I am now actually so far with my NS 8 installation that I can send my beloved NS 7 into well-deserved retirement.
However, it is giving me a headache that the administration page of NS 8 is also accessible via the Internet when I open port 80 or 443. With NS 7, access was regulated via port 980 or port 9090 (Cockpit). Is there a similar option for NS 8 without having to make major changes to the existing infrastructure?
I did this also with several .yml files, e.g. in mariadb1.yml to restrict access to /phpmyadmin.
It works. Thanks for that.
Is this surviving updates ?
Apparently the last core update overwrites the _api_server.yml file again. You simply have to reset the entry - MwTrustedNetworks. Unattractive, but doable.
after the current core update, the settings in _api_server.yml file are no longer overwritten. It is no longer necessary to make a subsequent correction.
@davidep is there any way to make this change persistent or even configurable in the UI?
It is not very favorable to have to re-check this with every core update, probability is much too high that it gets forgotten and opens up the access silently again.
It’s 2025, March 21
New Installation NS8 on March 19, Rocky 9.5 + Core Update (traefik 3.3.4)
On March 19 or 20 there was an update to traefik 3.3.4,
now configs/_api_server.yml does not exist.
Where should I add “- MwTrustedNetworks” now?
I searched for ‘ApiServer-https’ but did just get: