Firewall settings and Docker
If your firewall settings are too restrictive, they may not work with Docker, and you may not be able to install GroundWork Monitor 8. Also, GroundWork uses port 5433 in the installation and upgrade process, so if you are blocking access to this port on the host, you may have this problem. Some security programs like SELinux, AppArmor, and anti-virus programs may do this. On CentOS and Red Hat systems with default firewalld rulesets, there is a known issue that actually prevents container-to-container communications which has the same effect.
Any of these conditions can halt the GroundWork Monitor installation or upgrade during the setup of the database with an error like the following:
If you see this error, you can take the following steps to complete your GroundWork Monitor 8 installation or upgrade. You will need to resolve the firewalld ruleset, security suite or anti-virus restriction issues to be compatible with using Docker. You should also at least temporarily allow port 5433/tcp for the duration of the install or upgrade, and this restriction can be reinstated.
For example, these steps will disable the default firewalld configuration and leave your GroundWork server in a potentially vulnerable state, so be sure to follow up and set up compatible secure rules after you have completed installing or upgrading GroundWork Monitor.
Disable the existing firewalld ruleset. Type, at the command line:
Remove the gw8 container that may have been left defined:
Restart the Docker daemon (note this instantiates the firewall rules Docker needs, but does not restart the firewall itself):
If desired, you may be able to complete the installation manually. From the command line in the gw8 directory, you can type:
TAGvalue is dependent on the version you are installing or upgrading to. You should see a message about the volumes getting initialized or migrations being run successfully.
Copy the environment files to the
gw8directory if in fact they are still missing. They may not be on upgrade, and should not be replaced if so:
Remove the gw8 container, since its purpose is fulfilled:
Start GroundWork if necessary (depending on the steps above, it may already be running:
Don't forget! You will need to determine and instantiate the appropriate firewall rules or security settings for your host!
GroundWork uses port TCP/443, and optionally TCP/5667 (for legacy GDMA) to the revproxy container, and it also requires container-to-container communications. You can adjust the firewalld settings to match your companies security policy as long as these conditions are met.
A useful example of adjusting firewalld rulesets to secure a Docker CE host can be found here.