Architecture
Security model
One administrator controls the full server. Only the proxy is open to the internet.
The internet reaches only the proxy. The proxy is the public edge of the server.
1 / 5
Ferry is for one team that runs its own server. A server has one account. The person who signs in with it, or who has one of its API tokens, controls the full server.
What the model protects
- The account, the tokens and the secrets stay on the server.
- Only the proxy is on the network.
- One runaway app cannot stop the server.
- Two Ferry servers cannot damage the containers of each other.
Ferry has no other users, no roles and no permissions per service. Read the known limitations before you put a server on the internet.
Connect from your machine
On a production server, keep the API on localhost. Reach it through an SSH tunnel.
ssh -L 7878:127.0.0.1:7878 you@your-server
ferry login --server http://127.0.0.1:7878