Перейти к содержимому

Security architecture

Это содержимое пока не доступно на вашем языке.

Production deployment requires explicit trust boundaries, secure defaults, and tested mitigations for replication, webhooks, and HTTP gateways.

[Client SDK / CLI] --TLS?--> [gRPC :2113]
[REST/WS Gateway] --HTTP--> [gRPC backend]
[HA peer nodes] --???--> [ReplicationService]
[Billing webhook] --HTTPS--> [External receiver]
[Admin UI BFF] --HTTP--> [gRPC backend]
Component Spoofing Tampering Repudiation Info disclosure DoS Elevation
gRPC (auth off) High High Medium High Medium High
ReplicationService High High High Medium High High
Billing webhook Low Medium Medium Medium Low Medium (SSRF)
WS gateway Medium Medium Low High Medium Medium
Admin destructive ops Low High Medium Low Medium High
  • mTLS between cluster members or shared cluster token on internal listener.
  • Unauthenticated ReplicationService on public bind is not supported.
  • CHRONACTA_PROFILE=production enforces: auth on, TLS on, loopback or explicit bind audit, webhooks allowlist only.
  • HTTPS only; DNS resolve + block private ranges; mandatory HMAC secret when URL configured; no per-request URL override in production profile.
  • WS CheckOrigin allowlist; deprecate ?token= query; TLS termination documented (gateway or reverse proxy).
  • New permission lifecycle.execute for scavenge; default-deny unknown gRPC methods when auth enabled.
  • Structured audit events for: scavenge execute, restore, remote backup, billing export, admin login failure.
  • Field-level encryption at rest
  • FIPS compliance