GuidesProduction setup
Security checklist
Keep the API private, create the account early, protect the data directory and open only three ports.
Access to the server
- Keep the API private. Leave
--api-addron127.0.0.1and use an SSH tunnel. Or expose it only through--dashboard-hostwith HTTPS. - Create the account immediately after the first start. Until it exists, each person who can read the setup link can create it. The link is in the server log and in
<data-dir>/setup_code. - Protect the data directory. It holds the values of variables, the passwords of datastores and the credentials in repository URLs. Limit who can log in as the user
ferry. - Open only ports 22, 80 and 443. Ferry binds the datastore ports to
127.0.0.1, thus they are never public. Reach them over SSH.
Treat the password and the tokens like root passwords
The password of the account and each API token give full control of each app on the server.
Next: tokens and secrets, then apps and servers.
Ferry creates the data directory with file mode 0700. It creates api_token, setup_code and instance_id with mode 0600. Keep these modes.
Ferry limits the failed sign-ins for the full server, not for each address. Thus a person who can reach the API can also delay your own sign-in.