Skip to content
Discussion options

You must be logged in to vote

@axelere Your concern is absolutely valid and not paranoid at all.

Our recommended approach is not to expose Core at all. Only the Proxy and Gateway should be public. The Core web UI should be reachable only from the internal network or via VPN.

Users can still enroll through the Proxy and connect to the VPN via the Gateway.

Users manage their accounts only after connecting to the VPN.

With this approach, we do not see a strong need to divide the admin-related and user-related screens in the Core web UI.

More on our recommendations here.

Replies: 3 comments 5 replies

Comment options

You must be logged in to vote
3 replies
@axelere
Comment options

@teon
Comment options

teon Aug 15, 2025
Maintainer

@axelere
Comment options

Comment options

You must be logged in to vote
0 replies
Answer selected by axelere
Comment options

You must be logged in to vote
2 replies
@teon
Comment options

teon Jan 28, 2026
Maintainer

@axelere
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants