Skip to content

Install the UFW firewall by default; add -W to opt out - #853

Merged
antobinary merged 2 commits into
v4.0.x-releasefrom
40-firewall-opt-out
Sep 30, 2026
Merged

antobinary merged 2 commits into
v4.0.x-releasefrom
40-firewall-opt-out

Conversation

@antobinary

@antobinary antobinary commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

What

bbb-install.sh now sets up the UFW firewall on every BigBlueButton install unless -W is passed. Until now the firewall was only set up when -w was passed.

Changes

  • -W (new): skips the firewall setup.

  • -w: still accepted, so existing install and upgrade commands keep working. It no longer changes anything and prints a deprecation warning:

    bbb-install: WARNING: -w is deprecated -- the UFW firewall is now installed by default. To opt out, pass -W instead.
    
  • SSH port guard: moved out of the -w handler into a new check_ssh_port, which runs with the other pre-install checks, before anything is installed.

    • It now reads the effective server configuration from sshd -T. The old check grepped /etc/ssh/ssh_config, which is the client configuration, so it practically never fired.
    • If sshd does not listen on port 22 the install stops with an error pointing at -W, because enableUFWRules only allows SSH on port 22 and would lock the admin out.
    • The guard is skipped when -W is passed, or when /etc/bigbluebutton/bbb-conf/apply-config.sh already exists (the script leaves an existing file untouched, so there is nothing to guard).
  • Docs: -w is removed from every example in the help text, the script header and the README quickstart. The README firewall paragraph describes the new default and -W.

Behaviour changes to be aware of

  • Upgrades enable the firewall. A server that was installed without -w gets UFW enabled the next time the install command is re-run, unless it already has an apply-config.sh.
  • Non-standard SSH port. A server with sshd on a port other than 22 now stops with an error unless -W is passed. Previously it only hit this path with -w.
  • -W does not disable UFW. It only skips the setup; a firewall that is already enabled stays enabled.
  • Coturn-only installs are unchanged. Running without -v still does not set up UFW.
  • Known gap. An SSH port changed only through an ssh.socket override, without touching sshd_config, is not detected.

Testing

Check Result
bash -n bbb-install.sh PASS
-h, -w -h, -W -h parse and print the help PASS
Warning printed only when -w is passed PASS
check_ssh_port with stubbed sshd on port 22 PASS (continues)
check_ssh_port with stubbed sshd on port 2222 PASS (stops with error)
check_ssh_port with stubbed sshd on ports 22 and 2222 PASS (continues)
check_ssh_port with no sshd installed PASS (continues)
default clean installation PASS

@antobinary
antobinary requested a review from kepstin September 30, 2026 14:57
Comment thread bbb-install.sh Outdated

@kepstin kepstin left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code changes look fine, I just have some minor recommendations for improving the script's help text.

Co-authored-by: Calvin Walton <calvin.walton@blindsidenetworks.com>
@antobinary
antobinary merged commit bcd9f2f into v4.0.x-release Sep 30, 2026
2 checks passed
@antobinary
antobinary deleted the 40-firewall-opt-out branch September 30, 2026 19:11
antobinary added a commit that referenced this pull request Sep 30, 2026
Port of #853 from v4.0.x-release. The firewall is set up unless -W is
passed; -w is kept as an accepted, warning-only flag so existing
commands keep working and the letter is not reused for something else.
antobinary added a commit that referenced this pull request Sep 30, 2026
Backport of #853 from v4.0.x-release. The firewall is set up unless -W
is passed; -w is kept as an accepted, warning-only flag so existing
commands keep working and the letter is not reused for something else.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants