Moving this to planned as there is clearly a lot of interest in this feature. We will update once we know where this fits into our development pipeline.
Cezar
•
Sep 29, 2022
Not ufw. This must be in front of the servers, not at the OS level.
This is so critical considering the servers are publicly available on the internet.
If you run docker, you’re completely exposed as docker manages iptables rules to allow container networking to work.
You can place a Palo Alto or a large host with SDN in front of the VMs and manage FW rules from the web interface for each VM using REST.
Arni Johannesson
Team•
Sep 29, 2022
Cezar: Hello Cezar - one thing doesn't exclude the other. We want to allow for easy UFW management in our Dashboard and then probably in the future we would consider DC-level firewalling as an add-on to your server (like most other providers do it)
I will add this as a seperate feature request here shortly.
Arni Johannesson
Team•
Sep 29, 2022
Cezar: I added it just now, here: https://webdockio.canny.io/feature-requests/p/datacenter-level-firewall-option
Arni Johannesson
Team•
Sep 29, 2022
Epsilon PS _ Paul Schiffer: Yes when logged in as admin I get that URL forced upon me - sorry I didn't notice. It's the same page so not a big deal. Thanks for flagging it :)
Arni Johannesson
Team•
Sep 29, 2022
Epsilon PS _ Paul Schiffer: No unfortunately we have exhausted all branding options with Canny - there are more things than what you mention we'd like to be able to do (like, link the header logo back to our main website), but for now this is what we get with Canny.
Arni Johannesson
Team•
Oct 24, 2022
Epsilon PS _ Paul Schiffer: Got it. We are scheduling a call with the folks at Canny soon where I will bring up these details. Thanks.!
Arni Johannesson changed status to In Review
Team•
Sep 28, 2022
We would like to see how many upvotes this feature gets before committing to it.
Beda Schmid
•
Oct 28, 2024
I disagree with this.
1. For some reason at some point WD has enabled a feature (and suggests to use it) that allows removal/hiding of SSH users in the Admin Panel. By my understanding this was done with security in mind as in “if someone unexpected gets into the Admin panel” etc etc 2. Thus, allowing someone to edit UFW in the Admin Panel for me is a showstopper. IMO this should only be edited on the server directly, by an SSH’d user.
For the concern of: > If you run docker, you’re completely exposed as docker manages iptables rules to allow container networking to work.
… please do not use Docker like that if opening ports is a concern.
You can use docker perfectly fine WITHOUT exposing any ports by mapping it to the same network as your proxy server and in it, forward everything to your_container:PORT (or use the localhost IP 127.0.0.1:PORT:PORT in the docker container and proxy to 127.0.0.1:PORT in your proxy server such as caddy)
This should definitely not be an argument for allowing someone to edit UFW (or worse, IPTABLES) in the webdock admin.
Perhaps I misunderstand the request - please correct me if so. However if I understood it correctly, thumbs down - and an immediate follow up request to be able to turn this off, if it gets implemented :)
Epsilon PS _ Paul Schiffer
•
Apr 25
You stated valid concerns, however details are missing.
The reason this was brought up at all is because a datacenter-level firewall large enough to handle all traffic is expensive (money-, process- and planning-wise) and only feasible as a long-term project, if at all.
So the ufw management, for the non-expert users of the vps, would’ve increased security easily by removing the cli hurdle. Yes, in times of AI, the hurdle lessened, but its still there.
A firewall in front of the server is always better, and because the hypervisor in use changed, I believe its now more attainable than 3+ years ago when this feature was first suggested.
The vision for this should for example be the way Hetzner does it with their pure cloud VMs, with the firewall feature. No switch-level ACL dumb stuff like with the dedicated servers.
And on docker combined with ufw:
Sure, if carefully setting the port forwardings, it can be done safe, but many docker users use pre-done docker-compose files or other commands, not built for public VPS with direct public IPs.
And the real question also is, how many Webdock VPS customers actually use docker, only where the docker ufw issue is relevant.
Log in to comment and vote
Comments18
Sep 6, 2023
This is now in progress
Sep 29, 2022
Moving this to planned as there is clearly a lot of interest in this feature. We will update once we know where this fits into our development pipeline.
Cezar
Sep 29, 2022
Not ufw. This must be in front of the servers, not at the OS level. This is so critical considering the servers are publicly available on the internet. If you run docker, you’re completely exposed as docker manages iptables rules to allow container networking to work. You can place a Palo Alto or a large host with SDN in front of the VMs and manage FW rules from the web interface for each VM using REST.
Arni Johannesson
Sep 29, 2022
Cezar: Hello Cezar - one thing doesn't exclude the other. We want to allow for easy UFW management in our Dashboard and then probably in the future we would consider DC-level firewalling as an add-on to your server (like most other providers do it) I will add this as a seperate feature request here shortly.
Arni Johannesson
Sep 29, 2022
Cezar: I added it just now, here: https://webdockio.canny.io/feature-requests/p/datacenter-level-firewall-option
Arni Johannesson
Sep 29, 2022
Epsilon PS _ Paul Schiffer: Yes when logged in as admin I get that URL forced upon me - sorry I didn't notice. It's the same page so not a big deal. Thanks for flagging it :)
Arni Johannesson
Sep 29, 2022
Epsilon PS _ Paul Schiffer: No unfortunately we have exhausted all branding options with Canny - there are more things than what you mention we'd like to be able to do (like, link the header logo back to our main website), but for now this is what we get with Canny.
Arni Johannesson
Oct 24, 2022
Epsilon PS _ Paul Schiffer: Got it. We are scheduling a call with the folks at Canny soon where I will bring up these details. Thanks.!
Sep 28, 2022
We would like to see how many upvotes this feature gets before committing to it.
Beda Schmid
Oct 28, 2024
I disagree with this.
1. For some reason at some point WD has enabled a feature (and suggests to use it) that allows removal/hiding of SSH users in the Admin Panel. By my understanding this was done with security in mind as in “if someone unexpected gets into the Admin panel” etc etc
2. Thus, allowing someone to edit UFW in the Admin Panel for me is a showstopper. IMO this should only be edited on the server directly, by an SSH’d user.
For the concern of:
> If you run docker, you’re completely exposed as docker manages iptables rules to allow container networking to work.
… please do not use Docker like that if opening ports is a concern.
You can use docker perfectly fine WITHOUT exposing any ports by mapping it to the same network as your proxy server and in it, forward everything to
your_container:PORT(or use thelocalhostIP127.0.0.1:PORT:PORTin the docker container and proxy to127.0.0.1:PORTin your proxy server such as caddy)This should definitely not be an argument for allowing someone to edit UFW (or worse, IPTABLES) in the webdock admin.
Perhaps I misunderstand the request - please correct me if so. However if I understood it correctly, thumbs down - and an immediate follow up request to be able to turn this off, if it gets implemented :)
Epsilon PS _ Paul Schiffer
Apr 25
You stated valid concerns, however details are missing.
The reason this was brought up at all is because a datacenter-level firewall large enough to handle all traffic is expensive (money-, process- and planning-wise) and only feasible as a long-term project, if at all.
So the ufw management, for the non-expert users of the vps, would’ve increased security easily by removing the cli hurdle. Yes, in times of AI, the hurdle lessened, but its still there.
A firewall in front of the server is always better, and because the hypervisor in use changed, I believe its now more attainable than 3+ years ago when this feature was first suggested.
The vision for this should for example be the way Hetzner does it with their pure cloud VMs, with the firewall feature. No switch-level ACL dumb stuff like with the dedicated servers.
And on docker combined with ufw:
Sure, if carefully setting the port forwardings, it can be done safe, but many docker users use pre-done docker-compose files or other commands, not built for public VPS with direct public IPs.
And the real question also is, how many Webdock VPS customers actually use docker, only where the docker ufw issue is relevant.