Deployment Overview of Haltdos Community WAF on Server¶
Prerequisites and Basic Requirements¶
To ensure a successful deployment, the server must meet the following requirements:
-
Operating System: Ubuntu (specifically required for the installation script).
-
Privileges: Root or sudo access is required to install packages and manage services.
-
Network Ports:
-
Port
80(HTTP): Used by Certbot for SSL certificate validation and Nginx redirection. -
Port
443(HTTPS): The primary port for secure application traffic. -
Dependencies:
-
curl -
nginx -
certbot
FQDN of the final panel on the hostkey.in domain¶
The application is accessed via a specific Fully Qualified Domain Name (FQDN) generated based on the server ID and prefix.
| Parameter | Value |
|---|---|
| Prefix | haltdos |
| Domain | hostkey.in |
| Full template | haltdos{Server_ID}.hostkey.in |
Application installation process¶
The application is installed using an official deployment script and a reverse proxy configuration. The following steps are performed during the installation:
-
System Preparation:
-
The system hostname is set to the generated FQDN.
-
The
/etc/hostsfile is updated to map the local loopback address to the FQDN. -
Package Installation: The
curl,nginx, andcertbotpackages are installed via the package manager. -
Service Management: Any existing web server services (such as default Nginx or Apache2) are stopped, and any Docker containers occupying ports 80 or 443 are stopped to free up these ports for SSL management.
-
Application Installation: The Haltdos Community WAF is installed using the official installation script:
-
SSL Configuration: Certbot is used to obtain a Let's Encrypt SSL certificate for the FQDN using the
--standalonemethod.
Access Rights and Security¶
-
Firewall/Ports: The system relies on Nginx acting as a reverse proxy, listening on port 443 (HTTPS) and redirecting all traffic from port 80 (HTTP) to HTTPS.
-
SSL Protocols: The configuration enforces
TLSv1.2andTLSv1.3. -
Nginx Security: A custom Nginx configuration is created at
/etc/nginx/sites-available/haltdos.confwhich includes security headers such asX-Real-IP,X-Forwarded-For, andX-Forwarded-Proto.
Docker Containers and Their Deployment¶
The deployment utilizes a specialized container to manage SSL certificates via Nginx and Certbot.
Nginx-Certbot Container
-
Image:
jonasal/nginx-certbot:latest -
Network Mode:
host -
Restart Policy:
unless-stopped -
Volumes:
-
nginx_secrets:/etc/letsencrypt(Shared volume for SSL certificates) -
/data/nginx/user_conf.d:/etc/nginx/user_conf.d(Configuration directory) -
Environment Variables:
Custom Scripts and Additional Setup¶
The deployment performs several environment setup actions:
-
Hostname Configuration: The server's internal hostname is modified to match the application's FQDN.
-
Nginx Reverse Proxy Setup: A configuration file is generated at
/etc/nginx/sites-available/haltdos.confto proxy traffic from port 443 to the application running locally on port9000.
Application Update Instructions¶
To update the main application, you must re-run the official installation script:
cd /root
curl -s -k -o setup.sh https://binary.haltdos.com/community/waf/setup.sh
chmod +x setup.sh
./setup.sh
Location of configuration files and data¶
-
Nginx Site Configuration:
/etc/nginx/sites-available/haltdos.conf -
Nginx Enabled Configuration:
/etc/nginx/sites-enabled/haltdos.conf -
SSL Certificates:
/etc/letsencrypt/live/{FQDN}/ -
Docker Nginx Configs:
/data/nginx/user_conf.d
Available ports for connection¶
| Port | Protocol | Description |
|---|---|---|
| 80 | HTTP | Redirected to HTTPS |
| 443 | HTTPS | Secure application access (via Nginx Proxy) |
| 9000 | HTTPS | Internal application port |
Starting and Stopping the application¶
The application is managed through the system's service manager via Nginx:
-
Start Nginx:
systemctl start nginx -
Stop Nginx:
systemctl stop nginx -
Restart Nginx:
systemctl restart nginx