Install the UFW firewall by default; add -W to opt out - #853
Merged
Merged
Conversation
kepstin
reviewed
Sep 30, 2026
kepstin
reviewed
Sep 30, 2026
kepstin
left a comment
Contributor
There was a problem hiding this comment.
Code changes look fine, I just have some minor recommendations for improving the script's help text.
kepstin
approved these changes
Sep 30, 2026
Co-authored-by: Calvin Walton <calvin.walton@blindsidenetworks.com>
antobinary
added a commit
that referenced
this pull request
Sep 30, 2026
Port of #853 from v4.0.x-release. The firewall is set up unless -W is passed; -w is kept as an accepted, warning-only flag so existing commands keep working and the letter is not reused for something else.
antobinary
added a commit
that referenced
this pull request
Sep 30, 2026
Backport of #853 from v4.0.x-release. The firewall is set up unless -W is passed; -w is kept as an accepted, warning-only flag so existing commands keep working and the letter is not reused for something else.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
bbb-install.shnow sets up the UFW firewall on every BigBlueButton install unless-Wis passed. Until now the firewall was only set up when-wwas passed.Changes
-W(new): skips the firewall setup.-w: still accepted, so existing install and upgrade commands keep working. It no longer changes anything and prints a deprecation warning:SSH port guard: moved out of the
-whandler into a newcheck_ssh_port, which runs with the other pre-install checks, before anything is installed.sshd -T. The old check grepped/etc/ssh/ssh_config, which is the client configuration, so it practically never fired.-W, becauseenableUFWRulesonly allows SSH on port 22 and would lock the admin out.-Wis passed, or when/etc/bigbluebutton/bbb-conf/apply-config.shalready exists (the script leaves an existing file untouched, so there is nothing to guard).Docs:
-wis removed from every example in the help text, the script header and the README quickstart. The README firewall paragraph describes the new default and-W.Behaviour changes to be aware of
-wgets UFW enabled the next time the install command is re-run, unless it already has anapply-config.sh.-Wis passed. Previously it only hit this path with-w.-Wdoes not disable UFW. It only skips the setup; a firewall that is already enabled stays enabled.-vstill does not set up UFW.ssh.socketoverride, without touchingsshd_config, is not detected.Testing
bash -n bbb-install.sh-h,-w -h,-W -hparse and print the help-wis passedcheck_ssh_portwith stubbed sshd on port 22check_ssh_portwith stubbed sshd on port 2222check_ssh_portwith stubbed sshd on ports 22 and 2222check_ssh_portwith no sshd installed