1.5 KiB
1.5 KiB
Security Policy
Security Model
Stoat Admin is designed to keep the application containers private even when the admin entrypoint is fronted by its own HTTPS proxy. The intended deployment model is:
admin-proxyis the only published service and terminates HTTPS for the admin stack with Caddy's internal CAadmin-webandadmin-apiare reachable only on the private admin container networkadmin-apijoins the Stoat network only so it can reach MongoDB- the dashboard is not exposed through the public Stoat reverse proxy
- the API still requires session-based authentication with an Argon2id-hashed admin credential
This means the reverse proxy limits what is exposed, the shared Stoat network is used only where needed, and the application session still limits user access.
Reporting
If you discover a security issue, avoid opening a public issue with exploit details. Share the report privately with the maintainer and include:
- affected version or commit
- reproduction steps
- impact
- any suggested mitigation
Deployment Notes
- Keep
SESSION_SECRETandRESEND_API_KEYout of the repository. - Restrict permissions on the SQLite database file mounted at
/data/admin.db. - Set
ADMIN_WEB_ORIGINprecisely. Do not use*. - Verify the compose port bindings expose only
admin-proxy, notadmin-weboradmin-api. - Trust Caddy's internal root CA only on the admin devices that should access the dashboard.
- Protect the
admin_proxy_datavolume. It contains the private CA material used to issue the dashboard certificate.