Security architecture
Это содержимое пока не доступно на вашем языке.
Production deployment requires explicit trust boundaries, secure defaults, and tested mitigations for replication, webhooks, and HTTP gateways.
Trust boundaries
Section titled “Trust boundaries”[Client SDK / CLI] --TLS?--> [gRPC :2113][REST/WS Gateway] --HTTP--> [gRPC backend][HA peer nodes] --???--> [ReplicationService][Billing webhook] --HTTPS--> [External receiver][Admin UI BFF] --HTTP--> [gRPC backend]Threat summary (STRIDE, high level)
Section titled “Threat summary (STRIDE, high level)”| Component | Spoofing | Tampering | Repudiation | Info disclosure | DoS | Elevation |
|---|---|---|---|---|---|---|
| gRPC (auth off) | High | High | Medium | High | Medium | High |
| ReplicationService | High | High | High | Medium | High | High |
| Billing webhook | Low | Medium | Medium | Medium | Low | Medium (SSRF) |
| WS gateway | Medium | Medium | Low | High | Medium | Medium |
| Admin destructive ops | Low | High | Medium | Low | Medium | High |
Controls
Section titled “Controls”D1 — Replication authentication
Section titled “D1 — Replication authentication”- mTLS between cluster members or shared cluster token on internal listener.
- Unauthenticated
ReplicationServiceon public bind is not supported.
D2 — Production config profile
Section titled “D2 — Production config profile”CHRONACTA_PROFILE=productionenforces: auth on, TLS on, loopback or explicit bind audit, webhooks allowlist only.
D3 — Webhook outbound
Section titled “D3 — Webhook outbound”- HTTPS only; DNS resolve + block private ranges; mandatory HMAC secret when URL configured; no per-request URL override in production profile.
D4 — HTTP gateways
Section titled “D4 — HTTP gateways”- WS
CheckOriginallowlist; deprecate?token=query; TLS termination documented (gateway or reverse proxy).
D5 — RBAC
Section titled “D5 — RBAC”- New permission
lifecycle.executefor scavenge; default-deny unknown gRPC methods when auth enabled.
D6 — Audit
Section titled “D6 — Audit”- Structured audit events for: scavenge execute, restore, remote backup, billing export, admin login failure.
Not provided
Section titled “Not provided”- Field-level encryption at rest
- FIPS compliance
References
Section titled “References”- billing-webhook.md
- transports.md
- multi-tenant.md — OIDC SSO

