Hardening checklist

Use layered controls. Configure them through the UI or Docker labels according to resource ownership; both paths are first-class and produce the same Edge behavior.

Public exposure

  • Expose only Edge on the intended HTTP and HTTPS ports.
  • Keep application containers private on clearplane-services without host port mappings.
  • Keep Core, UI, ContainerProxy, and /internal/* private.
  • Do not attach control-plane containers to additional application or public networks.
  • Restrict host, Docker daemon, and deployment access to trusted administrators.

Management access

  • Limit the management routes to trusted source addresses or countries with access control.
  • Apply a rate limit policy to slow repeated requests before they exhaust application capacity.
  • Enable automatic bans for repeated violations and abusive 4xx behavior.
  • Use strong administrator credentials and grant only the permissions each operator needs.

Automatic bans complement access control and rate limiting. They react to observed behavior and apply a temporary IP ban across Clearplane; they are not a substitute for fixing an exposed application or leaked credential.

Published services

  • Enable HTTPS and redirect HTTP only after the certificate is active.
  • Assign access control and rate limit policies based on the service's audience and capacity.
  • Configure auto-ban thresholds from observed normal traffic, then review security events for false positives.
  • Apply response headers policies that match the application, including transport, framing, content-type, referrer, permissions, and server-header controls.
  • Keep upstream applications authenticated, patched, and private even when Edge supplies the public route.

Use Configure access, traffic, and delivery for equal UI and Docker-label workflows, Ban abusive clients automatically for behavior-based protection, and Reference for exact settings.

Change safely

  • Start route-scoped when testing a new policy. For policy families that support global scope, move to global only when the same behavior belongs on every unassigned route.
  • Verify the effective source, apply state, and loaded configuration revision after a change.
  • Test allowed traffic, blocked traffic, and upstream failure behavior—not only a successful save.
  • Keep recovery material and operational data protected using your host platform's backup and access-control procedures.