mirror of
https://github.com/open-jarvis/OpenJarvis.git
synced 2026-07-28 13:26:48 +00:00
All three deployment methods bound 0.0.0.0:8000 with no API key, so following
the README produced a server reachable from any device on the network with no
auth. `check_bind_safety` already refuses to start a non-loopback bind without
a key (so these configs actually failed to start) — this wires the key in so
the documented path yields a *working, authenticated* server.
- docker-compose.yml: require `OPENJARVIS_API_KEY` via `${VAR:?...}` so
`docker compose up` fails fast when unset; added `deploy/docker/.env.example`
(un-ignored in .gitignore).
- systemd: add `EnvironmentFile=/etc/openjarvis/env` (no `-` prefix, so a
missing key file blocks startup rather than exposing an open server).
- launchd: bind `127.0.0.1` by default (the personal-device default — no
network exposure, no key needed) with a documented, commented opt-in to
0.0.0.0 + `OPENJARVIS_API_KEY`. Avoids shipping a usable default credential.
- Docs (docker/systemd/launchd) updated with the key-setup step.
- Tests assert each config can't reintroduce an open server, plus
`check_bind_safety` behavior across loopback/public × key/no-key.
Closes #221
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
21 lines
648 B
Desktop File
21 lines
648 B
Desktop File
[Unit]
|
|
Description=OpenJarvis API Server
|
|
After=network.target
|
|
|
|
[Service]
|
|
Type=simple
|
|
User=openjarvis
|
|
WorkingDirectory=/opt/openjarvis
|
|
ExecStart=/opt/openjarvis/.venv/bin/jarvis serve --host 0.0.0.0 --port 8000
|
|
Restart=on-failure
|
|
RestartSec=5
|
|
Environment=HOME=/opt/openjarvis
|
|
# Binding 0.0.0.0 requires authentication. This file MUST exist and contain:
|
|
# OPENJARVIS_API_KEY=<key> (generate one: `jarvis auth generate-key`)
|
|
# It is not prefixed with "-", so the unit fails to start if the file is
|
|
# missing — preventing an accidentally unauthenticated public server.
|
|
EnvironmentFile=/etc/openjarvis/env
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|