1.1 KiB
Security
Supported version
Security fixes are intended for the current 2.x line.
Runtime hardening
The supplied container/deployment examples run non-root with a read-only root filesystem, dropped Linux capabilities and no privilege escalation. Kubernetes examples use RuntimeDefault seccomp and disable automatic service-account token mounting.
Runtime secrets can be read from files through LICENSE_TOKEN_FILE and BULK_API_KEY_FILE. Do not commit real licence tokens or API keys.
The dedicated bulk image is fail-closed by default: it requires a valid runtime licence, the bulk_api capability and an API key configuration before becoming ready.
Reporting
Do not open public issues containing active licence tokens, API keys, private infrastructure details or exploitable security findings. Use the project contact channel configured by the maintainer.
Trust store
Only public issuer/lease keys from the operator's Universal License Platform belong in internal/app/trusted_keys.json. Never place private signing keys in this repository or image.