sitescope a small health monitor and status page for a few hosts

Use

NixOS module

nixosModules.default runs the hub, the agent, or both on one host, as separate users with hardened systemd units.

Options

All under services.sitescope.

option default
enable false
role "hub" or "agent"
listenAddress "127.0.0.1" for the hub an agent’s wg0 address; required for an agent
port 8470 for the hub, 9105 for an agent
agent.enable false also run an agent on the hub host
agent.listenAddress the hub host’s wg0 address
agent.port 9105
adminGroup "sitescope-admin" members may use the control socket
settings { } the JSON configuration; see Configuration
environmentFile null KEY=value file outside the store
package this flake’s package

The module asserts that an agent has an address, and that agent.enable is only used with role = "hub".

The hub unit

sitescope.service, user sitescope:

The agent unit

sitescope-agent.service, user sitescope-agent:

On a hub host with agent.enable, the agent is a separate process and user, so the process holding the vault never has CAP_NET_ADMIN.

Shared hardening

Both units: ProtectSystem=strict, ProtectHome, PrivateTmp, PrivateDevices, NoNewPrivileges, the kernel and cgroup protections, RestrictNamespaces, RestrictRealtime, RestrictSUIDSGID, LockPersonality, MemoryDenyWriteExecute, SystemCallArchitectures=native, UMask=0077, Restart=on-failure. A config change restarts the unit.

Firewall

The module doesn’t open ports. Open 9105 on wg0 only:

networking.firewall.interfaces.wg0.allowedTCPPorts = [ 9105 ];

The hub’s port stays on loopback, behind your reverse proxy.