Skip to content

Firewall and private networks

Falak manages a firewall on every server with nftables, and can join servers into WireGuard private networks so they talk over encrypted private addresses.

The policy is drop everything inbound, then allow what the rules say:

  • Established connections and ICMP are accepted.
  • Rules for private networks come first, then your deny rules, then your allow rules, each in order.
  • The SSH port is always accepted by the agent, so you cannot lock yourself out.

Seeded when a server finishes provisioning:

Rule Protocol Port Servers
SSH TCP 22 all
HTTP TCP 80 app, web, lb
HTTPS TCP 443 app, web, lb

The firewall tab of a server: the default SSH, HTTP and HTTPS allow rules and a form to add rules.

  1. Open the server page → Firewall.

  2. Click Add rule and fill in:

    Field Allowed values
    Name Up to 120 characters
    Action allow or deny
    Protocol tcp, udp or any
    Port A port (1–65535) or a range like 8000-8100; empty = all ports
    Source An IPv4/IPv6 address or CIDR like 203.0.113.0/24; empty = anywhere
  3. Save. The full rule set is sent to the agent (net.firewall.apply) and applied atomically.

Example: let an app server reach PostgreSQL on a database server:

Server Name Action Protocol Port Source
db-1 Postgres from app-1 allow tcp 5432 10.90.0.2/32 (app-1’s private address)

Managing rules needs network.manage. Failures raise the Firewall apply failed alert (network.firewall_failed); Firewall applied again (network.firewall_recovered) follows the first success after that.

A private network connects servers over WireGuard. Falak generates the keys, assigns addresses and keeps every member’s configuration in sync.

  1. Open Network → Private networks and click New network.
  2. Enter a name. Optionally change the address range (default 10.90.0.0/24, FALAK_PRIVATE_NETWORK_CIDR) and the listen port (default 51820, FALAK_WIREGUARD_PORT; 1024–65535).
  3. Add servers. Each gets an address in the range; persistent keepalive is 25 seconds.

Falak installs wireguard-tools on a member on demand, the first time it joins a private network (since v0.7.1; fresh servers without it never brought their private networks up before). Servers outside private networks don’t get it.

What uses the private network:

  • Database references: DB_HOST resolves to a dedicated database server’s private-network address first.
  • Redis and Valkey references from sites on other servers of the environment (see Redis and Valkey ports).
  • Load balancers proxy to backends over the private network.

Falak adds the rules a private network needs to each member’s firewall automatically, before your own deny rules, so a deny rule never cuts the mesh. If your cloud provider filters traffic, open the WireGuard UDP port between members there.

Some providers put servers of one account and region on a private network of their own. Where Falak can be sure two servers share one, it uses it as a fallback when they share no Falak private network:

  • DigitalOcean and Lightsail only: both servers created by Falak with the same provider credential, in the same region.
  • Not Hetzner, Vultr or Linode — their private networks are opt-in, and Falak doesn’t track membership — and never custom servers. Put those in a Falak private network.

Redis and Valkey references use this order: a Falak private network first, then the provider private network, and never the public address.

A Redis or Valkey instance gets its own port (6380–6479). Falak opens that port only as far as its consumers need, on agents with db.redis.network (v0.7.1):

  • Containers on the same server: the port is accepted from the Docker address ranges arriving on the Docker bridges (docker0, br-*) — not on the public interface.
  • Other servers of the environment: the port is accepted from exactly those servers’ private addresses, on the interface they arrive on (the Falak private network’s WireGuard interface, or the provider’s private interface). Other members of the same private network are still dropped: these rules come before the private network’s own accept rule.
  • Everyone else: dropped. No rule opens an instance’s port publicly, and the instance never listens on a public address.

You don’t add these rules yourself; Falak converges them when sites, servers or private networks change.

  • WireGuard private networks are covered by unit and feature tests, not yet by the end-to-end suite.
  • The firewall manages inbound rules only.