01
An encrypted private network
I connect the machines with an encrypted private network (NetBird, WireGuard).
Cloud galaxy Case 5 of 7
The problem
The constraint
What I did
01
I connect the machines with an encrypted private network (NetBird, WireGuard).
02
The public arrives through a tunnel that starts from the server and goes out (Cloudflare Tunnel): nothing listens on the internet.
03
The firewall denies everything by default. You connect only with a key, and only from the private network.
04
I describe everything in Ansible: a lost server is rebuilt in one command.
The result
Under a scan, the application server shows no open port.
0 open ports
on a scan of the application server
Stack