Add observability and security-hardening proposals, gitignore settings.local

Two new OpenSpec changes:
- observability (30 tasks): health endpoints, Prometheus, Grafana+Loki,
  structured logging, dashboards, alerting
- security-hardening (24 tasks): Caddy headers, scanner blocking,
  gitleaks, pnpm audit, dependabot, non-root Docker, fail2ban

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
Ullrich Schäfer 2026-03-25 09:48:08 +01:00
parent 734b022004
commit 7d20dbb12f
No known key found for this signature in database
GPG key ID: A32FF691A0F752D9
13 changed files with 564 additions and 0 deletions

View file

@ -0,0 +1,42 @@
## Why
A security audit found several gaps: no security headers (HSTS, CSP, etc.),
no secret scanning in CI, no dependency vulnerability scanning, Docker
containers running as root, and bot scanners probing for `.env` files with
no filtering. The cookie and auth setup is solid, but the infrastructure and
CI layers need hardening.
## What Changes
- **Security headers**: HSTS, X-Content-Type-Options, X-Frame-Options,
Referrer-Policy, Permissions-Policy via Caddyfile
- **Content-Security-Policy**: Restrict script/style/font sources
- **Gitleaks**: Secret scanning in CI to prevent credential leaks
- **Dependency auditing**: `pnpm audit` in CI + Dependabot for automated updates
- **Docker hardening**: Non-root user in all Dockerfiles
- **Bot/scanner blocking**: Caddy matcher to reject known scanner paths
(`.env`, `.git`, `wp-config`, etc.) with 403 before hitting the app
- **Fail2ban or equivalent**: Rate-limit SSH brute force and scanner IPs
at the server level
- **SECURITY.md**: Vulnerability disclosure policy
## Capabilities
### New Capabilities
- `security-hardening`: Security headers, CI secret/dependency scanning,
Docker non-root, scanner blocking, server-level rate limiting
### Modified Capabilities
- `infrastructure`: Caddy security headers + scanner blocking, Docker non-root,
Terraform firewall adjustments, CI scanning steps
## Impact
- **Caddyfile**: Security headers + scanner path blocking
- **Dockerfiles**: Add non-root user (journal, planner, brouter)
- **CI**: Add gitleaks step, pnpm audit step
- **Repo**: Add `.gitleaks.toml`, `dependabot.yml`, `SECURITY.md`
- **Server**: Optional fail2ban or UFW configuration
- **Dependencies**: None for app code; gitleaks is a CI action