Archarden is designed around a deliberately small public surface.
443/tcpvia Nginx Proxy Manager- WireGuard UDP (default
51820/udp)
- NPM admin: WireGuard-only
- Uptime Kuma: WireGuard-only
- SSH after lockdown: WireGuard-only
ntfy is the only intended public-facing service. Archarden generates a private-by-default configuration:
auth-default-access: deny-allweb-root: disablerequire-login: true- generated admin account
- generated publisher user and write-only publisher token
- no anonymous wildcard read ACL
Archarden also disables LLMNR and MulticastDNS under systemd-resolved, keeps SELinux enforcing, and verifies that no unexpected public listeners remain.