

I don’t proxy the port, I proxy the routes needed for auth and interface. This isn’t that hard.
EDIT: ah I see what you’re saying, you’re talking about the app surface rather than the raw admin API. The risk is small enough with the remaining attack surface that I’m not particularly worried, though obviously I’d like it to be better.





Cranberries are pretty damn tart while still being edible.