FerryDocs

Security checklist

Keep the API private, create the account early, protect the data directory and open only three ports.

Edit on GitHub
InternetPorts 80, 443your appsPort 22SSH, for youAPI127.0.0.1 onlyDatastores127.0.0.1 only
The internet reaches three ports. The rest stays private.

Access to the server

  • Keep the API private. Leave --api-addr on 127.0.0.1 and use an . Or expose it only through --dashboard-host with HTTPS.
  • Create the account immediately after the first start. Until it exists, each person who can read the setup link can create it. The link is in the server log and in <data-dir>/setup_code.
  • Protect the . It holds the values of variables, the passwords of datastores and the credentials in repository URLs. Limit who can log in as the user ferry.
  • Open only ports 22, 80 and 443. Ferry binds the datastore ports to 127.0.0.1, thus they are never public. Reach them over .

Treat the password and the tokens like root passwords

The password of the account and each give full control of each app on the server.

Next: tokens and secrets, then apps and servers.

On this page