You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Add an explicit server configuration opt-in that permits Beacon to bind to non-loopback interfaces, restoring direct private-network/Tailscale access such as http://100.88.255.7:4600/ while preserving loopback-only behavior by default.
Self-contained context: Beacon currently validates server.host as loopback-only in internal/config/config.go, which prevents server.host = "0.0.0.0". That validation was added by 3d7a26e when the remote/multi-machine CLI surface was removed. The actual HTTP listener still uses fmt.Sprintf("%s:%d", cfg.Server.Host, cfg.Server.Port) in internal/beaconcli/cmd_serve.go, so allowing a non-loopback host behind an explicit opt-in restores direct Tailnet-IP access without reintroducing removed remote ingest/control-plane features.
In scope: add a named config field with a secure default that allows non-loopback server.host only when explicitly enabled; update validation, defaults, tests, and production docs.
Non-goals: do not reintroduce multi-machine fleet setup, enrollment, remote ingest, owner-token auth, reverse-proxy auth, or the removed loopback Host guard.
Backward compatibility: do not preserve general legacy behavior, add shims, or frame this as legacy support. The explicit user requirement is to restore the direct Tailnet access workflow through a deliberate modern config path.
Prefer a small config surface in [server], for example allow_non_loopback = true, with default false. Validation should reject non-loopback server.host values unless this option is true. Keep the server listener behavior unchanged once validation passes. Update docs to show a Tailscale/private-network example and call out that anyone who can reach the bound interface can inspect Beacon data.
Acceptance Criteria
Default config still binds 127.0.0.1:4600 and rejects server.host = "0.0.0.0" without opt-in.
Config with server.host = "0.0.0.0" and the explicit opt-in validates and can reach serve startup logic without failing on host validation.
Tests cover load/validation behavior and beacon up early rejection/acceptance around the opt-in.
Production docs describe loopback as the default, proxy/VPN as preferred for most remote access, and the explicit Tailscale/private-network bind option with security tradeoffs.
No removed multi-machine auth/control-plane/ingest surface is restored.
Required Validation
make fmt-check passes.
make generate-check passes.
go test ./internal/config ./internal/beaconcli passes.
make test passes.
make lint passes.
make install-local INSTALL_DIR="$HOME/.local/bin" succeeds.
PR Expectations
PR description should link #317 and #316, list exact validation results, and call out the security-sensitive review focus: opt-in only, default unchanged, docs clear.
Objective
Add an explicit server configuration opt-in that permits Beacon to bind to non-loopback interfaces, restoring direct private-network/Tailscale access such as
http://100.88.255.7:4600/while preserving loopback-only behavior by default.Context
server.hostas loopback-only ininternal/config/config.go, which preventsserver.host = "0.0.0.0". That validation was added by3d7a26ewhen the remote/multi-machine CLI surface was removed. The actual HTTP listener still usesfmt.Sprintf("%s:%d", cfg.Server.Host, cfg.Server.Port)ininternal/beaconcli/cmd_serve.go, so allowing a non-loopback host behind an explicit opt-in restores direct Tailnet-IP access without reintroducing removed remote ingest/control-plane features.internal/config/config.go,internal/config/config_test.go,internal/beaconcli/cmd_serve.go,internal/beaconcli/main_test.go,docs/production.md.Scope
server.hostonly when explicitly enabled; update validation, defaults, tests, and production docs.Implementation Notes
Prefer a small config surface in
[server], for exampleallow_non_loopback = true, with defaultfalse. Validation should reject non-loopbackserver.hostvalues unless this option is true. Keep the server listener behavior unchanged once validation passes. Update docs to show a Tailscale/private-network example and call out that anyone who can reach the bound interface can inspect Beacon data.Acceptance Criteria
127.0.0.1:4600and rejectsserver.host = "0.0.0.0"without opt-in.server.host = "0.0.0.0"and the explicit opt-in validates and can reach serve startup logic without failing on host validation.beacon upearly rejection/acceptance around the opt-in.Required Validation
make fmt-checkpasses.make generate-checkpasses.go test ./internal/config ./internal/beaconclipasses.make testpasses.make lintpasses.make install-local INSTALL_DIR="$HOME/.local/bin"succeeds.PR Expectations
PR description should link #317 and #316, list exact validation results, and call out the security-sensitive review focus: opt-in only, default unchanged, docs clear.