cockpit-ufw-module: Uncomplicated Firewall in Cockpit
UFW on a home or small server is usually configured over SSH: ufw status numbered, then ufw allow 443/tcp. cockpit-ufw-module covers the same cycle in the browser: package, status, policies, rules. It is one panel from the cockpit-modules group — UFW under Tools.
The UI is Russian, in PatternFly v5. You need Cockpit 264+ and administrator rights for writes. MIT license; current release is tag v.1.0.1.
Why a panel if ufw already exists
The client is already there: system ufw. What is missing is a view without a terminal and safe input: port, CIDR, rule number.
The panel does not replace iptables with its own engine. HTML and JS call host commands through cockpit.spawn as argv arrays, not shell strings. Input is validated on the client: port (including a range and a list), IPv4/IPv6 and CIDR, action allow / deny / reject / limit. Without Cockpit admin rights, package and rule operations do not run.
What the page shows
Four blocks, top to bottom:
| Block | Job |
|---|---|
| ufw package | installed or not, version, manager (APT, DNF, YUM, Pacman), install and remove |
| Status | active / inactive, logging level, incoming/outgoing policies, enable / disable / reload |
| Rules | table from ufw status numbered: number, to, action, from, delete |
| Add rule | action, protocol, port, source IP/CIDR |
While the firewall is off, the rules table is hidden: UFW does not apply them, even if the config still has entries. The counter then reads “N rules (inactive)”.
Installing the module
Use the store if it is already on the host. Otherwise install by hand:
Files go to /usr/share/cockpit/ufw. Refresh Cockpit — UFW appears under Tools.
For the current user without root:
The module lands in ~/.local/share/cockpit/ufw.
install.sh installs only the panel. The ufw package is installed from the UI, with Install ufw.
Typical flow on a clean host
Order matters more than the buttons. After the package install the module runs ufw --force reset, sets allow for incoming and outgoing, opens 22/tcp, and enables the ufw systemd unit. It does not enable the firewall — that is a separate button with an SSH warning.
- Tools → UFW → Install ufw. Confirm. On APT this starts with
apt-get update. - Add explicit rules for what you manage from this host. Cockpit listens on 9090/tcp — after the package install that rule is missing, only SSH 22 is present. If you later set incoming to
denywithout 9090, the panel disappears. - Services you need:
80/tcp,443/tcp, a range such as8000:8010. The source can be a CIDR, for example10.0.0.0/8. - Before adding, the UI shows a command preview (
ufw allow 443/tcp) — the same argv that will run on the host. - Enable. While default incoming is
allow, access is not cut: only explicit deny/reject/limit rules take effect. - Once SSH, Cockpit, and sites still work — switch the incoming policy to
deny. Leave outgoing onallowin the usual case.
Examples the form accepts:
limit is UFW’s rate limit on new connections, useful on 22. reject replies with ICMP/TCP reset; deny drops silently.
Install ufw runs ufw --force reset. Existing rules on the host are wiped. On a host that already has a tuned firewall, install the package by hand and use the panel only for status and small edits.
What the panel does not do
This is not the full ufw from the man page. The UI has no:
- application profiles (
ufw allow OpenSSH,ufw app list); - interface binding (
on eth0); - rule comments;
- in/out direction on the add form — new rules are inbound;
- logging level changes (the Logging line is read-only);
- routed policy, even though
ufw status verboseis parsed.
Removing the package disables UFW (ufw --force disable) and uninstalls it through the system manager; APT uses --purge.
Local check without touching a live host — Docker Compose from the repository: a privileged container with systemd, Ubuntu, Cockpit, and ufw, default http://localhost:9090, login admin / admin. That is a demo, not a production pattern.
Sources, issues, and tags live at gitlab.com/cockpit-modules/cockpit-ufw-module. Neighbouring panels in the same group: fail2ban, cron, CertManager.