trails/openspec/changes/security-hardening/proposal.md
Ullrich Schäfer 7d20dbb12f
Add observability and security-hardening proposals, gitignore settings.local
Two new OpenSpec changes:
- observability (30 tasks): health endpoints, Prometheus, Grafana+Loki,
  structured logging, dashboards, alerting
- security-hardening (24 tasks): Caddy headers, scanner blocking,
  gitleaks, pnpm audit, dependabot, non-root Docker, fail2ban

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-25 09:48:08 +01:00

42 lines
1.7 KiB
Markdown

## Why
A security audit found several gaps: no security headers (HSTS, CSP, etc.),
no secret scanning in CI, no dependency vulnerability scanning, Docker
containers running as root, and bot scanners probing for `.env` files with
no filtering. The cookie and auth setup is solid, but the infrastructure and
CI layers need hardening.
## What Changes
- **Security headers**: HSTS, X-Content-Type-Options, X-Frame-Options,
Referrer-Policy, Permissions-Policy via Caddyfile
- **Content-Security-Policy**: Restrict script/style/font sources
- **Gitleaks**: Secret scanning in CI to prevent credential leaks
- **Dependency auditing**: `pnpm audit` in CI + Dependabot for automated updates
- **Docker hardening**: Non-root user in all Dockerfiles
- **Bot/scanner blocking**: Caddy matcher to reject known scanner paths
(`.env`, `.git`, `wp-config`, etc.) with 403 before hitting the app
- **Fail2ban or equivalent**: Rate-limit SSH brute force and scanner IPs
at the server level
- **SECURITY.md**: Vulnerability disclosure policy
## Capabilities
### New Capabilities
- `security-hardening`: Security headers, CI secret/dependency scanning,
Docker non-root, scanner blocking, server-level rate limiting
### Modified Capabilities
- `infrastructure`: Caddy security headers + scanner blocking, Docker non-root,
Terraform firewall adjustments, CI scanning steps
## Impact
- **Caddyfile**: Security headers + scanner path blocking
- **Dockerfiles**: Add non-root user (journal, planner, brouter)
- **CI**: Add gitleaks step, pnpm audit step
- **Repo**: Add `.gitleaks.toml`, `dependabot.yml`, `SECURITY.md`
- **Server**: Optional fail2ban or UFW configuration
- **Dependencies**: None for app code; gitleaks is a CI action