 200 + session cookie, wrong password → 401).
hermes: dashboard auth gate + container firewall port
All checks were successful
Build Images / build (pull_request) Successful in 40s
Check / check (pull_request) Successful in 4m17s
380e267051
The dashboard backend refuses non-loopback binds without a registered auth
provider, and the container firewall dropped the host vhost's proxied traffic
(allowedTCPPorts was empty). Feed the basic-auth credentials through the
existing sops env file and open the dashboard port.

Rekey needed before deploy: add HERMES_DASHBOARD_BASIC_AUTH_PASSWORD and
HERMES_DASHBOARD_BASIC_AUTH_SECRET to secrets/hermes.yaml (creation rule
already exists; sops secrets/hermes.yaml with the YubiKey). Values are in
the vault item 'hermes dashboard (freun-dev)'.
All checks were successful
Build Images / build (pull_request) Successful in 40s
Check / check (pull_request) Successful in 4m17s
Required
Details
This pull request can be merged automatically.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin hermes-dashboard-auth:hermes-dashboard-auth
git switch hermes-dashboard-auth
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
repomaa/nixos!27
No description provided.