Core
Bootstrap admin
Security
Which MCP clients may connect is not an instance setting: each workspace
decides it in Settings → MCP Clients (see
Governing connected clients).
An instance that sets
CONDUIT_CIMD_ALLOWED_DOMAINS refuses to boot until the
variable is unset, since it would otherwise admit every URL-based client the
operator meant to restrict.
Client IP attribution
Conduit records a client IP on audit-log entries and keys its per-IP rate limits (sign-in, sign-up, OAuth, failed MCP auth) on it.X-Forwarded-For and
X-Real-Ip are set by whoever sends the request, so Conduit honors them only
when the connection’s peer address is a proxy you have declared in
CONDUIT_TRUSTED_PROXIES. Otherwise it uses the peer address and logs a warning
once per process.
By default Conduit trusts loopback only (127.0.0.0/8 and ::1). Because
Conduit runs in a container, a loopback peer is by definition inside its own
network namespace: Conduit itself, or a sidecar sharing the pod — the
service-mesh topology, where the mesh proxy forwards over loopback. A pod-mate
can already read Conduit’s environment and service account, so trusting its
forwarded header grants nothing extra; the pod is the unit of trust.
If you run the Conduit binary directly on a host with other users or processes,
that no longer holds — any local process could forge the header. Set
CONDUIT_TRUSTED_PROXIES= (empty) there to trust nothing.
Every other proxy needs configuring, including in-cluster ones. A Kubernetes
ingress controller and a docker run -p bridge gateway both arrive from a
private-range address, which Conduit does not trust by default because an
attacker’s pod or another host on the same network is indistinguishable from
them.
The value is a comma-separated list of IPv4/IPv6 addresses and CIDR ranges. It
replaces the loopback default rather than adding to it, so list 127.0.0.0/8
and ::1/128 too if you need both. Unparseable entries are ignored.
What to set
There is deliberately no shorthand for “all private ranges” or “everything”.
Trusting a whole private range is the misconfiguration this setting exists to
prevent — on a Kubernetes cluster without NetworkPolicies, a Docker bridge, or an
office LAN, it trusts every peer that shares the network, including one an
attacker controls. Trusting everything is worse still: it would leave only the
attacker-controlled end of the forwarded chain to read.
Finding your proxy’s address
You don’t have to guess. Start Conduit, send a request through your proxy, and read the warning it logs:peer= value is your proxy. Trust the range it belongs to — proxy pods and
containers get new addresses when they restart, so use the CIDR rather than the
single address you happened to see:
Two consequences worth knowing
- If a proxy fronts your instance and you don’t configure it, every request resolves to that proxy’s address. Audit entries all show one IP, and each per-IP rate limit becomes a single instance-wide bucket — enough to throttle legitimate sign-ins during a login spike.
- List your proxy chain, and nothing beyond it. Conduit walks the forwarded chain right to left and returns the first address that is not trusted. So every intermediary must be listed for the walk to reach the real client — with a load balancer in front of your ingress controller, list both — while an address that is listed can never be reported as a client. Trusting a range that contains real users silently attributes their requests to the proxy.
Outbound requests
Every request Conduit makes to another service goes through one hardened HTTP client that blocks private and other special-use addresses, refuses redirects, and requireshttps. The two variables above are its only exemptions.
Network Access is the full picture: every host Conduit
connects to, what each is used for, and when it is contacted.
Documentation
Observability
Data retention
Conduit CLI
The CLI setup UI is feature-flagged and hidden by default. Read by theconduit CLI on users’ machines, not by the server.