Files
ai-disclosure-standard/SECURITY.md
jbergner 6e152a5121
Some checks failed
release-tag / release-image (push) Failing after 1m38s
2.0.2 Update und Anpassungen
2026-07-24 10:08:19 +02:00

34 lines
1.8 KiB
Markdown

# Security
## Supported version
Security fixes are intended for the current 2.x line.
## Runtime hardening
The supplied container/deployment examples run non-root with a read-only root filesystem, dropped Linux capabilities and no privilege escalation. Kubernetes examples use `RuntimeDefault` seccomp and disable automatic service-account token mounting.
Runtime secrets can be read from files through `LICENSE_TOKEN_FILE` and `BULK_API_KEY_FILE`. Do not commit real licence tokens or API keys.
The dedicated bulk image is fail-closed by default: it requires a valid runtime licence, the `bulk_api` capability and an API key configuration before becoming ready.
## Reporting
Do not open public issues containing active licence tokens, API keys, private infrastructure details or exploitable security findings. Use the project contact channel configured by the maintainer.
## Trust store
Only public issuer/lease keys from the operator's Universal License Platform belong in `internal/app/trusted_keys.json`. Never place private signing keys in this repository or image.
## Proxy trust and client addresses
`TRUST_PROXY=true` requires `TRUSTED_PROXY_CIDRS`. Forwarded address headers are used only when the directly connected peer belongs to one of those networks. Client IPs are omitted from request logs unless `LOG_CLIENT_IP=true` is explicitly enabled.
## Prometheus
`/metrics` is disabled by default. `METRICS_ENABLED=true` requires a bearer secret of at least 32 characters via `METRICS_TOKEN` or preferably `METRICS_TOKEN_FILE`. Do not expose the endpoint publicly even when authentication is enabled.
## Operator information
`LEGAL_STRICT=true` is a deployment guard against empty or placeholder operator/privacy configuration. It does not certify legal compliance and should be combined with a review of the actual deployment and applicable jurisdiction.