Files
glpi-ai-agent-controller/SECURITY.md
jbergner fe32431d21
Some checks failed
release-tag / release-image (push) Failing after 55s
init
2026-08-01 23:54:45 +02:00

1.2 KiB

Security

Docker socket

/var/run/docker.sock is a privileged host-control interface. A compromise of this application can compromise the Docker host. Do not expose the controller directly to the internet.

Recommended controls:

  • bind the HTTP port to loopback or a dedicated management network
  • terminate TLS at a hardened reverse proxy
  • add network-level access control in addition to Basic Auth
  • use a long random password
  • keep controller.json read-only
  • keep the target allowlist minimal
  • do not allow the controller to recreate itself
  • mount only the project directories that are actually required
  • review backups because they contain secrets

Secret handling

Secrets are omitted from the initial HTML and fetched only after an authenticated focus action. They are still visible to the browser after retrieval. Backups contain the complete .env and use mode 0600; protect the backup volume and include it in the host's secure backup policy.

Reporting

Report suspected vulnerabilities privately to the project owner. Include the affected version, deployment model, reproduction steps and impact. Do not include real credentials or .env files in reports.