Hardened by default. Zero leaks.
Defense in-depth engineered into the foundation. From rootless Podman user namespaces that prevent container breakouts, to automated host firewalls, Let's Encrypt wildcard TLS, and Argon2id cryptographic password hashing—your infrastructure is fortified from the moment you connect.
Only ports 22, 80, and 443 are reachable. Internal databases (5432, 6379, 3306) are never bound to public IPs.
Zero-touch Let's Encrypt certificates. HTTP/3 and TLS 1.3 enforced with automated ACME certificate rotation.
Root inside the container maps to unprivileged UID 100042 outside. Breakouts cannot inherit host root privileges.
Memory-hard Argon2id password hashing and encrypted environment keys with zero plaintext logs or storage.
DROP. Public exposure checked: Ports 22, 80, 443 only. All other incoming packets silently rejected.100000:65536). Container processes running with unprivileged capabilities only (CAP_NET_BIND_SERVICE dropped).*.rubuz.cloud verified. Expiry in 89 days. Auto-renewal scheduled at day 60.Why traditional Docker panels are vulnerable. And how Rubuz eliminates the risk.
Most hosting panels run Docker as full root (`dockerd`). If an attacker finds a remote code execution bug in one PHP or Node app, they break out and gain root control of your entire server.
The Insecure Legacy Approach
- ✕Root Daemon Escape Risk: Containers run under the root `dockerd` daemon. An escape exploit grants immediate root access to the entire host machine.
- ✕Silent Firewall Bypass: Docker manipulates iptables directly, frequently bypassing your UFW firewall rules and silently publishing raw database ports to the open internet.
- ✕Cross-Container Snooping: Shared unsegmented Docker bridges permit any compromised container on the host to scan and attack other neighboring applications.
- ✕Weak Password Hashing & Plaintext Secrets: Panels frequently store credentials with legacy MD5/SHA256 or store unencrypted database passwords in plain text on disk.
Hardened Defense-In-Depth
- ✓Rootless User Namespaces: Containers have zero root privileges on the host. An attacker who breaks out finds themselves trapped as an unprivileged UID with zero system access.
- ✓Strict UFW Respect (Zero Silent Leaks): Podman never overrides your firewall. Database ports (5432, 6379, 3306) bind strictly to container bridges, completely invisible to the outside web.
- ✓Isolated Per-App Virtual Networks: Each application stack runs in an isolated network sandbox. A breach in one app cannot access databases or microservices in another stack.
- ✓Argon2id Memory-Hard Cryptography: All password hashes and encryption keys use industry-standard Argon2id, immune to modern GPU and ASIC cracking attacks.
Engineered for airtight resilience.
Security isn't a checkbox or an add-on plugin. It is the fundamental architecture on which every container, database, and route is built.
Rootless Podman User Namespaces
Even if a vulnerability is discovered in an application like WordPress or Next.js, the attacker cannot compromise your server. Rubuz maps root inside the container to an unprivileged subuid on the host.
Automated Host Firewall (UFW) Lockdown
When you connect a VPS to Rubuz, host firewall rules are configured automatically. Only ports 22 (SSH), 80 (HTTP), and 443 (HTTPS) are permitted. All backend databases are strictly walled off.
Automated Let's Encrypt Wildcard TLS
Every application and subdomain deployed via Rubuz is automatically protected with modern TLS 1.3 certificates. Automated renewals execute seamlessly 30 days before expiration with zero manual intervention.
Argon2id Hashing & Ephemeral Sessions
Rubuz employs Argon2id—the winner of the Password Hashing Competition—configured with high memory cost parameters. Control panel authentication utilizes cryptographically signed, short-lived session tokens.
Everything you need to know about Rubuz Security.
What is rootless Podman and why is it safer than traditional Docker? ↓
In traditional Docker setups, the container daemon runs as the host `root` user (`dockerd`). If a containerized app is compromised and an attacker finds a container escape vulnerability, they immediately inherit full root privileges on the physical host. Podman runs containers inside unprivileged user namespaces. Root inside the container is actually an unprivileged UID on the host, meaning container escapes hit an impenetrable security wall with zero root access.
Can an attacker breach my server and read other applications' databases? ↓
No. Rubuz isolates every application stack into its own private virtual container network bridge. Databases like PostgreSQL and Redis communicate exclusively over internal network namespaces that are unreachable by other apps and completely unexposed to the public internet.
Does Rubuz leave open ports or background daemons running on my server? ↓
Zero. Unlike legacy hosting panels that install web servers, PHP daemons, and database managers running directly on the host, Rubuz connects to your server strictly via encrypted SSH. There are no proprietary daemons, no background listeners, and no extra ports opened on your firewall.
How are SSL certificates managed and will my site ever go offline due to expired certs? ↓
Rubuz provisions genuine Let's Encrypt TLS certificates automatically via ACME HTTP-01 or DNS-01 challenges. Certificates are evaluated daily and renewed 30 days before expiration. Reloads occur seamlessly in memory without dropping live HTTP connections.
Can I use Cloudflare with Rubuz for DDoS protection and Full SSL? ↓
Yes, fully supported. You can enable Cloudflare proxying (Orange Cloud) with SSL mode set to Full (Strict). Rubuz handles the origin SSL certificate so traffic between Cloudflare edge nodes and your VPS remains 100% encrypted end-to-end.
Host with absolute security. Without the DevOps complexity.
Connect any Linux server in 60 seconds. Enjoy rootless sandboxing, automated firewall protection, and zero root daemon risks today.
✓ No credit card required • Connect unlimited servers • 14-day trial