ArchitectureSecurity model
What listens where
Only the proxy accepts connections from other machines. All other ports are on 127.0.0.1.
The proxy listens on 0.0.0.0. Each machine can reach it: it is the public edge.
1 / 4
A listener on 127.0.0.1 (localhost) accepts connections only from the server itself. A listener on 0.0.0.0 accepts connections from each machine.
The listeners
| Listener | Default | Who can reach it |
|---|---|---|
API and dashboard (--api-addr) | 127.0.0.1:7878 | The server itself only |
Proxy (--proxy-addr, --https-addr) | 0.0.0.0:8080 | Everywhere: this is the public edge |
| App containers | 127.0.0.1:<random> | The server itself only. The public reaches them through the proxy. |
| Datastores | 127.0.0.1:<fixed port> | The server itself only |
The networking model tells why the ports of the containers are on 127.0.0.1.
What to do
Keep --api-addr on 127.0.0.1. To use the API from another machine, read Reach the API through SSH.
Production setup gives a complete hardened setup.