Features StacksPricing About Contact
Sign in →
04 // Core Architecture • Hardened Security

Hardened by default. Zero leaks.

Defense in-depth engineered into the foundation. From rootless Podman user namespaces that prevent container breakouts, to automated host firewalls, Let's Encrypt wildcard TLS, and Argon2id cryptographic password hashing—your infrastructure is fortified from the moment you connect.

Rootless User Namespaces Strict UFW Port Lockdown Argon2id Secret Vaulting Auto-Renewing Wildcard TLS
security-posture // srv-fra1.rubuz.host • CIS Benchmark Grade: A+
Host Hardening: 100/100 (0 Root Daemons)
Layer 01 // Perimeter 🛡️
UFW Port Shield

Only ports 22, 80, and 443 are reachable. Internal databases (5432, 6379, 3306) are never bound to public IPs.

✓ 0 Publicly Leaked Ports
Layer 02 // Transport 🔒
Automated Wildcard TLS

Zero-touch Let's Encrypt certificates. HTTP/3 and TLS 1.3 enforced with automated ACME certificate rotation.

✓ TLS 1.3 Strict HSTS
Layer 03 // Isolation 📦
Rootless Podman Sandboxing

Root inside the container maps to unprivileged UID 100042 outside. Breakouts cannot inherit host root privileges.

✓ Jailbreak Proof UID Map
Layer 04 // Secrets 🔑
Argon2id Secrets Vault

Memory-hard Argon2id password hashing and encrypted environment keys with zero plaintext logs or storage.

✓ Constant-Time Verification
Live Security Audit & Kernel Guard Logs
0 Vulnerabilities Detected
14:02:18 ✓
UFW Audit: Verified default policy DROP. Public exposure checked: Ports 22, 80, 443 only. All other incoming packets silently rejected.
14:02:19 ✓
Namespace Sandbox Check: Verified subuid allocation (100000:65536). Container processes running with unprivileged capabilities only (CAP_NET_BIND_SERVICE dropped).
14:02:20 ✓
TLS Certificate Inspector: Let's Encrypt wildcard certificate for *.rubuz.cloud verified. Expiry in 89 days. Auto-renewal scheduled at day 60.
14:02:21 ✓
Daemonless Architecture: Scanned system process table. Zero persistent management daemons executing as root. Control plane strictly communicates over temporary authenticated SSH sessions.
01 // Architectural Comparison

Why traditional Docker panels are vulnerable. And how Rubuz eliminates the risk.

Most hosting panels run Docker as full root (`dockerd`). If an attacker finds a remote code execution bug in one PHP or Node app, they break out and gain root control of your entire server.

✕ Traditional Root Docker Daemons

The Insecure Legacy Approach

  • ✕
    Root Daemon Escape Risk: Containers run under the root `dockerd` daemon. An escape exploit grants immediate root access to the entire host machine.
  • ✕
    Silent Firewall Bypass: Docker manipulates iptables directly, frequently bypassing your UFW firewall rules and silently publishing raw database ports to the open internet.
  • ✕
    Cross-Container Snooping: Shared unsegmented Docker bridges permit any compromised container on the host to scan and attack other neighboring applications.
  • ✕
    Weak Password Hashing & Plaintext Secrets: Panels frequently store credentials with legacy MD5/SHA256 or store unencrypted database passwords in plain text on disk.
Rubuz Engineering Standard
✓ Rubuz Rootless Podman Architecture

Hardened Defense-In-Depth

  • ✓
    Rootless User Namespaces: Containers have zero root privileges on the host. An attacker who breaks out finds themselves trapped as an unprivileged UID with zero system access.
  • ✓
    Strict UFW Respect (Zero Silent Leaks): Podman never overrides your firewall. Database ports (5432, 6379, 3306) bind strictly to container bridges, completely invisible to the outside web.
  • ✓
    Isolated Per-App Virtual Networks: Each application stack runs in an isolated network sandbox. A breach in one app cannot access databases or microservices in another stack.
  • ✓
    Argon2id Memory-Hard Cryptography: All password hashes and encryption keys use industry-standard Argon2id, immune to modern GPU and ASIC cracking attacks.
02 // The Four Pillars

Engineered for airtight resilience.

Security isn't a checkbox or an add-on plugin. It is the fundamental architecture on which every container, database, and route is built.

Pillar 01

Rootless Podman User Namespaces

Even if a vulnerability is discovered in an application like WordPress or Next.js, the attacker cannot compromise your server. Rubuz maps root inside the container to an unprivileged subuid on the host.

Containment Guarantees:
• Zero root daemon (`dockerd`) running on host
• Host files and kernel configurations completely unreachable
• Immune to container-to-host privilege escalation exploits
Pillar 02

Automated Host Firewall (UFW) Lockdown

When you connect a VPS to Rubuz, host firewall rules are configured automatically. Only ports 22 (SSH), 80 (HTTP), and 443 (HTTPS) are permitted. All backend databases are strictly walled off.

Firewall Principles:
• Default incoming policy set strictly to DROP
• PostgreSQL (5432) and Redis (6379) bound only to internal bridges
• Zero docker iptables bypass vulnerabilities
Pillar 03

Automated Let's Encrypt Wildcard TLS

Every application and subdomain deployed via Rubuz is automatically protected with modern TLS 1.3 certificates. Automated renewals execute seamlessly 30 days before expiration with zero manual intervention.

Cryptographic Standards:
• Elliptic curve cryptography (ECDSA P-256 / X25519)
• Strict HTTP Strict Transport Security (HSTS) preloading
• Zero downtime during certificate rollover
Pillar 04

Argon2id Hashing & Ephemeral Sessions

Rubuz employs Argon2id—the winner of the Password Hashing Competition—configured with high memory cost parameters. Control panel authentication utilizes cryptographically signed, short-lived session tokens.

Secret Protections:
• Environment variables encrypted at rest with AES-256-GCM
• Constant-time comparison prevents timing attacks
• Sensitive credentials never echoed in server deployment logs
04 // Frequently Asked Questions

Everything you need to know about Rubuz Security.

What is rootless Podman and why is it safer than traditional Docker? ↓

In traditional Docker setups, the container daemon runs as the host `root` user (`dockerd`). If a containerized app is compromised and an attacker finds a container escape vulnerability, they immediately inherit full root privileges on the physical host. Podman runs containers inside unprivileged user namespaces. Root inside the container is actually an unprivileged UID on the host, meaning container escapes hit an impenetrable security wall with zero root access.

Can an attacker breach my server and read other applications' databases? ↓

No. Rubuz isolates every application stack into its own private virtual container network bridge. Databases like PostgreSQL and Redis communicate exclusively over internal network namespaces that are unreachable by other apps and completely unexposed to the public internet.

Does Rubuz leave open ports or background daemons running on my server? ↓

Zero. Unlike legacy hosting panels that install web servers, PHP daemons, and database managers running directly on the host, Rubuz connects to your server strictly via encrypted SSH. There are no proprietary daemons, no background listeners, and no extra ports opened on your firewall.

How are SSL certificates managed and will my site ever go offline due to expired certs? ↓

Rubuz provisions genuine Let's Encrypt TLS certificates automatically via ACME HTTP-01 or DNS-01 challenges. Certificates are evaluated daily and renewed 30 days before expiration. Reloads occur seamlessly in memory without dropping live HTTP connections.

Can I use Cloudflare with Rubuz for DDoS protection and Full SSL? ↓

Yes, fully supported. You can enable Cloudflare proxying (Orange Cloud) with SSL mode set to Full (Strict). Rubuz handles the origin SSL certificate so traffic between Cloudflare edge nodes and your VPS remains 100% encrypted end-to-end.

Fortify Your Infrastructure

Host with absolute security. Without the DevOps complexity.

Connect any Linux server in 60 seconds. Enjoy rootless sandboxing, automated firewall protection, and zero root daemon risks today.

✓ No credit card required • Connect unlimited servers • 14-day trial