FerryDocs
Architecture

Security model

One administrator controls the full server. Only the proxy is open to the internet.

Edit on GitHub
Your serverInternetAdministratorcookie or tokenProxy0.0.0.0:8080API127.0.0.1:7878Containers127.0.0.1 onlyDocker

The internet reaches only the proxy. The proxy is the public edge of the server.

1 / 5

Ferry is for one team that runs its own server. A server has one . The person who signs in with it, or who has one of its , controls the full server.

What the model protects

  • The account, the tokens and the secrets stay on the server.
  • Only the is on the network.
  • One runaway app cannot stop the server.
  • Two Ferry servers cannot damage the containers of each other.

Ferry has no other users, no roles and no permissions per service. Read the known limitations before you put a server on the internet.

Connect from your machine

On a production server, keep the on . Reach it through an .

Terminal
ssh -L 7878:127.0.0.1:7878 you@your-server
ferry login --server http://127.0.0.1:7878

In this section

On this page