FerryDocs

Apps and servers

Keep the limits on, give each server its own prefix, and know what Ferry does not protect.

Edit on GitHub
Private networkApp AApp BPostgres
Each container can reach each service and datastore on the private network

The checklist

  • Keep the limits on. A limit of 0 turns its guard off. Size the limits for the host. Keep OOMScoreAdjust= in the unit. Then the kernel stops a container before ferryd when the server runs out of memory.
  • Give each server its own data directory and . Ferry refuses to start on a prefix that another data directory owns. Do not override that with --take-over. See Multiple servers.
  • Trust the forwarded headers. The proxy drops the X-Forwarded-*, Forwarded and X-Real-IP headers that a client sends. It sets X-Forwarded-For to the address that connects, and no more. Thus your apps can use them. See Networking.

What Ferry does not do

SubjectLimit
AccountsOne administrator account. No other users and no roles.
API tokensEach token has full access. No IP allow lists.
DeploysEach person who can deploy can run any code on the server.
ResourcesContainers have memory, CPU and process limits. Builds have none, and disks have no quotas.
NetworkEach container can reach each service and datastore on the .

See the security model.

On this page