Groups & access policies
Who may reach whom, and two things that surprise people.
Groups are free text. A device is in exactly one, set by the setup key it used or changed later; users can be in several. Policies then decide who may reach whom.
What a policy says
- Sources and destinations — Groups the traffic comes from, and groups or specific Resources it goes to.
- Direction — Both ways, or one way — sources may start connections, destinations may only answer.
- Protocol and ports — All, or TCP/UDP with port ranges, or ICMP.
- Posture checks — Extra conditions the device itself must satisfy. Pro.
- Active — Off keeps the policy without applying it.
Visibility is mutual, permission is not
If a policy lets one group reach another, devices on both sides see each other in Peers — a tunnel needs both ends configured. What one-way direction controls is who may start a connection.
A Resource policy grants the Resource, not the machine
Letting a group reach a database behind a routing peer does not let them reach the routing peer itself. If you want both, say both.
docker compose exec mangofly mangofly-server --create-policy "eng to lab" \
--from eng --to lab --one-way --protocol tcp --ports 22,8000-8080