Skip to main content

Security

Network security​

Operational
LayerConfiguration
OVH Edge FirewallAllows inbound TCP 22, 80, 443, 2222; final deny-all for other IPv4 traffic
UFWAllows the same four ports; default incoming policy is deny
SSHKey authentication only; password authentication disabled
Fail2banInstalled and active
Docker and UFW

Ports published by Docker containers bypass UFW rules. The OVH Edge Firewall is what keeps additional container ports unreachable from the Internet. Any change to the Edge Firewall must take this into account.

Secrets​

Never store or commit passwords, API keys, access tokens, private keys or production credentials — in code or in documentation.

Documentation portal access​

The documentation portal is private.

  • Operational HTTP Basic Authentication on the Coolify application (Traefik), as a temporary protection. Credentials are managed in Coolify only.
  • Planned Authentication and authorization in front of Docusaurus with Authentik + OIDC/OAuth2/SSO, replacing Basic Auth.

Quality and security tooling​

ToolPurposeStatus
SonarQubeCode qualityPlanned
TrivyContainer and dependency scanningPlanned
ClamAVMalware scanningDeferred until real user uploads exist

Future GPX upload security should include quarantine, size limits, MIME/type validation, secure XML parsing (XXE and XML-bomb protection), GPX validation, generated filenames and quotas.