← CloudCédric MerlinFREN

Cloud galaxy Case 5 of 7

No open port, even under a scan

The problem

A startup needs a secure, sovereign infrastructure, with nobody to run it.

The constraint

Two small servers, and no private network provided by the host.

What I did

01

An encrypted private network

I connect the machines with an encrypted private network (NetBird, WireGuard).

02

One entry, outbound

The public arrives through a tunnel that starts from the server and goes out (Cloudflare Tunnel): nothing listens on the internet.

03

Everything closed by default

The firewall denies everything by default. You connect only with a key, and only from the private network.

04

Rebuilt in one command

I describe everything in Ansible: a lost server is rebuilt in one command.

Diagram: from an exposed server to a closed oneAt the start, eight red ports on the server receive attacks from the internet. At the end, all of them are closed: a shield stops the attacks, the public comes in through an outbound tunnel to Cloudflare, a private network connects the second server, and the scan shows 0 open ports.INTERNETCLOUDFLAREoutbound tunnelWireGuardNETWORKSSH by key$ make bootstrapok0 open ports

The result

Under a scan, the application server shows no open port.

0 open ports

on a scan of the application server

Stack

  • Ansible
  • NetBird
  • WireGuard
  • Cloudflare Tunnel
  • nftables
  • Docker
  • restic