Skip to content

cockpit-ufw-module: Uncomplicated Firewall in Cockpit

UFW on a home or small server is usually configured over SSH: ufw status numbered, then ufw allow 443/tcp. cockpit-ufw-module covers the same cycle in the browser: package, status, policies, rules. It is one panel from the cockpit-modules group — UFW under Tools.

The UI is Russian, in PatternFly v5. You need Cockpit 264+ and administrator rights for writes. MIT license; current release is tag v.1.0.1.

Why a panel if ufw already exists

The client is already there: system ufw. What is missing is a view without a terminal and safe input: port, CIDR, rule number.

The panel does not replace iptables with its own engine. HTML and JS call host commands through cockpit.spawn as argv arrays, not shell strings. Input is validated on the client: port (including a range and a list), IPv4/IPv6 and CIDR, action allow / deny / reject / limit. Without Cockpit admin rights, package and rule operations do not run.

What the page shows

Four blocks, top to bottom:

BlockJob
ufw packageinstalled or not, version, manager (APT, DNF, YUM, Pacman), install and remove
Statusactive / inactive, logging level, incoming/outgoing policies, enable / disable / reload
Rulestable from ufw status numbered: number, to, action, from, delete
Add ruleaction, protocol, port, source IP/CIDR

While the firewall is off, the rules table is hidden: UFW does not apply them, even if the config still has entries. The counter then reads “N rules (inactive)”.

Installing the module

Use the store if it is already on the host. Otherwise install by hand:

git clone https://gitlab.com/cockpit-modules/cockpit-ufw-module.git
cd cockpit-ufw-module
sudo ./install.sh

Files go to /usr/share/cockpit/ufw. Refresh Cockpit — UFW appears under Tools.

For the current user without root:

./install.sh --user

The module lands in ~/.local/share/cockpit/ufw.

Note

install.sh installs only the panel. The ufw package is installed from the UI, with Install ufw.

Typical flow on a clean host

Order matters more than the buttons. After the package install the module runs ufw --force reset, sets allow for incoming and outgoing, opens 22/tcp, and enables the ufw systemd unit. It does not enable the firewall — that is a separate button with an SSH warning.

  1. Tools → UFW → Install ufw. Confirm. On APT this starts with apt-get update.
  2. Add explicit rules for what you manage from this host. Cockpit listens on 9090/tcp — after the package install that rule is missing, only SSH 22 is present. If you later set incoming to deny without 9090, the panel disappears.
  3. Services you need: 80/tcp, 443/tcp, a range such as 8000:8010. The source can be a CIDR, for example 10.0.0.0/8.
  4. Before adding, the UI shows a command preview (ufw allow 443/tcp) — the same argv that will run on the host.
  5. Enable. While default incoming is allow, access is not cut: only explicit deny/reject/limit rules take effect.
  6. Once SSH, Cockpit, and sites still work — switch the incoming policy to deny. Leave outgoing on allow in the usual case.

Examples the form accepts:

22/tcp
443,80
8000:8010
from 10.0.0.0/8 to any port 443 proto tcp

limit is UFW’s rate limit on new connections, useful on 22. reject replies with ICMP/TCP reset; deny drops silently.

Warning

Install ufw runs ufw --force reset. Existing rules on the host are wiped. On a host that already has a tuned firewall, install the package by hand and use the panel only for status and small edits.

What the panel does not do

This is not the full ufw from the man page. The UI has no:

  • application profiles (ufw allow OpenSSH, ufw app list);
  • interface binding (on eth0);
  • rule comments;
  • in/out direction on the add form — new rules are inbound;
  • logging level changes (the Logging line is read-only);
  • routed policy, even though ufw status verbose is parsed.

Removing the package disables UFW (ufw --force disable) and uninstalls it through the system manager; APT uses --purge.

Local check without touching a live host — Docker Compose from the repository: a privileged container with systemd, Ubuntu, Cockpit, and ufw, default http://localhost:9090, login admin / admin. That is a demo, not a production pattern.

Sources, issues, and tags live at gitlab.com/cockpit-modules/cockpit-ufw-module. Neighbouring panels in the same group: fail2ban, cron, CertManager.