Skip to content

Harden Security Posture

Use after operational hardening and before production traffic. Harden Production configures the environment; this page verifies the security boundaries actually hold in it.

Use a pinned verified release, stable mode, complete Secret, private storage, TLS ingress, authenticated metrics, and tested backup/incident paths.

  1. Expose only required endpoints; keep storage, Audit, Coordinator, and Control private.
  2. Retain non-root, read-only, dropped-capability, seccomp, and no-new-privileges settings.
  3. Confirm secrets are projected, restricted, separately backed up, and inaccessible to agents.
  4. Verify browser origins, cookies, registration allowlist, password/SMTP policy, and proxy trust.
  5. Verify STS deny cases for credentials, scope, revocation, replay, and Approval.
  6. Verify Gateway binding/header, egress, dangerous addresses, redirects, revocation, and pre-dispatch denial.
  7. Verify stream/audit HMAC, tamper, DLQ/replay, and metrics auth.
  8. Reserve bootstrap admin credentials for break-glass.

Retain negative-test IDs, readiness, rendered settings, network results, provenance, alert test, and restore evidence.

Remove affected endpoint/workload from traffic, restore verified config, and open an incident for possible exposure. Never switch to dev or disable safety checks.

Verify artifacts with Verify a Release.