Skip to content

Firewall and allowlist

Every new database has its firewall on, with a default of deny: nothing can connect until you add an allow rule. The database’s Settings tab shows the current state, for example Closed until an allowed IP address is added or Open to 2 allowed address rules.

Rules are managed with the API for now, using an API key. Add ?region=<region> (the database’s region) to each call.

Terminal window
export DOCKHIVE_API_KEY=dh_pat_...
export DB=3f2a9c1b7e4d # the database id, from the console URL or GET /api/v1/databases
export REGION=eu
Terminal window
curl -X POST "https://gw.dockhive.sh/api/v1/databases/$DB/firewall/rules?region=$REGION" \
-H "Authorization: Bearer $DOCKHIVE_API_KEY" \
-H "Content-Type: application/json" \
-d '{"ip_address": "203.0.113.4", "cidr_mask": 32, "action": "allow", "description": "office"}'
Field Notes
ip_address Required. IPv4 only.
action Required. allow or deny.
cidr_mask Default 32 (a single address). Use 24 for a /24 range.
priority 1 to 10000, default 100. Lower numbers are checked first; the first match wins. The default action applies last.
description Optional note, up to 255 characters.
Terminal window
curl "https://gw.dockhive.sh/api/v1/databases/$DB/firewall/rules?region=$REGION" \
-H "Authorization: Bearer $DOCKHIVE_API_KEY"
curl -X DELETE "https://gw.dockhive.sh/api/v1/databases/$DB/firewall/rules/RULE_ID?region=$REGION" \
-H "Authorization: Bearer $DOCKHIVE_API_KEY"
Call Effect
POST …/firewall/allow-all Allows every address (0.0.0.0/0).
POST …/firewall/deny-all Denies every address.
POST …/firewall/default-action with {"action": "allow"} or "deny" Changes what happens when no rule matches.
POST …/firewall/toggle with {"enabled": false} Turns filtering off entirely. The database is then open to every address.
GET …/firewall/status Shows whether the firewall is on, the default action and rule counts.

All paths start with https://gw.dockhive.sh/api/v1/databases/$DB and need ?region=$REGION.