Security architecture
Production deployment requires explicit trust boundaries, secure defaults, and tested mitigations for replication, webhooks, and HTTP gateways.
Trust boundaries
Section titled “Trust boundaries”[Client SDK / CLI] --TLS?--> [gRPC :2113][REST/WS Gateway] --HTTP--> [gRPC backend][HA peer nodes] --???--> [ReplicationService][Billing webhook] --HTTPS--> [External receiver][Admin UI BFF] --HTTP--> [gRPC backend]Threat summary (STRIDE, high level)
Section titled “Threat summary (STRIDE, high level)”| Component | Spoofing | Tampering | Repudiation | Info disclosure | DoS | Elevation |
|---|---|---|---|---|---|---|
| gRPC (auth off) | High | High | Medium | High | Medium | High |
| ReplicationService | High | High | High | Medium | High | High |
| Billing webhook | Low | Medium | Medium | Medium | Low | Medium (SSRF) |
| WS gateway | Medium | Medium | Low | High | Medium | Medium |
| Admin destructive ops | Low | High | Medium | Low | Medium | High |
Controls
Section titled “Controls”D1 — Replication authentication
Section titled “D1 — Replication authentication”- mTLS between cluster members or shared cluster token on internal listener.
- Unauthenticated
ReplicationServiceon public bind is not supported.
D2 — Production config profile
Section titled “D2 — Production config profile”CHRONACTA_PROFILE=productionenforces: auth on, TLS on, loopback or explicit bind audit, webhooks allowlist only.
D3 — Webhook outbound
Section titled “D3 — Webhook outbound”- HTTPS only; DNS resolve + block private ranges; mandatory HMAC secret when URL configured; no per-request URL override in production profile.
D4 — HTTP gateways
Section titled “D4 — HTTP gateways”- WS
CheckOriginallowlist; deprecate?token=query; TLS termination documented (gateway or reverse proxy).
D5 — RBAC
Section titled “D5 — RBAC”- New permission
lifecycle.executefor scavenge; default-deny unknown gRPC methods when auth enabled.
D6 — Audit
Section titled “D6 — Audit”- Structured audit events for: scavenge execute, restore, remote backup, billing export, admin login failure.
Not provided
Section titled “Not provided”- Field-level encryption at rest
- FIPS compliance
References
Section titled “References”- billing-webhook.md
- transports.md
- multi-tenant.md — OIDC SSO

