4.3 KiB
Security
Overview
SilverLinux hosts critical infrastructure for Silver Solutions.
This document describes the security measures implemented on the server and operational security requirements.
Access Control
SSH Access
SSH access is limited to authorized administrators.
Authentication:
- SSH key authentication
- Password login discouraged
- Root login disabled
Primary user:
ubuntu
Firewall
UFW
UFW is enabled and used as the primary host firewall.
Allowed ports:
| Port | Purpose |
|---|---|
| 22 | SSH |
| 80 | HTTP |
| 443 | HTTPS |
All other ports should remain blocked unless explicitly required.
Intrusion Protection
Fail2Ban
Fail2Ban is enabled.
Purpose:
- Detect brute-force attacks
- Automatically block malicious IP addresses
- Protect SSH access
Secrets Management
Shared secrets are stored in:
/srv/secrets/company.env
Examples:
- SMTP credentials
- PostgreSQL passwords
- MSSQL SA password
- OpenProject secrets
- Future OAuth secrets
Rules:
- Never commit secrets to Git
- Never share secrets in documentation
- Never hardcode passwords in Docker Compose files
See:
docs/secrets.md
SSL Certificates
SSL certificates are managed through Nginx Proxy Manager.
Certificates are automatically renewed.
All public services should be accessible through HTTPS only.
Email Security
Outgoing email is provided through Gmail SMTP.
Credentials are stored in:
/srv/secrets/company.env
Requirements:
- Use Gmail App Passwords only
- Never store personal account passwords
- Rotate credentials if exposure is suspected
Sender address:
noreply@silveressence.net
Authentication
Current
- Local user accounts
- Strong passwords
Planned
Future OAuth providers:
- Google OAuth2
- GitHub OAuth2
Requirements:
- Store client secrets in company.env
- Use least-privilege scopes
- Disable unused authentication providers
Disabled
- OpenID authentication
Reason:
OpenID is not required and increases attack surface.
Two-Factor Authentication
Where supported:
- Enable 2FA for administrator accounts
- Encourage 2FA for all users
Priority:
- Gitea administrators
- OpenProject administrators
Database Security
PostgreSQL and Microsoft SQL Server are not exposed publicly.
Database access is restricted to Docker internal networks.
Applications and DbGate communicate with the database containers through the internal Docker network.
DbGate is the public administration entry point and must require authentication and HTTPS. Its web interface is routed through Nginx Proxy Manager; database ports 5432 and 1433 remain private.
Docker Security
Services are isolated through Docker containers.
Principles:
- Public services should be exposed only through Nginx Proxy Manager
- Internal services should not expose ports publicly
- Services should communicate through Docker networks
- Containers should run with the minimum required privileges
Networks:
- proxy
- internal
System Updates
The operating system and containers should be updated regularly.
Recommendations:
- Apply Ubuntu security updates
- Update Docker images periodically
- Remove unused containers and images
- Review security advisories for critical services
Backup Security
Backups must include:
- Configuration files
- Docker Compose files
- Application data
- PostgreSQL databases
- Shared secrets
Backups must never be stored inside public repositories.
Security Review Checklist
Periodically verify:
- SSH keys are current
- Unused accounts are removed
- Fail2Ban is active
- UFW is active
- SSL certificates are valid
- Secrets are not stored in repositories
- Backups are functioning
- Administrator accounts have 2FA enabled
- Review application logs
- Review Docker logs
- Review authentication failures
- Review Fail2Ban bans
Incident Response
If a credential is exposed:
- Rotate the credential immediately.
- Update
/srv/secrets/company.env. - Restart affected services.
- Review logs for unauthorized access.
- Update documentation if required.
Related Documentation
- docs/server.md
- docs/secrets.md
- docs/backups.md
- docs/email.md
- nginx-proxy-manager/README.md