3 ms·
How does one update an oldschool web admin page to interact with this model? For example, suppose Kermpany had already been up and running for a while with a s
by JackC 6y ago
How does one update an oldschool web admin page to interact with this model?
For example, suppose Kermpany had already been up and running for a while with a standard Django website running behind Cloudflare with an admin page at example.com/admin/.
Now the things in the blog post have happened, and Kermpany wants to make sure that only machines on the "humans" CIDR can connect to the routes hosted at example.com/admin/.
What happens next? Does the admin tool move to a new domain?
The manual wireguard solution I know of is to add the example.com IP to the list of AllowedIPs, so the wireguard interface gets used for all requests from the local machine to example.com, and then restrict the /admin/ route in nginx to just the wireguard server's IP. But that takes a lot of bookkeeping and I feel like I'm missing something.
- codethief 6y agoI don't think there's another way than the two ways you've already described. IMO, moving the admin tool to a separate domain (and server!) would be the best option here in terms of security. That way, there are clear boundaries and fewer attack vectors and you also don't need to do as much bookkeeping.