I’m deploying my NodeJS / Docker app to a staging server at the moment, and unlike in development where the web server and Postgres DB were all handled as part of the docker container, i now have a managed DB service that i’m connecting to directly.
My questions are, with the web app firewall settings, do i need to open up any ports for either:
1 - The Docker Remote, currently port 2376 as per the wappler target settings?
2 - The standard Postgres port so the DB and web app can ‘talk’, currently port 5432
Secondly, With the DB managed service, i have added my own IP address so i can directly access the DB etc. But now that i have deployed to a staging server, do i need to add the server IP to the list of allowed IPs for the managed DB?
For the record, I can access the DB and access tables etc in the Wappler DB manager as i’ve connected directly using the supplied details for the managed DB, and also using SSL and the CA cert saved in the project files.
Currently the web app is not able to run any of the APIs as when in the browser, it can’t seem to connect to the DB but can in the Wappler DB manager.
I believe so, though in Wappler 5 you might only need port 22 (SSH) due to the introduction of a SSH connection method instead of "Docker Remote"
No, the web app should be able to perform outbound connections and if the firewall is configured properly, it won't kill established/outbound connections, so it may connect to the managed DB on port 5432 without explicit port whitelisting. Firewalls have the capability to do inbound and outbound filtering, and when we usually open or close ports we're generally talking on inbound connections
The exact answer to this question depends on your provider, if they've performed such whitelist for you or if they're whitelisting by default. If unsure, yes, whitelist your server's IP address.
Wappler UI might use your Internet connection instead of your server's, so it's not a guarantee your server can connect to the DB
Hey @Apple i appreciate your detaileds responses… and the point about Wappler connecting to the DB as i’m doing it from my PC makes perfect sense.
I justed added the Web servers IP address to the whitelist for the managed DB and it worked straight away, so that seems to have been the main bottleneck.
I didn’t add the Docker remote port (2376) to the firewall, so that seems to not effects things in my case.
And, even though i did add open port 5432 in the firewall rules yesterday, it didn’t appear to do anything or perhaps something with Docker is overriding it etc as when i use a port checker tool port 5432 is still closed, maybe that’s how things are supposed to be.
Anyway, whitelisting the web servers IP address was all that was needed and that makes sense when i think about it with a clear head
Correction: With all the changes i was making, i realised that with the firewall active, the Docker Machine couldn’t connect with the server and i couldn’t deploy (re-deploy) to the staging target.
Solution:
I needed to ALLOW port 2376 in the firewall rules (or remove my server from the firewall rules all together) and the machine could then connect.
I’m sure those use to this would have seen this as a no-brainer, but for some of us, this side of the development process is still new