Hardening checklist
Use layered controls. Configure them through the UI or Docker labels according to resource ownership; both paths are first-class and produce the same Edge behavior.
Public exposure
- Expose only Edge on the intended HTTP and HTTPS ports.
- Keep application containers private on
clearplane-serviceswithout host port mappings. - Keep Core, UI, ContainerProxy, and
/internal/*private. - Do not attach control-plane containers to additional application or public networks.
- Restrict host, Docker daemon, and deployment access to trusted administrators.
Management access
- Limit the management routes to trusted source addresses or countries with access control.
- Apply a rate limit policy to slow repeated requests before they exhaust application capacity.
- Enable automatic bans for repeated violations and abusive 4xx behavior.
- Use strong administrator credentials and grant only the permissions each operator needs.
Automatic bans complement access control and rate limiting. They react to observed behavior and apply a temporary IP ban across Clearplane; they are not a substitute for fixing an exposed application or leaked credential.
Published services
- Enable HTTPS and redirect HTTP only after the certificate is active.
- Assign access control and rate limit policies based on the service's audience and capacity.
- Configure auto-ban thresholds from observed normal traffic, then review security events for false positives.
- Apply response headers policies that match the application, including transport, framing, content-type, referrer, permissions, and server-header controls.
- Keep upstream applications authenticated, patched, and private even when Edge supplies the public route.
Use Configure access, traffic, and delivery for equal UI and Docker-label workflows, Ban abusive clients automatically for behavior-based protection, and Reference for exact settings.
Change safely
- Start route-scoped when testing a new policy. For policy families that support global scope, move to global only when the same behavior belongs on every unassigned route.
- Verify the effective source, apply state, and loaded configuration revision after a change.
- Test allowed traffic, blocked traffic, and upstream failure behavior—not only a successful save.
- Keep recovery material and operational data protected using your host platform's backup and access-control procedures.