From 7cdc03361c1a4c007ac5d0ad404618ffd8f27296 Mon Sep 17 00:00:00 2001 From: Graham McIntire Date: Thu, 19 Jun 2025 10:00:31 -0500 Subject: [PATCH] add live dashboard in prod --- .github/DOCKER_SECURITY.md | 104 ------------------------------------- lib/aprs_web/router.ex | 1 + 2 files changed, 1 insertion(+), 104 deletions(-) delete mode 100644 .github/DOCKER_SECURITY.md diff --git a/.github/DOCKER_SECURITY.md b/.github/DOCKER_SECURITY.md deleted file mode 100644 index f6f0b1f..0000000 --- a/.github/DOCKER_SECURITY.md +++ /dev/null @@ -1,104 +0,0 @@ -# Docker Security Strategy for APRS.me - -This document outlines our approach to maintaining secure Docker images for the APRS.me application. - -## System Dependencies Update Strategy - -Keeping system dependencies updated is crucial for security. Our strategy includes: - -1. **Regular Base Image Updates** - - We use specific dated versions of Debian slim images (`bullseye-YYYYMMDD-slim`) - - Images are rebuilt weekly via CI to incorporate latest security patches - - Each build uses `--pull` to ensure we get the latest base image versions - -2. **Full Package Updates During Build** - - Every build performs `apt-get update && apt-get upgrade` in both build and runtime stages - - We explicitly remove package lists after updates to reduce image size - - Only necessary runtime packages are installed in the final image - -3. **Minimized Attack Surface** - - Non-root user execution with specific UID/GID - - Removal of setuid/setgid permissions - - Secure permissions on system files - - Use of tini as init process - - Minimal set of installed packages - -4. **Continuous Monitoring** - - Weekly automated builds via GitHub Actions - - Security scanning with Trivy and Docker Scout - - Detailed vulnerability reports for OS and application dependencies - - Automatic failure on critical vulnerabilities - -## How System Updates Are Applied - -System dependencies are updated at several points: - -1. **During Image Build Time** - ```dockerfile - RUN apt-get update -y && \ - apt-get upgrade -y && \ - apt-get clean && \ - rm -f /var/lib/apt/lists/*_* - ``` - -2. **Via Scheduled Rebuilds** - - Weekly GitHub Actions workflow rebuilds the image with latest dependencies - - Base image is pulled with `--pull` flag to ensure latest version - - No-cache builds ensure all layers are rebuilt with fresh packages - -3. **During Deployment** - - Images are rebuilt for each deployment - - CI/CD pipeline includes security scanning before deployment - -## Security Scanning Process - -Our Docker images undergo multiple security scans: - -1. **Trivy Scanning** - - OS package vulnerabilities detection - - Application dependency vulnerabilities detection - - Configuration issue detection - -2. **Docker Scout** - - Deep analysis of base image security - - Comprehensive CVE detection - - Dependency analysis - -3. **Artifact Storage** - - Scan results are stored as GitHub Actions artifacts - - Summary reports are generated for easy review - - Historical data allows tracking security improvements - -## Manual Update Process - -To manually update the Docker image with the latest system dependencies: - -1. Run the update script: - ```bash - ./scripts/update-docker-image.sh - ``` - -2. This script will: - - Build a fresh image with latest dependencies using `--no-cache --pull` - - Run a security scan if Trivy is available - - Provide guidance on next steps - -3. Verify the updated image works as expected before deployment - -## Best Practices We Follow - -- We pin specific versions of Elixir, OTP, and Debian in our Dockerfile -- Multi-stage builds minimize the final image size -- We use non-root users with minimal permissions -- We secure system files and directories -- We remove unnecessary files and packages -- We use tini as an init process for proper signal handling -- We scan for vulnerabilities in both OS and application dependencies -- We update base images regularly (at least monthly) - -## Improvement Roadmap - -- Consider distroless images for further attack surface reduction -- Implement auto-update PR creation for base image versions -- Add dependency confusion detection -- Implement more granular vulnerability allowlisting for false positives \ No newline at end of file diff --git a/lib/aprs_web/router.ex b/lib/aprs_web/router.ex index c04c7f8..0f5c260 100644 --- a/lib/aprs_web/router.ex +++ b/lib/aprs_web/router.ex @@ -36,6 +36,7 @@ defmodule AprsWeb.Router do live "/packets/:callsign", PacketsLive.CallsignView, :index live "/badpackets", BadPacketsLive.Index, :index live "/:callsign", MapLive.CallsignView, :index + live_dashboard "/dashboard", metrics: AprsWeb.Telemetry end # Other scopes may use custom stacks.