Hey there, thanks for Kamal as an amazing tool. I was wondering how the community here keeps their servers secure.
- What tools do you use? Do you invoke custom
.sh scripts via Kamal? Do you use software like ansible? Do they work nicely together?
- Are there any best practices on server hardening, especially thought in conjunction with a Rails app that uses Kamal to deploy their Docker Containers?
I'm asking beyond using Docker Hardened Images, e.g. how to set up firewall rules, ip tables, ssh access, keeping apt dependencies up-to-date. Of course, this is individual per project, but I'm sure there are some common defaults one could build upon. Just wondering what the take from the Kamal community on server security is, thanks for any pointers.
Hey there, thanks for Kamal as an amazing tool. I was wondering how the community here keeps their servers secure.
.shscripts via Kamal? Do you use software like ansible? Do they work nicely together?I'm asking beyond using Docker Hardened Images, e.g. how to set up firewall rules, ip tables, ssh access, keeping
aptdependencies up-to-date. Of course, this is individual per project, but I'm sure there are some common defaults one could build upon. Just wondering what the take from the Kamal community on server security is, thanks for any pointers.