Keep a box secure
A Mantle box exposes one front door, and its secrets live in .env. This page lists what is exposed, what leaves the box and what to keep safe.
What is exposed
- Only the front door (Caddy) listens on the network, on ports 80 and 443.
- The debug port (3000) listens on
127.0.0.1only. - Docker’s published ports bypass the host firewall. To keep a brain off the network, install with
--localhost, which setsMANTLE_BIND_ADDR=127.0.0.1. A firewall rule alone does not do it. - Use a domain with HTTPS for any box reachable from the internet. See Add a domain and HTTPS.
What leaves the box
- Prompts and retrieved context, to the model providers you configure. Nothing, if you use only local models.
- Email you send, and sign-in codes mailed to client logins.
- Telegram messages on a paired bot.
- Calls to MCP or OpenAPI connectors you connect.
- Update checks (version numbers only).
The secrets in .env
| Secret | Why it matters |
|---|---|
MANTLE_MASTER_KEY |
Decrypts stored API keys, mail passwords and secrets. Lose it and they are gone for good, backups included. Never change it on a running brain. |
SESSION_SECRET |
Signs every login session. |
MANTLE_SETUP_CODE |
Claims a fresh box. It stops working once the first account exists. |
| Database and object store passwords | Access to all data. |
The installer generates these, and re-running it never replaces an existing key.
What to keep safe
- Keep a copy of
.envoff the box, apart from your backups. A backup and the key it needs, stored together, is one theft away from fully readable. - Keep
.envreadable by its owner only. The installer sets mode 600. - Copy backups off the box. See Back up and restore.
Logins and access
- Every item has a level: admin, team, client or public. The database itself enforces it: a member reads items at team level or below, a client only client-level items. Admins read everything.
- Use a separate brain for groups that must not share admins.
- End a login’s access in Settings > Logins with Disabled or Sign out everywhere. It takes effect on the next request. See Add member and client logins.
- Check Settings > Audit log when something appears that nobody remembers creating.
The updater
The updater container controls Docker on the host. It opens no ports and accepts only two requests from Jackdaw: update to a version, or switch an optional service. If you do not want that, stop the updater service and update from the command line. See Update Mantle.