Skip to content

Deployment Overview of Haltdos Community WAF on Server

Prerequisites and Basic Requirements

To ensure a successful deployment, the server must meet the following requirements:

  • Operating System: Ubuntu (specifically required for the installation script).

  • Privileges: Root or sudo access is required to install packages and manage services.

  • Network Ports:

  • Port 80 (HTTP): Used by Certbot for SSL certificate validation and Nginx redirection.

  • Port 443 (HTTPS): The primary port for secure application traffic.

  • Dependencies:

  • curl

  • nginx

  • certbot

FQDN of the final panel on the hostkey.in domain

The application is accessed via a specific Fully Qualified Domain Name (FQDN) generated based on the server ID and prefix.

Parameter Value
Prefix haltdos
Domain hostkey.in
Full template haltdos{Server_ID}.hostkey.in

Application installation process

The application is installed using an official deployment script and a reverse proxy configuration. The following steps are performed during the installation:

  1. System Preparation:

  2. The system hostname is set to the generated FQDN.

  3. The /etc/hosts file is updated to map the local loopback address to the FQDN.

  4. Package Installation: The curl, nginx, and certbot packages are installed via the package manager.

  5. Service Management: Any existing web server services (such as default Nginx or Apache2) are stopped, and any Docker containers occupying ports 80 or 443 are stopped to free up these ports for SSL management.

  6. Application Installation: The Haltdos Community WAF is installed using the official installation script:

    curl -s -k -o setup.sh https://binary.haltdos.com/community/waf/setup.sh
    chmod +x setup.sh
    ./setup.sh
    

  7. SSL Configuration: Certbot is used to obtain a Let's Encrypt SSL certificate for the FQDN using the --standalone method.

Access Rights and Security

  • Firewall/Ports: The system relies on Nginx acting as a reverse proxy, listening on port 443 (HTTPS) and redirecting all traffic from port 80 (HTTP) to HTTPS.

  • SSL Protocols: The configuration enforces TLSv1.2 and TLSv1.3.

  • Nginx Security: A custom Nginx configuration is created at /etc/nginx/sites-available/haltdos.conf which includes security headers such as X-Real-IP, X-Forwarded-For, and X-Forwarded-Proto.

Docker Containers and Their Deployment

The deployment utilizes a specialized container to manage SSL certificates via Nginx and Certbot.

Nginx-Certbot Container

  • Image: jonasal/nginx-certbot:latest

  • Network Mode: host

  • Restart Policy: unless-stopped

  • Volumes:

  • nginx_secrets:/etc/letsencrypt (Shared volume for SSL certificates)

  • /data/nginx/user_conf.d:/etc/nginx/user_conf.d (Configuration directory)

  • Environment Variables:

  • [email protected]

Custom Scripts and Additional Setup

The deployment performs several environment setup actions:

  • Hostname Configuration: The server's internal hostname is modified to match the application's FQDN.

  • Nginx Reverse Proxy Setup: A configuration file is generated at /etc/nginx/sites-available/haltdos.conf to proxy traffic from port 443 to the application running locally on port 9000.

Application Update Instructions

To update the main application, you must re-run the official installation script:

cd /root
curl -s -k -o setup.sh https://binary.haltdos.com/community/waf/setup.sh
chmod +x setup.sh
./setup.sh

Location of configuration files and data

  • Nginx Site Configuration: /etc/nginx/sites-available/haltdos.conf

  • Nginx Enabled Configuration: /etc/nginx/sites-enabled/haltdos.conf

  • SSL Certificates: /etc/letsencrypt/live/{FQDN}/

  • Docker Nginx Configs: /data/nginx/user_conf.d

Available ports for connection

Port Protocol Description
80 HTTP Redirected to HTTPS
443 HTTPS Secure application access (via Nginx Proxy)
9000 HTTPS Internal application port

Starting and Stopping the application

The application is managed through the system's service manager via Nginx:

  • Start Nginx: systemctl start nginx

  • Stop Nginx: systemctl stop nginx

  • Restart Nginx: systemctl restart nginx

question_mark
Is there anything I can help you with?
question_mark
AI Assistant ×