Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Discuss
  3. Source code security when using Cloudron

Source code security when using Cloudron

Scheduled Pinned Locked Moved Discuss
3 Posts 3 Posters 546 Views 3 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • Z Offline
    Z Offline
    zonzonzon
    wrote on last edited by
    #1

    Hello everyone,

    I have a question regarding our usual practice of installing Cloudron on a VPS due to usage needs.
    When we move to a new provider or if, for some reason, an unauthorized person gains access to the old VPS or its disk, can they access the source code of all websites installed on Cloudron?

    What would be the best security solution for us when using Cloudron to minimize the risk of data loss? Thank you.

    fbartelsF 1 Reply Last reply
    1
    • Z zonzonzon

      Hello everyone,

      I have a question regarding our usual practice of installing Cloudron on a VPS due to usage needs.
      When we move to a new provider or if, for some reason, an unauthorized person gains access to the old VPS or its disk, can they access the source code of all websites installed on Cloudron?

      What would be the best security solution for us when using Cloudron to minimize the risk of data loss? Thank you.

      fbartelsF Offline
      fbartelsF Offline
      fbartels
      App Dev
      wrote on last edited by fbartels
      #2

      @zonzonzon said in Source code security when using Cloudron:

      can they access the source code of all websites installed on Cloudron?

      Yes, as soon as someone has physical access to a server they will have means to also see what is stored on disk. The only way around this would be full disk encryption, but during the runtime of the server the data is still decrypted which means as long as the server is running data is readable and only becomes inaccessible upon reboot (up until you enter the decryption passphrase).

      Or you are using an app that implements end to end encryption. If you're developing wordpress apps and you are concerned about someone stealing your source, then maybe obfuscation would be a means, but this only makes it harder still not impossible.

      1 Reply Last reply
      3
      • girishG Offline
        girishG Offline
        girish
        Staff
        wrote on last edited by
        #3

        When you say 'source code all websites', maybe you mean WordPress and LAMP websites? If so, ignore this comment. But source code of all cloudron packages and the final built images is all public - https://hub.docker.com/u/cloudron . you don't even need server credentials or install Cloudron for that matter to see the source code of apps.

        For WP/Lamp, I consider the websites themselves as "data" and "configuration" and not "source code".

        1 Reply Last reply
        1
        • girishG girish moved this topic from Off-topic on
        Reply
        • Reply as topic
        Log in to reply
        • Oldest to Newest
        • Newest to Oldest
        • Most Votes


        • Login

        • Don't have an account? Register

        • Login or register to search.
        • First post
          Last post
        0
        • Categories
        • Recent
        • Tags
        • Popular
        • Bookmarks
        • Search