Restrict direct Paseo mesh access to authorised Nebula clients #155

Open
opened 2026-08-09 20:48:01 +01:00 by nimmo · 0 comments
Owner

Context

Paseo daemons on Vega and Lyra now listen on their Nebula overlay IPs at TCP port 6767, enabling direct mesh connections alongside the public relay.

The host firewall limits this listener to nebula.mesh, but the current Nebula policy is permissive: any enrolled mesh peer can attempt a connection. Paseo password authentication remains required, but network access should be narrowed as defence in depth.

Scope

  • Define which Nebula hosts/users may connect directly to Paseo on Vega and Lyra.
  • Add Nebula inbound firewall rules restricting TCP 6767 to those authorised peers or groups.
  • Preserve relay access through code.nimmog.uk.
  • Preserve direct connections for the intended mesh clients.
  • Document the direct-connection security model and recovery steps.

Acceptance criteria

  • Unauthorised Nebula peers cannot reach TCP 6767 on Vega or Lyra.
  • Authorised clients can still connect directly to both hosts.
  • Relay connections continue to work.
  • Paseo password authentication remains enabled.
  • The policy is declared in Nix and validated with nix flake check.
  • A test deployment and no-op follow-up are recorded before closing.
## Context Paseo daemons on Vega and Lyra now listen on their Nebula overlay IPs at TCP port `6767`, enabling direct mesh connections alongside the public relay. The host firewall limits this listener to `nebula.mesh`, but the current Nebula policy is permissive: any enrolled mesh peer can attempt a connection. Paseo password authentication remains required, but network access should be narrowed as defence in depth. ## Scope - Define which Nebula hosts/users may connect directly to Paseo on Vega and Lyra. - Add Nebula inbound firewall rules restricting TCP `6767` to those authorised peers or groups. - Preserve relay access through `code.nimmog.uk`. - Preserve direct connections for the intended mesh clients. - Document the direct-connection security model and recovery steps. ## Acceptance criteria - Unauthorised Nebula peers cannot reach TCP `6767` on Vega or Lyra. - Authorised clients can still connect directly to both hosts. - Relay connections continue to work. - Paseo password authentication remains enabled. - The policy is declared in Nix and validated with `nix flake check`. - A test deployment and no-op follow-up are recorded before closing.
Sign in to join this conversation.
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
nimmo/nixos-config#155
No description provided.