diff --git a/apps/docs/self-hosting/configuration.mdx b/apps/docs/self-hosting/configuration.mdx index 09478722..fc45b8d0 100644 --- a/apps/docs/self-hosting/configuration.mdx +++ b/apps/docs/self-hosting/configuration.mdx @@ -14,8 +14,38 @@ The installer writes API keys to `~/.supermemory/env`, which is loaded on every | Variable | Purpose | Default | |---|---|---| | `PORT` (or `SUPERMEMORY_PORT`) | HTTP listen port | `6767` | +| `HOST` (or `SUPERMEMORY_HOST`) | Network interface to bind (`127.0.0.1` for loopback, `0.0.0.0` for all interfaces) | `0.0.0.0` | | `SUPERMEMORY_DATA_DIR` | Where the graph engine's data, auth secret, and model cache live | `./.supermemory` | +### Network interface binding & Security + +By default, the self-hosted binary binds to all network interfaces (`0.0.0.0`), allowing access from local containers, remote devices, and the host. + + +**Public & Shared Network Caution**: On shared networks (coffee shops, offices, hotels), listening on `0.0.0.0` exposes the server port to other devices on the LAN. +To enforce loopback-only binding on local machines: +```bash +SUPERMEMORY_HOST=127.0.0.1 supermemory-server +# or in ~/.supermemory/env: +# SUPERMEMORY_HOST=127.0.0.1 +``` + + +#### Localhost Loopback Isolation + +For local development alongside tools like Claude Code, Cursor, or Codex, bind explicitly to `127.0.0.1` so that requests can only originate from your local machine: + +```bash +HOST=127.0.0.1 PORT=6767 supermemory-server +``` + +If you are running an older binary release (such as v0.0.6) that hardcodes `0.0.0.0`, you can isolate port access to localhost without elevated administrator privileges: + +- **Reverse Proxy / Port Forwarding**: Run a local forwarder such as `socat` or Nginx bound strictly to `127.0.0.1`. +- **Docker / Container Isolation**: Run the container with explicit loopback binding: `-p 127.0.0.1:6767:6767`. +- **OS Firewall**: Restrict inbound port 6767/6768 traffic via `pfctl` (macOS) or `iptables` / `ufw` (Linux). + + ## LLM providers In production, Supermemory uses its own proprietary models tuned for long-horizon data understanding. Self-hosted, you bring your own LLM for the intelligent steps — summaries, contextual chunking, and memory extraction. Embeddings default to a local model (no API key) and can optionally use OpenAI, Gemini, or Ollama — see [Embeddings](/self-hosting/embeddings). Configure **at least one** LLM provider: diff --git a/apps/docs/self-hosting/quickstart.mdx b/apps/docs/self-hosting/quickstart.mdx index d0b37991..5cab868f 100644 --- a/apps/docs/self-hosting/quickstart.mdx +++ b/apps/docs/self-hosting/quickstart.mdx @@ -76,6 +76,10 @@ In production, Supermemory runs proprietary models tuned for long-horizon data u **Docker / non-interactive:** set an LLM key via env and, if you don’t want local embeddings, set `SUPERMEMORY_EMBEDDING_PROVIDER` / `MODEL` / `DIMENSIONS`. There is no wizard without a TTY. + +**Loopback-only binding:** By default, the server binds to `0.0.0.0`. To restrict access to your local machine (recommended on shared Wi-Fi networks), start with `SUPERMEMORY_HOST=127.0.0.1 supermemory-server`. See [Configuration](/self-hosting/configuration#network-interface-binding--security). + + ## Add your first memory