Skip to content

Make listening address configurable - #19

Merged
itsthisjustin merged 2 commits into
crosspoint-reader:mainfrom
mroethke:feature/configure_listening_address
Oct 4, 2026
Merged

itsthisjustin merged 2 commits into
crosspoint-reader:mainfrom
mroethke:feature/configure_listening_address

Conversation

@mroethke

@mroethke mroethke commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

This adds a environment variable LISTEN_ADDRESS that allows to configure the listening address. For security purposes it defaults to localhost.

It also updates the compose files to set the old, implicit, address of ::, since the new default does not work with docker.

crosspoint-sync listens on all interfaces without a way to change this,
add a LISTEN_ADDRESS env var to configure the listening socket.
The listening address was changed to default to localhost which won't do
for docker, this changes the listen address back to the old value in the
docker-compose files.
@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: abd51dd3-6ca0-460f-8e50-e9625706ad28
📥 Commits

Reviewing files that changed from the base of the PR and between ec98b5b and a0b8641.

📒 Files selected for processing (3)
  • docker-compose.dev.yml
  • docker-compose.yml
  • src/index.ts

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
🔇 Additional comments (3)
docker-compose.dev.yml (1)

11-12: LGTM!

docker-compose.yml (1)

11-12: LGTM!

src/index.ts (1)

12-12: LGTM!

Also applies to: 32-32, 37-37


📝 Walkthrough

Walkthrough

The Compose files set LISTEN_ADDRESS to "::". The server reads that setting, defaults to localhost, binds to the resulting address, and includes the reported address in its startup log.

Changes

Listen address configuration

Layer / File(s) Summary
Configure and bind the server
docker-compose.dev.yml, docker-compose.yml, src/index.ts
Both Compose files set LISTEN_ADDRESS to "::". The server reads the setting, defaults to localhost, binds to that address, and adds the reported address to the startup log.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Feature

Suggested reviewers: itsthisjustin

Merge Risk: ⚪ Minimal · up to a0b86

The Compose configurations preserve the intended external listener address, while standalone runs default to localhost. No verified issue currently warrants delaying the change.

Security Architecture Review

Security architecture risk: 🔵 Low · up to a0b86

The default listener becomes more restrictive, while Compose deliberately preserves external access. Existing application authorization remains in place. The deployed image version and host networking behavior are not established, limiting assurance about rollout behavior.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — With Compose's wildcard listener and published port, remote clients permitted by host networking can reach this service's public routes and authentication boundaries. Supported scope is the exposed service instance and its application interfaces, not new authority over other hosts or environments. Effective Internet reachability depends on deployment networking.

Security Findings and Attack Paths

  • inferred — The inspected listener change does not establish a newly enabled attacker path relative to the target branch: Compose retains intended external exposure, and the unconfigured default becomes more restrictive. Existing exposed routes remain architecture facts, not verified PR-introduced vulnerabilities. This conclusion is limited to the assessed listener path.

Trust Boundaries and Controls

  • observed — Deployment configuration controls transport reachability; request middleware controls authenticated application access. Both Compose files continue to configure registration as enabled, so localhost-by-default must not be interpreted as a restriction on registration in the explicitly exposed Compose deployments.

Hardening Proposals

  • proposed — Pin the production image to a known version or digest and document coordinated image/configuration rollback, so operators can establish whether the deployed application honors LISTEN_ADDRESS. This is deployment hardening for an existing mutable-image choice, not an observed PR regression.
🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly states the main change: making the listening address configurable.
Description check ✅ Passed The description explains the new LISTEN_ADDRESS setting, its localhost default, and the Compose configuration change.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@itsthisjustin
itsthisjustin merged commit 752b17a into crosspoint-reader:main Oct 4, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants