Skip to content

Server Hardening Best Practices #1856

Description

@Splines

Hey there, thanks for Kamal as an amazing tool. I was wondering how the community here keeps their servers secure.

  • What tools do you use? Do you invoke custom .sh scripts via Kamal? Do you use software like ansible? Do they work nicely together?
  • Are there any best practices on server hardening, especially thought in conjunction with a Rails app that uses Kamal to deploy their Docker Containers?

I'm asking beyond using Docker Hardened Images, e.g. how to set up firewall rules, ip tables, ssh access, keeping apt dependencies up-to-date. Of course, this is individual per project, but I'm sure there are some common defaults one could build upon. Just wondering what the take from the Kamal community on server security is, thanks for any pointers.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions