TL;DR UFW
UFW is configured on every CloudSonic server allowing only ports 80, 443, and 2222, with all other inbound traffic blocked at the firewall level from day one.
UFW is a user-friendly frontend for iptables that manages firewall rules on every CloudSonic server, configured from provisioning to allow only ports 80, 443, and 2222 with all other inbound traffic blocked. CrowdSec and Fail2ban write dynamic block rules directly to iptables as threats are detected, while all monitoring ports for Prometheus exporters are bound to the Tailscale interface and never exposed through UFW. UFW sits alongside AppArmor, CrowdSec, and Fail2ban as one of four independent security layers active on every CloudSonic server.
UFW for Firewall Management on CloudSonic
UFW on CloudSonic is configured during provisioning to allow only ports 80, 443, and 2222 with all other inbound traffic blocked by default. CrowdSec and Fail2ban write dynamic block rules directly to iptables as threats are detected, working independently of UFW's static rules so malicious IP addresses are banned in real time without requiring UFW rule changes. All monitoring ports for Prometheus exporters are bound to the Tailscale interface rather than the public interface, so they are never exposed through UFW regardless of firewall configuration.
Useful Commands
sudo ufw status verbose