| What | Where it is reachable |
|---|---|
| The Installer's screens and API | Port 8000, on every host interface, over HTTP. Put HTTPS in front as TLS and certificates describes |
| The Installer's database container | Not published. Reachable from the Installer's containers only |
| The Installer on the shared Docker network | The Installer's backend container, port 8000, for DataMind OS |
| DataMind OS | The ports its own Compose file publishes. See System requirements |
Roles are on Users. Secret files and what each protects are on What lives on the host.
Docker routes published ports through its own nat rules, ahead of ufw and firewalld INPUT rules.
Filter the port in the DOCKER-USER chain. Insert two rules: drop traffic to the port, then allow
your administration network above it. Replace 203. with your administrators' subnet and
eth0 with the host's external interface.
sudo iptables -I DOCKER-USER -i eth0 -p tcp -m conntrack --ctorigdstport 8000 --ctdir ORIGINAL -j DROP sudo iptables -I DOCKER-USER -i eth0 -p tcp -m conntrack --ctorigdstport 8000 --ctdir ORIGINAL -s 203.0.113.0/24 -j ACCEPT
Match with --ctorigdstport, not --dport: Docker has already rewritten the destination when the
packet reaches DOCKER-USER. Save the rules with your distribution's iptables tooling so they survive
a reboot. On a host with IPv6 enabled, add the same rules with ip6tables.
Check it worked. From a machine outside the allowed subnet:
curl -sS --max-time 5 http://<host>:8000/api/health
The request times out. From an allowed machine it returns {"status":"ok","db":"up"}.
deployment/ holds every value DataMind OS runs with, including CURATO_SERVICE_TOKEN. Make it
readable by root only:
sudo chown root:root /opt/delamain/deployment/.env sudo chmod 600 /opt/delamain/deployment/.env
The Installer runs as root, so it still reads and rewrites the file, and a rewrite keeps the mode. Run the two commands again after you restore or recreate the file.
Check it worked.
stat -c '%a %U' /opt/delamain/deployment/.env
600 root
Docker routes published ports before ufw sees them. Add the rule to the DOCKER-USER chain, as
Restrict the port shows.
In the Installer's own database. Admins manage them on Users.