Skip to content

Access to Your Muppy Instance

Who this page is for. You administer a Muppy instance that oursbl.eu operates. The instance sits behind the oursbl.eu Sunray Zero Trust. This page shows how to decide who reaches it, from your instance's own settings, without asking us. To protect your App Servers with Sunray, read Protect Your App Servers with Your Own Sunray.

How it works

Visitor → oursbl.eu Sunray ──── your Muppy instance
               │
               │ polls, Bearer token
               ▼
     your Muppy instance  /inouk-scp/v1/server/

Every visitor of your instance passes the oursbl.eu Sunray first. Sunray asks for a sign-in, unless your settings let the visitor through. It reads those settings from your instance itself: your instance publishes them as a Configuration Proxy, at /inouk-scp/v1/server/. That endpoint returns your instance alone, under the name of its web.base.url, with its internal users.

When oursbl.eu also protects your App Servers, its Sunray reads /inouk-scp/v1/ instead, which adds them to your instance.

You change the settings; Sunray applies them. Nobody at oursbl.eu has to act.

The settings are in Settings ▸ Sunray Proxy (SCP), in three blocks: Connect a Sunray Server to this Sunray Configuration Proxy, Access without a Sunray login and Public Paths. The first block links to this page.

When a change takes effect

The oursbl.eu Sunray reads your instance every 5 minutes. A change you save is applied at the next read. Testing sooner measures the previous state.

Allowed CIDRs: addresses that need no sign-in

Settings ▸ Sunray Proxy (SCP) ▸ Access without a Sunray login ▸ Allowed CIDRs lists the addresses that reach your instance without a Sunray sign-in: your office, your VPN. Your instance keeps its own login.

  • One IP address or CIDR network per line. # opens a comment.
  • An address is sent in its canonical form, once: 198.51.100.7 as 198.51.100.7/32, 10.0.0.5/24 as 10.0.0.0/24.
  • A line is refused, and never sent, when:
    • it is not an address nor a network;
    • it is an IPv6 address with a zone (%);
    • its prefix is shorter than /8 in IPv4 or /19 in IPv6 — 0.0.0.0/0 and ::/0 included;
    • it is an IPv6 range that covers part of a range carrying IPv4 addresses, with a prefix shorter than /104 (::ffff:0:0/96, ::/96, 64:ff9b::/96) or /24 (6to4, 2002::/16).
  • Validation Result, under the list, shows in YAML what is sent (sent) and each refused line with its reason (refused). A red box says when a line is refused.

Settings ▸ Sunray Proxy (SCP) ▸ Access without a Sunray login: a list with refused lines, its Validation Result and the red box

Allow access from everywhere

Settings ▸ Sunray Proxy (SCP) ▸ Access without a Sunray login ▸ Allow access from everywhere opens your instance to everyone, without a Sunray sign-in. Your instance keeps its own login. While it is checked, Allowed CIDRs and Public Paths have no effect, and a red box says so.

Settings ▸ Sunray Proxy (SCP) ▸ Access without a Sunray login: Allow access from everywhere checked, and its red box

Public Paths: parts of your instance open to everyone

Settings ▸ Sunray Proxy (SCP) ▸ Public Paths ▸ Public Paths opens some paths of your instance to everyone, without a Sunray sign-in: a webhook, an API, a health check.

  • One path per line, starting with /. * stands for any run of characters other than ?. # opens a comment.
  • /web/health opens that path alone, with or without a query string. /api/v1/* opens everything under /api/v1/.
  • Validation Result shows the regular expressions sent to Sunray, and each refused line with its reason.

Settings ▸ Sunray Proxy (SCP) ▸ Public Paths: three public paths typed, two sent and one refused, with the Validation Result and the red box

Writing them is reserved to the Sunray Advanced User group, because a public path bypasses Zero Trust. Grant it in Settings ▸ Users, section Sunray. Another administrator sees the list read-only, and saving the Settings never changes it on their behalf.

A list of paths opens what it enumerates, and nothing else:

  • a public page also needs its assets — /web/assets/*, /web/image/* — and each of its language prefixes;
  • it suits technical entry points (a webhook, an API, a health check) and a few pages, such as a landing page without a login;
  • it does not suit a whole site. Opening a site except its back office would take exclusion rules, which Sunray does not have.

Check what your instance publishes

Settings ▸ Sunray Proxy (SCP) ▸ Connect a Sunray Server to this Sunray Configuration Proxy shows:

  • Endpoint URLs: /inouk-scp/v1/ (everything your instance publishes) and /inouk-scp/v1/server/ (your instance alone);
  • Bearer Token and Test Command, under Show credentials. The command is a ready-made curl. Run it to read exactly what Sunray reads.

The Bearer Token is shared with the oursbl.eu Sunray. Do not generate a new one on your own: the oursbl.eu Sunray would get 403 from then on, and your instance would keep the access rules it last read. To rotate it, contact oursbl.eu support.

Troubleshooting

Symptom Where to look
an edited list has no effect its line is refused — read its Validation Result — or the next read has not happened yet (5 minutes)
a public path still asks for a sign-in its line is refused, Allow access from everywhere is checked, or the next read has not happened yet
everybody reaches the instance without a sign-in Allow access from everywhere is checked
you cannot edit Public Paths you are not a member of the Sunray Advanced User group