Services
A service is one application behind NullWard. It has: one or more hostnames that route to it, one or more destinations (backends) that requests are sent to, the security and access settings that apply to its traffic. Requests are routed by hostname. Each hostname belongs to exactly one service. Add a service Go to Services > Services and click Add Service. Fill in the form: Name: a label for the dashboard. Host Pattern: the main hostname, either exact (app.example.com) or a wildcard (*.example.com). Additional hostnames: any other names that should reach the same application. Upstream Type: Direct HTTP/HTTPS for a backend NullWard can reach, or Application Tunnel for a backend behind a tunnel. Upstream URL: the backend address, for example http://10.0.1.20:8080 or https://app-backend:8443. Strip Path (optional): a path prefix to remove before forwarding, for example /api. Choose the toggles. WAF Enabled and TLS Enabled are off by default, so turn them on for internet-facing applications. Click Create Service. Then open the service (click its name, or the edit icon) to configure the rest. The service settings page All of a service's settings are on one page, grouped into sections. Click Save Changes in the bar at the bottom to apply them. There's no restart. General: hostnames and destinations Destinations lists the backends. Each destination has: Type: Direct HTTP or Application Tunnel. URL: for direct destinations, the backend address. For tunnel destinations, pick the Tunnel and Upstream Group instead. TLS Verification: Inherit service, Skip verification (for self-signed backend certificates) or Require valid cert. Protocol (HTTPS destinations): HTTP/1.1–2 or HTTP/3. See HTTP/3. Destinations can be turned off individually and reordered. The order matters for failover. Load balancing and health With two or more destinations, Load Balancing & Health offers: Policy: Round-robin, or Failover (always use the first healthy destination in list order). Sticky Sessions: off by default. When on, each visitor stays on the same backend: the same destination (cookie nw_upstream), and, through an application tunnel, the same pod or target behind the connector (cookie nw_affinity). Turn it on for applications that keep sessions in a backend's memory or issue a session cookie per backend, such as the Wazuh dashboard. Your application never sees either cookie. Tunnel affinity needs connectors 0.6.85 or later. The toggle also appears for a service whose only destination is a tunnel. Passive Cooldown (s): after a connection to a destination fails, the destination is skipped for this many seconds. This works even without an active health check. Active Health Check: probes a Path every Interval seconds. A destination is marked healthy or unhealthy after the configured number of passes or failures. Responses matching Expected Status (default 200-399) count as healthy. Maintenance Maintenance Mode shows visitors a maintenance page, with an optional message and expected end time. Scheduled Maintenance Windows turn it on automatically, once or on a recurring schedule. Each window has a mode: Full Block (all traffic), or Intercept Errors (5xx only), which shows the maintenance page only when the backend returns server errors. Security This is where the protection for the service is turned on: WAF Enabled and WAF Mode: block, or audit only. See Web application firewall. Auth Enabled: require sign-in. See Authentication. Other sections Section What it does TLS Configuration Certificates, TLS versions and ciphers, HTTP/3, upstream TLS verification, HTTPS redirect and HSTS. See TLS certificates. Bot Detection Challenge visitors with Turnstile, reCAPTCHA or hCaptcha. See Threat protection. IP Intelligence Check visitor IPs against a reputation provider. See Threat protection. IP Allowlist Allow only listed IPs to reach this service. All other IPs get a 403. See Threat protection. ML Security ML WAF settings for this service (licensed). See ML WAF…
NullWard documentation