koopa-admin-log/ISSUES.md
Hernâni Marques 1aa4d1bab8 docs: English ISSUES and Nym public listing locations
Document harbourmaster/explorer URLs and identity key; translate ISSUES to English.
2026-07-16 16:37:57 +02:00

126 lines
3.3 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# Open issues
As of **2026-07-16** (live scan on koopa). No secrets.
---
## I-2026-07-16-01 — firewalld: Nym ports on koopa unverified
| | |
|--|--|
| **Severity** | high (for public Nym reachability) |
| **Host** | koopa |
| **Status** | open |
VeciGate DNATs **1789/tcp+udp**, **1790/tcp**, **51822/udp** → koopa.
Without matching **firewalld** allow rules on koopa, traffic dies on the host.
Agent could not run `firewall-cmd` (**sudo password required**).
```bash
# on koopa (with sudo)
sudo firewall-cmd --permanent --add-port=1789/tcp
sudo firewall-cmd --permanent --add-port=1789/udp
sudo firewall-cmd --permanent --add-port=1790/tcp
sudo firewall-cmd --permanent --add-port=51822/udp
sudo firewall-cmd --reload
sudo firewall-cmd --list-ports
```
---
## I-2026-07-16-02 — Nym node not bonded / not in public explorers
| | |
|--|--|
| **Severity** | medium (visibility on the Nym network) |
| **Host** | koopa (`koopa-nym`) |
| **Status** | open |
Container **is running** (mixnode); API on **9080** answers.
Without a **bond** in the Nym wallet the node typically does **not** show up in Harbour Master / network explorers (unlike Tor after ORPort publish).
See also: `configs/nym/PUBLIC-LISTING.md`.
Logs: WARN `validator.nymtech.net/api/.../refresh-described`**404** (API path/version; node still runs mixmode).
**Identity key (public):** `55gPqeyHHj4CwpVZXLEQy9MjSvVTVXM8t2pMmNCH2MsW`
---
## I-2026-07-16-03 — `podman-restart.service` enabled, inactive this session
| | |
|--|--|
| **Severity** | low (until reboot is tested) |
| **Host** | koopa (user hernani) |
| **Status** | open / expected until reboot |
`systemctl --user is-enabled podman-restart` = **enabled**,
`is-active` = **inactive** (oneshot; has not run this boot session).
After reboot:
```bash
systemctl --user is-active podman-restart.service
podman ps -a --filter should-start-on-boot=true --format '{{.Names}} {{.Status}}'
```
---
## I-2026-07-16-04 — Stray container `kind_taussig`
| | |
|--|--|
| **Severity** | low (hygiene) |
| **Host** | koopa |
| **Status** | open |
Container **Up** ~5 days: `kind_taussig` (`debian:bookworm-slim`), one-off wallet/DEB test script, **`restart=no`**, not a production name.
Candidate to stop/remove when logs are no longer needed:
```bash
podman stop kind_taussig
podman rm kind_taussig
```
---
## I-2026-07-16-05 — Old exited Podman containers (clutter)
| | |
|--|--|
| **Severity** | low (hygiene) |
| **Host** | koopa |
| **Status** | open |
Several **Exited** containers (months/years old), e.g. `pensive_dubinsky`,
`hardcore_edison`, `taler-exchange-no-network`, `debian00`, …
No autostart; only clutter `podman ps -a`.
Optional cleanup: `podman container prune` (exited only, after review).
---
## I-2026-07-16-06 — Nym HTTP API listens on `*:9080`
| | |
|--|--|
| **Severity** | lowmedium (attack surface) |
| **Host** | koopa |
| **Status** | open (as configured in compose) |
`ss` shows **\*:9080** (rootlessport). **No** VeciGate DNAT for 9080.
Usually not reachable from WAN without NAT; reachable from LAN.
Optional harden: publish only `127.0.0.1:9080:8080` in compose.
---
## Not an issue (scan)
- All production `should-start-on-boot` containers **Up**
- No failed user units
- Taler ports 90109015 respond (401/302 OK)
- Linger=yes, container-* units enabled