Platform Security Controls
Every CloudSonic server is provisioned with the following security controls active by default; no configuration required on your part.
Network and Perimeter
UFW restricts all inbound traffic to ports 80, 443, and 2222 from the moment a server is provisioned. CrowdSec monitors Nginx, SSH, and PHP-FPM logs in real time, feeding block decisions to iptables using threat intelligence gathered across millions of deployments worldwide. Fail2ban catches brute force attempts against SSH and WordPress login endpoints that slip through before CrowdSec’s community blocklist identifies the source. Cloudflare Enterprise sits in front of every site on every plan, providing DDoS mitigation, WAF protection, and bot management at the network edge before traffic reaches your server.
Process Isolation
AppArmor enforces mandatory access control policies for every key process on your server including Nginx, PHP-FPM, MySQL, and Redis, restricting each to only the files, directories, and system calls it legitimately requires. If any process is compromised, AppArmor prevents it from reading sensitive files, writing outside its permitted directories, or spawning unexpected child processes.
Access Control
SSH is available on port 2222 only, with password authentication disabled and public key authentication required on every server. Tailscale creates a private WireGuard network between your server and your devices, allowing SSH access and all monitoring infrastructure to be restricted to your private Tailscale network without exposing those services to the public internet.
Encryption and Certificates
Let’s Encrypt SSL certificates are provisioned automatically during site setup and renewed automatically before expiry. For sites behind Cloudflare Enterprise, SSL terminates at the Cloudflare edge with a separate certificate, and the connection between Cloudflare and your origin server is encrypted with a CloudSonic-managed origin certificate. All internal service communication between Nginx, PHP-FPM, and Redis runs over Unix sockets rather than TCP ports, eliminating network-layer exposure between processes on the same server.
Monitoring and Visibility
Prometheus exporters for Node Exporter, Nginx, PHP-FPM, Redis, MySQL, and PostgreSQL run on every CloudSonic server, all bound to localhost and accessible only via Tailscale. No monitoring port is ever exposed to the public internet. Grafana dashboards connect to your Prometheus instance over your private Tailscale network, giving you full visibility into server performance without opening a single public port.
Memory and Process Protection
earlyoom runs on every server as a safety net against memory exhaustion, terminating low priority processes before the Linux kernel’s own out-of-memory killer takes over. Nginx, PHP-FPM, Redis, MariaDB, and PostgreSQL are explicitly protected from earlyoom termination, ensuring your web server and database survive memory pressure events caused by any other process on the server.