Secure Ory Console Lite
Ory Console Lite performs no authentication and no authorization. It forwards what you do to the admin APIs it is configured against, with whatever access those APIs grant. Treat reaching Ory Console Lite as equivalent to holding admin credentials for your entire Ory deployment.
Hardening checklist
- Never expose Ory Console Lite to the public internet. Keep it on a private network, behind a VPN, or behind an authenticating reverse proxy such as Ory Oathkeeper IAM Proxy that enforces your own login before any request reaches the container.
- Bind the published port to an interface you control.
-p 127.0.0.1:3000:3000keeps Ory Console Lite on the loopback interface. Publishing as-p 3000:3000exposes it on every interface of the host. - Keep the admin APIs off the public network too. Ory Console Lite reaches them from inside your network; nothing here requires Ory Kratos Identities, Ory Hydra Authorization, or Ory Keto Permissions admin ports to be publicly routable.
- Set a stable
CSRF_TOKEN_SECRET. Without one Ory Console Lite generates an ephemeral secret at startup, so tokens issued before a restart stop being accepted after it. - Pass credentials for protected admin APIs in the URL. If your admin APIs sit behind HTTP basic authentication, embed the
credentials in the value, as in
ORY_HYDRA_URL=https://user:[email protected]:4445. Ory Console Lite keeps them server-side and never sends them to the browser as part of an API call, but it does display the configured URL on the Settings page, so anyone who can reach Ory Console Lite can read them.
Next steps
- Troubleshooting — fixes for startup failures, unreachable services, and disabled features
- Ory Oathkeeper IAM Proxy — put an authenticating proxy in front of Ory Console Lite
Professional support?
Ory offers support for self-hosted Ory software through the Ory Enterprise License (OEL). Read more about the OEL here.