Concepts
Firewalls
Stateful rules for inbound and outbound traffic, applied to servers directly or by label.
A firewall is a set of rules that you apply to servers. Firewalls are stateful: replies to allowed connections are always let through.
A server without a firewall accepts all inbound traffic. Apply a firewall to every server that does not need to be fully open.
How rules work
- Inbound (
direction: in): everything is blocked except what a rule allows. - Outbound (
direction: out): if the firewall has no outbound rules, all outbound traffic is allowed. As soon as it has one, only what the outbound rules allow is let out. - If several firewalls apply to a server, the server gets the rules of all of them combined. Because rules only ever allow traffic, a firewall without outbound rules lets all outbound traffic out, even if another firewall on the same server has outbound rules.
Each rule has:
| Field | Values |
|---|---|
direction | in or out |
protocol | tcp, udp, icmp, esp or gre |
port | For tcp and udp only, and required there: a port ("443") or a range ("1000-2000") |
source_ips | Inbound rules: the CIDRs allowed to connect, e.g. 0.0.0.0/0 and ::/0 for everyone |
destination_ips | Outbound rules: the CIDRs the server may connect to |
description | Optional text |
A firewall can have up to 50 rules. Setting the rules replaces the whole list.
[
{ "direction": "in", "protocol": "tcp", "port": "22", "source_ips": ["198.51.100.0/24"], "description": "SSH from the office" },
{ "direction": "in", "protocol": "tcp", "port": "443", "source_ips": ["0.0.0.0/0", "::/0"] },
{ "direction": "in", "protocol": "icmp", "source_ips": ["0.0.0.0/0", "::/0"] }
]odx firewall create --name web --rules-file rules.json
odx firewall add-rule --direction in --protocol tcp --port 80 --source-ips 0.0.0.0/0,::/0 webApplying a firewall
A firewall is applied to resources in one of two ways (apply_to_resources):
server: one specific server.label_selector: every server in the project whose labels match the selector, for examplerole=web. Servers you create, relabel or delete later are picked up automatically; the firewall'sapplied_to_serversshows which servers currently match.
odx firewall apply-to-resource --type label_selector --label-selector role=web web
odx firewall apply-to-resource --type server --server db-1 webYou can also pass up to five firewalls when creating a server, so it is protected from its first boot.
A firewall that is still applied to resources has to be removed from them before you can delete it.