Security

What the host publishes

WhatWhere it is reachable
The Installer's screens and APIPort 8000, on every host interface, over HTTP. Put HTTPS in front as TLS and certificates describes
The Installer's database containerNot published. Reachable from the Installer's containers only
The Installer on the shared Docker networkThe Installer's backend container, port 8000, for DataMind OS
DataMind OSThe ports its own Compose file publishes. See System requirements

Roles are on Users. Secret files and what each protects are on What lives on the host.

Good practice for administrators

Restrict the port

Docker routes published ports through its own nat rules, ahead of ufw and firewalld INPUT rules. Filter the port in the DOCKER-USER chain. Insert two rules: drop traffic to the port, then allow your administration network above it. Replace 203.0.113.0/24 with your administrators' subnet and eth0 with the host's external interface.

bash
sudo iptables -I DOCKER-USER -i eth0 -p tcp -m conntrack --ctorigdstport 8000 --ctdir ORIGINAL -j DROP
sudo iptables -I DOCKER-USER -i eth0 -p tcp -m conntrack --ctorigdstport 8000 --ctdir ORIGINAL -s 203.0.113.0/24 -j ACCEPT

Match with --ctorigdstport, not --dport: Docker has already rewritten the destination when the packet reaches DOCKER-USER. Save the rules with your distribution's iptables tooling so they survive a reboot. On a host with IPv6 enabled, add the same rules with ip6tables.

Check it worked. From a machine outside the allowed subnet:

bash
curl -sS --max-time 5 http://<host>:8000/api/health

The request times out. From an allowed machine it returns {"status":"ok","db":"up"}.

Protect the deployment's environment file

deployment/.env holds every value DataMind OS runs with, including CURATO_SERVICE_TOKEN. Make it readable by root only:

bash
sudo chown root:root /opt/delamain/deployment/.env
sudo chmod 600 /opt/delamain/deployment/.env

The Installer runs as root, so it still reads and rewrites the file, and a rewrite keeps the mode. Run the two commands again after you restore or recreate the file.

Check it worked.

bash
stat -c '%a %U' /opt/delamain/deployment/.env
text
600 root

Questions, answered

Why does our ufw rule not block port 8000?

Docker routes published ports before ufw sees them. Add the rule to the DOCKER-USER chain, as Restrict the port shows.

Where do Installer accounts live?

In the Installer's own database. Admins manage them on Users.