New Ory Agent Security is now live! Claim your complimentary test drive. Get Started!

Skip to main content

Secure Ory Console Lite

Ory Console Lite performs no authentication and no authorization. It forwards what you do to the admin APIs it is configured against, with whatever access those APIs grant. Treat reaching Ory Console Lite as equivalent to holding admin credentials for your entire Ory deployment.

Hardening checklist​

  • Never expose Ory Console Lite to the public internet. Keep it on a private network, behind a VPN, or behind an authenticating reverse proxy such as Ory Oathkeeper IAM Proxy that enforces your own login before any request reaches the container.
  • Bind the published port to an interface you control. -p 127.0.0.1:3000:3000 keeps Ory Console Lite on the loopback interface. Publishing as -p 3000:3000 exposes it on every interface of the host.
  • Keep the admin APIs off the public network too. Ory Console Lite reaches them from inside your network; nothing here requires Ory Kratos Identities, Ory Hydra Authorization, or Ory Keto Permissions admin ports to be publicly routable.
  • Set a stable CSRF_TOKEN_SECRET. Without one Ory Console Lite generates an ephemeral secret at startup, so tokens issued before a restart stop being accepted after it.
  • Pass credentials for protected admin APIs in the URL. If your admin APIs sit behind HTTP basic authentication, embed the credentials in the value, as in ORY_HYDRA_URL=https://user:[email protected]:4445. Ory Console Lite keeps them server-side and never sends them to the browser as part of an API call, but it does display the configured URL on the Settings page, so anyone who can reach Ory Console Lite can read them.

Next steps​

Professional support?

Ory offers support for self-hosted Ory software through the Ory Enterprise License (OEL). Read more about the OEL here.