This project is intended to run as a public, read-only MeshCore Canada live map.
The public deployment should use PUBLIC_MODE=true, which exposes only:
/healthz/readyz/api/v1/public/state/api/v1/public/bootstrap/api/v1/public/history/api/v1/public/history/summary/api/v1/public/packets/ws/public- the static dashboard
Internal debug APIs must stay disabled for public deployments. Detailed
/metrics is loopback-only by default in public mode.
Never commit or share:
.envor any environment file containing real values- MQTT usernames or passwords
- MeshCore private keys
- channel secrets used for message decoding
- live SQLite databases, WAL files, or SHM files
- local
data/config.yamlfiles with operator-only overrides - raw packet captures copied from live traffic
The repository ignore rules are configured to keep these files out of git, but
check git status --ignored before publishing.
If you find a security or privacy issue, do not open a public issue with credentials, packet data, or private configuration. Contact the maintainer privately first, then share only the minimum sanitized reproduction details.
Public API responses are expected to omit public keys, packet hashes, raw packet summaries, path hex, observer public keys, and resolver debug reasons. Any change that touches public response shaping must keep the privacy tests passing.
Production must use immutable image digests, keep port 39476 loopback-only, and
restrict the port-80 ingress to the configured proxy network. Forwarded client
headers are trusted only when the immediate peer matches TRUSTED_PROXY_CIDRS.
MeshCore-controlled display strings, including node names, observer names, message senders, message text, anchors, and packet-path endpoint labels, are normalized before they leave the public API/WebSocket boundary. Public display fields are text only; HTML-significant characters are stripped so crafted node names cannot become markup in MC-CartoLive or downstream public consumers.
Frontend code should continue to render public strings as text, not HTML.