forked from heavy-duty/box
The 'no inbound path' contract is one notch too absolute for the tool's own flagship workflow: coding in a box, a dev server on :3000, and no way to open it in your browser. expose is the deliberate un-screwing. - Loopback only, always: the host side listens on 127.0.0.1, never 0.0.0.0 — no other machine can reach the box; only this host gets a door. No flag widens it (that is the escape hatch's job). - A verb, per-port, reversible, visible: each exposure is a named proxy device (expose-<port>); --list and box info show it, --remove undoes it. A box with a hole says so. - Mechanism (VMs): an Incus proxy device forwards host loopback to the box's ip:port, plus a SCOPED ingress ACL allow (this box's ip + this port only) so the forkproxy's connection survives the default drop — the drill decides whether that allow is needed or redundant. The in-box server must listen on 0.0.0.0 (a VM's forwarder reaches it over the network); inside an isolated box that is safe. Drill phase E: start a detached listener in a box, expose it, prove the HOST loopback reaches it, prove a NON-exposed port is still dropped (A7 survives), prove --remove shuts the door. Closes #55 |
||
|---|---|---|
| .. | ||
| box | ||