Harden Security Posture
Use after operational hardening and before production traffic. Harden Production configures the environment; this page verifies the security boundaries actually hold in it.
Prerequisites
Section titled “Prerequisites”Use a pinned verified release, stable mode, complete Secret, private storage, TLS ingress, authenticated metrics, and tested backup/incident paths.
Procedure
Section titled “Procedure”- Expose only required endpoints; keep storage, Audit, Coordinator, and Control private.
- Retain non-root, read-only, dropped-capability, seccomp, and no-new-privileges settings.
- Confirm secrets are projected, restricted, separately backed up, and inaccessible to agents.
- Verify browser origins, cookies, registration allowlist, password/SMTP policy, and proxy trust.
- Verify STS deny cases for credentials, scope, revocation, replay, and Approval.
- Verify Gateway binding/header, egress, dangerous addresses, redirects, revocation, and pre-dispatch denial.
- Verify stream/audit HMAC, tamper, DLQ/replay, and metrics auth.
- Reserve bootstrap admin credentials for break-glass.
Verification
Section titled “Verification”Retain negative-test IDs, readiness, rendered settings, network results, provenance, alert test, and restore evidence.
Recovery
Section titled “Recovery”Remove affected endpoint/workload from traffic, restore verified config, and open an incident for possible exposure. Never switch to dev or disable safety checks.
Next Step
Section titled “Next Step”Verify artifacts with Verify a Release.

