rdmsm4x-changelog-20260915-1401-apex-access-and-udm-wan-exposure
rdmsm4x-changelog-20260915-1401-apex-access-and-udm-wan-exposure
Put the bare dataroo.net domain (which was publicly
serving the UniFi OS login) behind Cloudflare Access. Confirmed from
off-site that the UDM login is also reachable directly on both WAN IPs,
and filed SEC-20260915-01 with a fix plan.
- When: 2026-09-15 13:55 – 14:01 EDT
- Scope: Cloudflare account (Access); read-only probes from jdmbair13m5 and 18a-rdpi5b
- Follows: rdmsm4x-changelog-20260914-1533-starlink18a-dns-and-dns-cleanup
Changes
- Cloudflare Access app
09f3cb88-2ef9-4ecf-b28b-60dc7109812b"UDM Beast Apex (dataroo.net)" was created. It mirrorsudm.dataroo.netapp1ba1915a: Owner-only, same IdP, 720h session. - Ticket SEC-20260915-01 opened (high). A comment was added to ISSUE-20260904-06.
net/fleet-netmgmt: findings § 2026-09-15 and a new SESSION-STATE.md (commits e9c904d and one follow-up).
Verification
- Drift check: the zone is still 39 records, unchanged since 09-14 15:31, and no reboot has happened.
- Apex
/,/?nc=and/loginreturned 302 to Access on 9/9 probes between 13:57:20 and 13:58:01. udm/grafanastill return 302.- External probe from Starlink egress 129.222.242.166 (control
1.1.1.1:443passed): both WAN IPs on 443 return "UniFi OS" 200, and port 22 is closed.
Undo
Delete the Access app:
DELETE accounts/<acct>/access/apps/09f3cb88-2ef9-4ecf-b28b-60dc7109812b.
Owner actions (Rich)
- SEC-20260915-01: the UniFi firewall change needs a working UniFi UI/API session (the SSO account was locked on 09-13). The ticket holds the order of steps: tunnel ingress first, then the WAN 443 block.
- Tailscale admin console: approve
10.0.4.0/22on 18a-rdpi5b if wanted, and remove the stale10.0.4.0/24on 701-apple-tv-bedroom.