Investigate further system security hardening #479
Labels
component: security
An issue relating to host security (e.g. hardened security preferences). This is NOT critical bugs.
component: services
An issue relating to a Python Discord service (e.g. Bot, Site, Lancebot)
group: ansible
Issues and pull requests related to the Ansible setup
Planning ticket to check out and investigate further possibilities at security
hardening. Ideally these should be contributed upstream if applicable.
Things to consider:
Of course, service-specific hardening strategies implemented in code also play a
role. For Postfix and OpenSSH for instance I am way less concerned than e.g. for
Jitsi. At the bare minimum, all services should run under a dedicated user.
This ticket is not for evaluating resource limits per service (e.g. to prevent
DoS on externally reachable services), although it might also be interesting to
evaluate that.
The text was updated successfully, but these errors were encountered: