Security & FAQ
Security notes
In the current release, the control node does not provide built-in TLS or mTLS.
- Put console HTTP (
:8089) and gRPC (:50051) behind a reverse proxy or gateway. - Enforce TLS on public and external traffic.
- All worker implementations reject insecure console endpoints by default.
- Set
WORKER_CONSOLE_INSECURE=trueonly when you intentionally allow plaintext gRPC.
Operational reminders
- The one-click installer creates an additional admin API key — delete it at your discretion.
- Dashboard login sessions are in-memory and are invalidated when
consolerestarts. - Only versions 0.10.0 and later preserve session state across control node and worker restarts; earlier versions lose sessions on restart.
FAQ
A worker stays offline after startup. What should I check?
Verify WORKER_CONSOLE_GRPC_TARGET first, then confirm network connectivity from the worker host to the control node.
Can the worker run on the same machine as the control node?
Yes.
Can a worker run inside Docker?
In theory, yes. In practice it is usually not recommended because you need to deal with KVM in Docker or Docker in Docker issues.
Where are the deeper implementation docs?
The repository includes internal and low-level docs: