Security
Network security
Operational| Layer | Configuration |
|---|---|
| OVH Edge Firewall | Allows inbound TCP 22, 80, 443, 2222; final deny-all for other IPv4 traffic |
| UFW | Allows the same four ports; default incoming policy is deny |
| SSH | Key authentication only; password authentication disabled |
| Fail2ban | Installed and active |
Docker and UFW
Ports published by Docker containers bypass UFW rules. The OVH Edge Firewall is what keeps additional container ports unreachable from the Internet. Any change to the Edge Firewall must take this into account.
Secrets
Never store or commit passwords, API keys, access tokens, private keys or production credentials — in code or in documentation.
Documentation portal access
The documentation portal is private.
- Operational HTTP Basic Authentication on the Coolify application (Traefik), as a temporary protection. Credentials are managed in Coolify only.
- Planned Authentication and authorization in front of Docusaurus with Authentik + OIDC/OAuth2/SSO, replacing Basic Auth.
Quality and security tooling
| Tool | Purpose | Status |
|---|---|---|
| SonarQube | Code quality | Planned |
| Trivy | Container and dependency scanning | Planned |
| ClamAV | Malware scanning | Deferred until real user uploads exist |
Future GPX upload security should include quarantine, size limits, MIME/type validation, secure XML parsing (XXE and XML-bomb protection), GPX validation, generated filenames and quotas.