@Team-XO-Backend @olivierlambert Hi,
Currently thought of somewhere else that Xen Orchestra and/or XO Proxy can be improved. Given that Vates uses open source software where it can, I’ve been wondering the following:
Why is there only reverse proxy settings documented for connecting Xen Orchestra and/or XO Proxy to the internet?
Couldn’t there also be software like a Web Application Firewall also used, or providing the internet interface access?
There’s both open source and closed source software and services available for this! Why not document the open source instances of this, at least for the start?
I’ve opened an GitHub Issue on this topic: https://github.com/vatesfr/xen-orchestra/issues/10444
The recommendation will still be to not expose it to the Internet, but there maybe situations where it’s unavoidable or the only option.
What does everyone think of the idea, of new additional documentation covering this?
@danp What would it take for as feedback for this to become, part of your support packages? As this will help, protect instances of Xen Orchestra and/or XO Proxy where avoiding Internet exposure, is unavoidable due to specific requirements and/or needs. I noticed these software and thought hey, this may fill a need that currently is underserved.
This could potentially create collaboration opportunities between the projects if the solution proves valuable to Xen Orchestra and/or XO Proxy users.