Security hardening: headers, scanning, Docker, firewall

- Caddy: HSTS, CSP, X-Frame-Options, nosniff, Referrer-Policy,
  Permissions-Policy on all responses
- Caddy: Block scanner paths (.env, .git, wp-config, etc.) with 403
- CI: Gitleaks secret scanning + pnpm audit for vulnerabilities
- Dependabot: Weekly npm + GitHub Actions + monthly Docker updates
- Docker: Non-root user in journal, planner, and brouter containers
- Server: UFW firewall (22/80/443 only) + fail2ban (8 IPs already banned)
- SECURITY.md: Vulnerability disclosure policy
- Privacy page: Security practices section added

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
Ullrich Schäfer 2026-03-25 09:58:12 +01:00
parent 0499133982
commit be3e69c10b
No known key found for this signature in database
GPG key ID: A32FF691A0F752D9
11 changed files with 211 additions and 18 deletions

View file

@ -12,13 +12,15 @@ RUN apt-get update && apt-get install -y --no-install-recommends wget unzip curl
&& rm "brouter-${BROUTER_VERSION}.zip" \
&& apt-get purge -y wget unzip && apt-get autoremove -y && rm -rf /var/lib/apt/lists/*
# Create directories for segments and profiles
RUN mkdir -p /data/segments /data/profiles
# Create non-root user and directories for segments and profiles
RUN addgroup --system app && adduser --system --ingroup app app \
&& mkdir -p /data/segments /data/profiles
# Copy default profiles from release and rename JAR for simpler CMD
RUN cp -r profiles2/* /data/profiles/ 2>/dev/null || true \
&& mv brouter-*-all.jar brouter.jar
USER app
EXPOSE 17777
# BRouter server: <segmentdir> <profiledir> <customprofiledir> <port> <maxthreads>