Caddy www block lacks trusted_proxies (strip client-supplied XFF at the edge) #129

Stängd
öppnade 2026-07-19 06:58:04 +00:00 av supernaut · 1 kommentar
Ägare

Severity: MEDIUM (defence-in-depth) — pre-onboarding infra audit (2026-07-19).

The www.gitborg.se block (ansible/roles/caddy/templates/Caddyfile.j2:60-67) is a bare reverse_proxy bitborg-web:3000 with no trusted_proxies, so Caddy appends the real client IP to any client-supplied X-Forwarded-For rather than stripping it. bitborg-web PR #60 fixes the app side (read the rightmost/last XFF hop), but the edge should also strip client-supplied XFF for defence-in-depth — as Forgejo already does (REVERSE_PROXY_TRUSTED_PROXIES + REVERSE_PROXY_LIMIT=1, app.ini.j2:69-74).

Ask

Add trusted_proxies (the podman subnet) to the www block so Caddy replaces rather than appends XFF. Related: monitoring-VM Caddy pasta client-IP loss #100. Effort S.

**Severity: MEDIUM** (defence-in-depth) — pre-onboarding infra audit (2026-07-19). The `www.gitborg.se` block (`ansible/roles/caddy/templates/Caddyfile.j2:60-67`) is a bare `reverse_proxy bitborg-web:3000` with **no `trusted_proxies`**, so Caddy appends the real client IP to any client-supplied `X-Forwarded-For` rather than stripping it. bitborg-web PR #60 fixes the app side (read the rightmost/last XFF hop), but the edge should also strip client-supplied XFF for defence-in-depth — as Forgejo already does (`REVERSE_PROXY_TRUSTED_PROXIES` + `REVERSE_PROXY_LIMIT=1`, `app.ini.j2:69-74`). ### Ask Add `trusted_proxies` (the podman subnet) to the `www` block so Caddy replaces rather than appends XFF. Related: monitoring-VM Caddy pasta client-IP loss #100. Effort S.
Upphovsperson
Ägare

Implemented on branch feat/129-caddy-trusted-proxies (committed, push pending — SSH agent re-locked). Added caddy_trusted_proxies (the internal podman subnet, 10.89.0.0/24) and trusted_proxies to all three reverse_proxy blocks (www, kanidm, forgejo), not just www — Caddy is the edge and sees the real client IP via socket activation (#81), so real clients are untrusted and Caddy overwrites their X-Forwarded-For, stripping spoofed hops. Rendered Caddyfile validated with caddy validate (2.11.4). Ready to push + PR + apply.

Implemented on branch `feat/129-caddy-trusted-proxies` (committed, **push pending** — SSH agent re-locked). Added `caddy_trusted_proxies` (the internal podman subnet, 10.89.0.0/24) and `trusted_proxies` to all three reverse_proxy blocks (www, kanidm, forgejo), not just www — Caddy is the edge and sees the real client IP via socket activation (#81), so real clients are untrusted and Caddy overwrites their X-Forwarded-For, stripping spoofed hops. Rendered Caddyfile validated with `caddy validate` (2.11.4). Ready to push + PR + apply.
Logga in för att delta i denna konversation.
Ingen milstolpe
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra#129
Ingen beskrivning angiven.