Features Stacks Solutions Pricing About Contact
Sign in →
Docs / Rootless Containers & Firewall Management
Security & Networking

Rootless Containers & Firewall Management

How Rubuz protects host operating systems and limits lateral movement.

Security is the core reason Rubuz was created. Most VPS panels run privileged daemons that leave your infrastructure vulnerable if an application is compromised.

Rootless Container Execution

In Rubuz:

  1. Applications run under unprivileged user namespaces (UID 10000+).
  2. The root user inside your container cannot access host filesystem nodes or kernel system calls.
  3. If an attacker uploads malicious PHP code or an unpatched vulnerability is exploited, the intruder remains trapped within the temporary container filesystem.

Automated Firewall (nftables)

Rubuz provisions minimal firewall policies:

  • Only necessary ports (80, 443, and SSH) are exposed to public interfaces.
  • Internal databases (MySQL, Redis, PostgreSQL) listen strictly on private loopback interfaces or virtual bridge networks (10.88.0.0/16).
  • Automatic brute-force prevention blocks repeating failed SSH and login requests using rate-limiting tables.

Security Best Practices

  • Always use clean, dedicated VPS instances for production environments.
  • Enable two-factor authentication (2FA) on your Rubuz account.
  • Store sensitive API tokens and database credentials in Rubuz encrypted environment variable vaults.
Still have questions?
Can't find what you need in the docs? Our engineers are ready to help.
Contact Support