Proposition : SÉCURISATION URGENTE - Accès réseau complet
Date : 26/01/2026 00:45
Status : EN ATTENTE VALIDATION
Priorité : CRITIQUE
Constat - FAILLES DE SÉCURITÉ MAJEURES
1. O2switch - Services publics sans restriction
Risque : Tout le monde peut voir le monitoring, les tasks, propositions, backlog.
2. Nginx local - 48 services sans restriction IP
Le DNS public *.33800.nowhere84.com résout vers 82.65.119.221 (Freebox) qui forward vers nginx. Tous les services sans deny all sont accessibles depuis internet.
Services critiques exposés :
- portainer.33800.nowhere84.com (admin Docker)
- portainer-dev.33800.nowhere84.com
- pve.33800.nowhere84.com (admin Proxmox)
- proxmox.33800.nowhere84.com
- grafana.33800.nowhere84.com
- prometheus.33800.nowhere84.com
- registry.33800.nowhere84.com (Docker Registry)
- supabase-studio-prod.33800.nowhere84.com
- vscode.33800.nowhere84.com
- Et 39 autres...
3. Documentation mémoire INCORRECTE
Le fichier ~/.claude/memory/pihole-split-dns.md contient des informations FAUSSES :
- "EXTÉRIEUR: DNS public ne résout PAS" → FAUX
- "Extérieur | ❌ DNS ne résout pas" → FAUX
Réalité : Le wildcard DNS public *.33800.nowhere84.com → 82.65.119.221 existe (voir credentials.md ligne 89).
Informations Raph (ami 86000 - Poitiers)
| Info |
Valeur |
| Nom |
Raph |
| NRO |
86194COU |
| Référence PTO |
FI-8456-6614 |
| IPv4 fixe |
82.67.42.47 |
| Préfixe IPv6 |
2a01:e0a:fb8:78c0::/64 |
| Localisation |
Poitiers (86000) |
| Pattern futur |
*.86000.nowhere84.com |
Plan de correction
Étape 1 : Sécuriser O2switch (IMMÉDIAT)
Créer .htaccess dans chaque dossier public :
Fichier : ~/public_html/dashboard/.htaccess, ~/public_html/claude/.htaccess, ~/public_html/status/.htaccess
# Restriction d'accès - Réseau privé + Raph
# Généré : 26/01/2026
Order deny,allow
Deny from all
# 33800 - Bordeaux (Freebox)
Allow from 82.65.119.221
# 86000 - Raph Poitiers (Freebox)
Allow from 82.67.42.47
Allow from 2a01:e0a:fb8:78c0::/64
Étape 2 : Sécuriser TOUS les services nginx (sauf Jellyfin)
Ajouter la restriction IP dans les 48 configs sans deny all :
# Restriction d'accès - Réseau privé + Raph
allow 192.168.1.0/24; # LAN 33800
allow 127.0.0.1; # Localhost
allow 82.67.42.47; # Raph IPv4
allow 2a01:e0a:fb8:78c0::/64; # Raph IPv6
deny all;
Exception : jellyfin.33800.nowhere84.com reste public (seul service autorisé en externe).
Liste des 48 fichiers à modifier :
- 33800.nowhere84.com.conf
- ai-orchestrator.33800.nowhere84.com.conf
- applio.conf
- auth.33800.nowhere84.com.conf
- bark.conf
- bdd.33800.nowhere84.com.conf
- browser.33800.nowhere84.com.conf
- coder.33800.nowhere84.com.conf
- comfyui.conf
- facefusion.conf
- fooocus.conf
- grafana.33800.nowhere84.com.conf
- hellocar-admin-prod.33800.nowhere84.com.conf
- hellocar-api-prod.33800.nowhere84.com.conf
- hellocar-public-prod.33800.nowhere84.com.conf
- medias.33800.nowhere84.com.conf
- musicgen.conf
- needfinder-api-dev.33800.nowhere84.com.conf
- needfinder-api.33800.nowhere84.com.conf
- nginx.33800.nowhere84.com.conf
- notif-logger.33800.nowhere84.com.conf
- ntfy.33800.nowhere84.com.conf
- ollama.33800.nowhere84.com.conf
- openwebui.conf
- pirtainer.33800.nowhere84.com.conf
- portainer-dev.33800.nowhere84.com.conf
- portainer.33800.nowhere84.com.conf
- prometheus.33800.nowhere84.com.conf
- proxmox.33800.nowhere84.com.conf
- pve.33800.nowhere84.com.conf
- qig.33800.nowhere84.com.conf
- qwikpress-file.33800.nowhere84.com.conf
- qwikpress.33800.nowhere84.com.conf
- registry.33800.nowhere84.com.conf
- sadtalker.conf
- supabase-api-dev.33800.nowhere84.com.conf
- supabase-api-prod.33800.nowhere84.com.conf
- supabase-studio-prod.33800.nowhere84.com.conf
- supabase.33800.nowhere84.com.conf
- test-deploy.33800.nowhere84.com.conf
- test.33800.nowhere84.com.conf
- triposr.conf
- ulias.33800.nowhere84.com.conf
- vscide.33800.nowhere84.com.conf
- vscode.33800.nowhere84.com.conf
- wan.conf
- yolo.33800.nowhere84.com.conf
Étape 3 : Mettre à jour les 7 configs existantes
Ajouter l'IP de Raph dans les configs qui ont déjà des restrictions :
- connectors.33800.nowhere84.com.conf
- dashboard.33800.nowhere84.com.conf
- downloads.33800.nowhere84.com.conf
- gitlab.33800.nowhere84.com.conf
- nextcloud.33800.nowhere84.com.conf
- pihole.33800.nowhere84.com.conf
- syncthing.33800.nowhere84.com.conf
Étape 4 : Mettre à jour Smart-Deploy
Modifier /stock_8to/33800-stack/scripts/deploy/lib/nginx.sh pour inclure l'IP de Raph dans le template private: true.
Étape 5 : Corriger la mémoire
Fichier : ~/.claude/memory/pihole-split-dns.md
- Corriger les informations FAUSSES sur le DNS public
- Clarifier que Pi-hole = Split-DNS local uniquement, PAS une protection externe
- La vraie protection = restrictions nginx
allow/deny
Nouveau fichier : ~/.claude/memory/raph-86000.md
- Documenter les infos de Raph
- Référencer dans CLAUDE.md
Fichier : ~/.claude/memory/credentials.md
- Ajouter section "IPs autorisées en externe"
Ordre d'exécution
- O2switch : Créer les 3 .htaccess (5 min)
- Nginx - 48 configs : Ajouter restrictions (script automatisé)
- Nginx - 7 configs : Ajouter IP Raph
- Test nginx :
nginx -t && systemctl reload nginx
- Smart-Deploy : Mettre à jour template
- Mémoire : Corriger pihole-split-dns.md + créer raph-86000.md
- Vérification : Tester accès depuis extérieur (doit être bloqué sauf Jellyfin)
Validation requise
- [ ] Approuves-tu ce plan ?
- [ ] Les IPs de Raph sont-elles correctes ?
- [ ] Jellyfin est-il le SEUL service qui doit rester public ?
- [ ] Dois-je aussi ajouter ton préfixe IPv6 (si tu en as un) ?