Home / Docs / HAProxy (Hardened) / Security
| Port | Purpose | State |
|---|---|---|
| 22 | SSH (key-only) | default-open |
| 80/443 | Frontends you configure in haproxy.cfg | default-open (firewall) — no listener until you configure one |
| 8404 | Stats endpoint — bound to 127.0.0.1 | optional (reach via SSH/IAP tunnel) |
"customer-must-open" means a cloud firewall rule and, where noted, an in-image configuration change — both deliberate. Closed by default is the design.
| We maintain | The hardened image: package selection, hardening baseline, CVE rebuilds, listing freshness, and these docs. |
|---|---|
| You control | The running instance: OS patching between image versions, network exposure, IAM, data, and backups. |
| Your cloud provides | Physical/hypervisor security, marketplace billing, and the firewall primitives this design relies on. |