Relay security and access

TLS termination, firewall rules, and access control for a residential JSON relay exposed to the web.

Close-up of white Cat-5e Ethernet cables with RJ45 connectors
Probe JSON usually leaves the LAN over Ethernet or a nearby relay, not the public internet directly. Photo: DiscDepotDundee.co.uk. CC BY-SA 4.0

Publishing garage telemetry to the internet invites scanning. Lock down who can read feeds, rate-limit public endpoints, and never expose the Arduino JSON port directly without understanding the risk.

Hardening checklist

  • HTTPS only on public URLs; HSTS at the reverse proxy.
  • Optional API keys or signed tokens for non-browser clients.
  • Firewall the Arduino to LAN-only; only the relay reaches it.
  • No secrets in firmware source committed to public repos.

Dashboard integration

Users paste HTTPS feed URLs in temperature feed settings. The site stores URLs per account: pair with Supabase auth so feeds are not world-editable.

Compare stacks

Node and Next patterns for APIs: Node Express API patterns. This project uses Astro fetch routes: Astro SSR.

FAQ

Do ESP32 freeze probes need a public IP?
No for push ingest: the board POSTs outbound HTTPS to ProbeHarbor. Pull feeds need a reachable HTTPS JSON URL if you use that path.

How should I harden a DIY JSON relay?
Terminate TLS, restrict source IPs when possible, and avoid embedding ingest keys in public repos. Prefer ProbeHarbor push keys from Dashboard → Devices.