DC Associates Group logoDC Associates Group

Home / Docs / HAProxy (Hardened) / Security

HAProxy (Hardened) — security notes

Network exposure

PortPurposeState
22SSH (key-only)default-open
80/443Frontends you configure in haproxy.cfgdefault-open (firewall) — no listener until you configure one
8404Stats endpoint — bound to 127.0.0.1optional (reach via SSH/IAP tunnel)

"customer-must-open" means a cloud firewall rule and, where noted, an in-image configuration change — both deliberate. Closed by default is the design.

Shared responsibility

We maintainThe hardened image: package selection, hardening baseline, CVE rebuilds, listing freshness, and these docs.
You controlThe running instance: OS patching between image versions, network exposure, IAM, data, and backups.
Your cloud providesPhysical/hypervisor security, marketplace billing, and the firewall primitives this design relies on.