ArchitectureSecurity model
Reach the API through SSH
Keep the API on localhost. An SSH tunnel brings its port to your machine.
The API listens only on 127.0.0.1 of the server. The internet cannot reach it.
1 / 3
This is the safer default for a production server. The API stays on localhost, and the SSH tunnel encrypts the traffic.
Do it
Open the tunnel
Run this command on your machine. Keep it open.
ssh -L 7878:127.0.0.1:7878 you@your-serverConnect the CLI
Run this command in a second terminal.
ferry login --server http://127.0.0.1:7878The dashboard is at http://127.0.0.1:7878 in your browser.
The other way is the dashboard on a hostname, with HTTPS.