Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions src/content/docs/docs/security.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,6 +28,12 @@ Run it on a trusted network, or behind a reverse proxy that terminates TLS and a

Authentication is only in force once a password is stored. Until then, the endpoint that sets one accepts the first caller. See [First setup](/docs/first-setup/).

### Addresses without a password

While no password is set, Stackyard answers only on IP addresses, `localhost`, single-label names, names under `.local`, `.home.arpa`, `.internal` and `.localhost`, and the names in **Allowed Addresses**. Any other address gets a 403. This stops a web page on another site from pointing its own name at your server (DNS rebinding) and changing your settings.

The first page load after install or upgrade sets the list. A host name is trusted and saved. An IP address or local name saves an empty list. With a password set, every address works and the list is not checked.

## Secrets

Stored secrets are stripped from the config before it reaches the browser. A populated field reports as set without returning its value, in config responses and in exports alike.
Expand Down
1 change: 1 addition & 0 deletions src/content/docs/docs/settings-reference.md
Original file line number Diff line number Diff line change
Expand Up @@ -40,6 +40,7 @@ If every app suddenly shows as unhealthy, the socket proxy address is the usual
| --- | --- |
| Password Protection | Sets or changes the dashboard password. Between 8 and 1024 characters. Leave blank to keep the existing one. Changing the password, or turning protection off, asks for the current password. |
| Sign out all devices | Ends every session everywhere, including the one you are using. Use it if you think a session may be compromised. |
| Allowed Addresses | Host names Stackyard answers on while no password is set, separated by commas. IP addresses and local names such as `nas` or `nas.local` always work and need no entry. The first address used to open Stackyard is added for you. See [Security](/docs/security/#addresses-without-a-password). |

Locked out? See [password recovery](/docs/troubleshooting/#i-forgot-the-password-and-i-am-locked-out).

Expand Down
11 changes: 11 additions & 0 deletions src/content/docs/docs/troubleshooting.md
Original file line number Diff line number Diff line change
Expand Up @@ -60,6 +60,15 @@ To fix it, on the server:

The container log shows `config file cannot be used; sign-in and saving are refused until it is fixed`, with the reason and the copy's name.

### Stackyard does not answer on this address

No password is set, and the address in your browser is not an IP address, a local name, or an entry in **Allowed Addresses**. Stackyard refuses it so a web page on another site cannot reach your settings. See [Security](/docs/security/#addresses-without-a-password).

1. Open Stackyard by its IP address, or by an address you already allowed.
2. In **General**, add the address to **Allowed Addresses** and save.
3. Or set a password. With a password, every address works.
4. Choose **Check again**.

### My dashboard is empty after a restart

Confirm both volumes are mounted. Without `./data` nothing persists.
Expand Down Expand Up @@ -248,6 +257,8 @@ Messages shown in the admin, and what each one means.
| `The password was changed elsewhere. Reload the page and try again.` | The password changed on another device while this save ran. Nothing was saved. |
| `Too many attempts. Try again later.` | 5 wrong passwords from this IP in 15 minutes. Wait, then try again. See [above](#one-persons-failed-logins-lock-everyone-out). |
| `Stackyard cannot use its settings file` | The config file is damaged or cannot be read. Sign-in and saving are off until it is fixed. See [above](#stackyard-cannot-read-its-settings-file). |
| `Stackyard does not answer on this address` | No password is set and this address is not allowed. See [above](#stackyard-does-not-answer-on-this-address). |
| `Keep ... in Allowed Addresses, or this page stops working.` | The save would drop the address this page is open on while no password is set. Remove it from another address. |
| `Enter the credential again for: ...` | The request a secret belonged to changed, so the secret was cleared. Re-enter and save. |
| `Nothing at that address answered.` | The socket proxy address is unreachable from inside the container. Usually a proxy published on the host's loopback. |
| `That name is resolved by Docker, which answers only for containers on a shared network.` | The socket proxy service name is not on a network Stackyard shares. |
Expand Down
Loading