Skip to content

Restore explicit non-loopback server bind mode #317

Description

@johnnygreco

Objective

Add an explicit server configuration opt-in that permits Beacon to bind to non-loopback interfaces, restoring direct private-network/Tailscale access such as http://100.88.255.7:4600/ while preserving loopback-only behavior by default.

Context

  • Tracker: GitHub goal delivery: restore explicit non-loopback Beacon bind mode #316
  • Self-contained context: Beacon currently validates server.host as loopback-only in internal/config/config.go, which prevents server.host = "0.0.0.0". That validation was added by 3d7a26e when the remote/multi-machine CLI surface was removed. The actual HTTP listener still uses fmt.Sprintf("%s:%d", cfg.Server.Host, cfg.Server.Port) in internal/beaconcli/cmd_serve.go, so allowing a non-loopback host behind an explicit opt-in restores direct Tailnet-IP access without reintroducing removed remote ingest/control-plane features.
  • Supporting links: GitHub goal delivery: restore explicit non-loopback Beacon bind mode #316, internal/config/config.go, internal/config/config_test.go, internal/beaconcli/cmd_serve.go, internal/beaconcli/main_test.go, docs/production.md.

Scope

  • In scope: add a named config field with a secure default that allows non-loopback server.host only when explicitly enabled; update validation, defaults, tests, and production docs.
  • Non-goals: do not reintroduce multi-machine fleet setup, enrollment, remote ingest, owner-token auth, reverse-proxy auth, or the removed loopback Host guard.
  • Backward compatibility: do not preserve general legacy behavior, add shims, or frame this as legacy support. The explicit user requirement is to restore the direct Tailnet access workflow through a deliberate modern config path.
  • Dependencies: none.
  • Sequencing: first and only implementation issue for GitHub goal delivery: restore explicit non-loopback Beacon bind mode #316.

Implementation Notes

Prefer a small config surface in [server], for example allow_non_loopback = true, with default false. Validation should reject non-loopback server.host values unless this option is true. Keep the server listener behavior unchanged once validation passes. Update docs to show a Tailscale/private-network example and call out that anyone who can reach the bound interface can inspect Beacon data.

Acceptance Criteria

  • Default config still binds 127.0.0.1:4600 and rejects server.host = "0.0.0.0" without opt-in.
  • Config with server.host = "0.0.0.0" and the explicit opt-in validates and can reach serve startup logic without failing on host validation.
  • Tests cover load/validation behavior and beacon up early rejection/acceptance around the opt-in.
  • Production docs describe loopback as the default, proxy/VPN as preferred for most remote access, and the explicit Tailscale/private-network bind option with security tradeoffs.
  • No removed multi-machine auth/control-plane/ingest surface is restored.

Required Validation

  • make fmt-check passes.
  • make generate-check passes.
  • go test ./internal/config ./internal/beaconcli passes.
  • make test passes.
  • make lint passes.
  • make install-local INSTALL_DIR="$HOME/.local/bin" succeeds.

PR Expectations

PR description should link #317 and #316, list exact validation results, and call out the security-sensitive review focus: opt-in only, default unchanged, docs clear.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions