Security
Security Best Practices
Comprehensive security recommendations for your Cafora Minecraft server.
Server Security Checklist
- Keep server software updated
- Keep all plugins updated
- Use a permissions plugin instead of OP
- Enable whitelist for private servers
- Configure regular automatic backups
- Monitor server console for suspicious activity
- Use strong passwords for your Cafora account
- Enable 2FA on your Cafora account
- Review firewall rules periodically
- Do not share API keys publicly
- Do not attempt to probe or connect to the origin IP (connections are dropped)
Network-Layer Protection
Cafora handles most of the network attack surface for you at the infrastructure layer:
- Minecraft and SFTP traffic is scrubbed by TCPShield Sentry
- Panel and API traffic goes through Cloudflare Tunnel
- The origin IP does not accept direct Minecraft / SFTP connections
So your focus should be on application-layer security: plugin vulnerabilities, permission configuration, and account credentials. See DDoS Protection.
Incident Response
If you suspect a security breach:
- Stop the server immediately
- Change your Cafora account password
- Review server logs for unauthorized activity
- Restore from a known-clean backup
- Contact Cafora support