GuidesProduction setup
Apps and servers
Keep the limits on, give each server its own prefix, and know what Ferry does not protect.
The checklist
- Keep the limits on. A limit of
0turns its guard off. Size the limits for the host. KeepOOMScoreAdjust=in the unit. Then the kernel stops a container beforeferrydwhen the server runs out of memory. - Give each server its own data directory and name prefix. Ferry refuses to start on a prefix that another data directory owns. Do not override that with
--take-over. See Multiple servers. - Trust the forwarded headers. The proxy drops the
X-Forwarded-*,ForwardedandX-Real-IPheaders that a client sends. It setsX-Forwarded-Forto the address that connects, and no more. Thus your apps can use them. See Networking.
What Ferry does not do
| Subject | Limit |
|---|---|
| Accounts | One administrator account. No other users and no roles. |
| API tokens | Each token has full access. No IP allow lists. |
| Deploys | Each person who can deploy can run any code on the server. |
| Resources | Containers have memory, CPU and process limits. Builds have none, and disks have no quotas. |
| Network | Each container can reach each service and datastore on the private network. |
See the security model.
A data directory that you moved keeps its instance_id. It needs no flag. --take-over is only for a data directory that lost its instance_id.