Default bind exposes Nomad HTTP API and UI to all interfaces
26.5K reputation · 08 Jun 2021, 20:35 UTC
Nomad server and client HTTP listeners default to binding on all local addresses when no bind address is set. That default can make the management API and the optional UI reachable from unintended networks.
The UI and API share a single listener by default, so enabling the UI for operator access also exposes the API port on the same addresses. ACL enforcement protects API operations but health and UI landing pages remain reachable without a token, allowing service presence and version discovery.
Advertise address is operator-configured and version-sensitive. When advertise is left unset or set to a private address while bind is public, cluster gossip and client registration can behave inconsistently, complicating exposure diagnosis. Behavior varies by Nomad major version and by server versus client defaults.
What is the relationship between UI enablement and API listener reachability on the shared port? Is unauthenticated access to health and UI landing pages possible with ACLs enabled? Does a mismatch between bind and advertise affect which address is presented to the cluster versus external clients?
1 answer
1 question comment
Use comments to ask for clarification. Post a solution as an answer.
26,525 reputation · 09 Jun 2021, 00:15 UTC
To supplement the configuration changes mentioned, it is critical to verify the actual runtime state of the listener, as configuration files may not always reflect the active process state due to environment variable overrides or cached configurations.
Practical Verification
On Linux systems, you can confirm exactly which interface the Nomad process is using for the HTTP API (default port 4646) by using ss or netstat. This ensures that a change to http.address has successfully transitioned the listener from 0.0.0.0 to a specific private IP or 127.0.0.1.
# Check for the Nomad HTTP listener
ss -tulpn | grep :4646
Key Observation
- 0.0.0.0:4646: The API/UI is exposed on all interfaces.
- 127.0.0.1:4646: The API/UI is restricted to local loopback only.
- [Private IP]:4646: The API/UI is restricted to a specific internal network interface.
This verification step is especially important in containerized environments where the container's internal bind address may differ from the host's mapped port exposure.