FerryDocs
ArchitectureSecurity model

What listens where

Only the proxy accepts connections from other machines. All other ports are on 127.0.0.1.

Edit on GitHub
Your serverInternetProxyopen to allApp container127.0.0.1:<random>API + dashboard127.0.0.1:7878Datastore127.0.0.1

The proxy listens on 0.0.0.0. Each machine can reach it: it is the public edge.

1 / 4

A listener on 127.0.0.1 () accepts connections only from the server itself. A listener on 0.0.0.0 accepts connections from each machine.

The listeners

ListenerDefaultWho can reach it
API and dashboard (--api-addr)127.0.0.1:7878The server itself only
(--proxy-addr, --https-addr)0.0.0.0:8080Everywhere: this is the public edge
App containers127.0.0.1:<random>The server itself only. The public reaches them through the proxy.
Datastores127.0.0.1:<fixed port>The server itself only

The networking model tells why the ports of the containers are on 127.0.0.1.

What to do

Keep --api-addr on 127.0.0.1. To use the API from another machine, read Reach the API through SSH.

Production setup gives a complete hardened setup.

On this page