add live dashboard in prod
This commit is contained in:
parent
76e93aba17
commit
7cdc03361c
2 changed files with 1 additions and 104 deletions
104
.github/DOCKER_SECURITY.md
vendored
104
.github/DOCKER_SECURITY.md
vendored
|
|
@ -1,104 +0,0 @@
|
||||||
# Docker Security Strategy for APRS.me
|
|
||||||
|
|
||||||
This document outlines our approach to maintaining secure Docker images for the APRS.me application.
|
|
||||||
|
|
||||||
## System Dependencies Update Strategy
|
|
||||||
|
|
||||||
Keeping system dependencies updated is crucial for security. Our strategy includes:
|
|
||||||
|
|
||||||
1. **Regular Base Image Updates**
|
|
||||||
- We use specific dated versions of Debian slim images (`bullseye-YYYYMMDD-slim`)
|
|
||||||
- Images are rebuilt weekly via CI to incorporate latest security patches
|
|
||||||
- Each build uses `--pull` to ensure we get the latest base image versions
|
|
||||||
|
|
||||||
2. **Full Package Updates During Build**
|
|
||||||
- Every build performs `apt-get update && apt-get upgrade` in both build and runtime stages
|
|
||||||
- We explicitly remove package lists after updates to reduce image size
|
|
||||||
- Only necessary runtime packages are installed in the final image
|
|
||||||
|
|
||||||
3. **Minimized Attack Surface**
|
|
||||||
- Non-root user execution with specific UID/GID
|
|
||||||
- Removal of setuid/setgid permissions
|
|
||||||
- Secure permissions on system files
|
|
||||||
- Use of tini as init process
|
|
||||||
- Minimal set of installed packages
|
|
||||||
|
|
||||||
4. **Continuous Monitoring**
|
|
||||||
- Weekly automated builds via GitHub Actions
|
|
||||||
- Security scanning with Trivy and Docker Scout
|
|
||||||
- Detailed vulnerability reports for OS and application dependencies
|
|
||||||
- Automatic failure on critical vulnerabilities
|
|
||||||
|
|
||||||
## How System Updates Are Applied
|
|
||||||
|
|
||||||
System dependencies are updated at several points:
|
|
||||||
|
|
||||||
1. **During Image Build Time**
|
|
||||||
```dockerfile
|
|
||||||
RUN apt-get update -y && \
|
|
||||||
apt-get upgrade -y && \
|
|
||||||
apt-get clean && \
|
|
||||||
rm -f /var/lib/apt/lists/*_*
|
|
||||||
```
|
|
||||||
|
|
||||||
2. **Via Scheduled Rebuilds**
|
|
||||||
- Weekly GitHub Actions workflow rebuilds the image with latest dependencies
|
|
||||||
- Base image is pulled with `--pull` flag to ensure latest version
|
|
||||||
- No-cache builds ensure all layers are rebuilt with fresh packages
|
|
||||||
|
|
||||||
3. **During Deployment**
|
|
||||||
- Images are rebuilt for each deployment
|
|
||||||
- CI/CD pipeline includes security scanning before deployment
|
|
||||||
|
|
||||||
## Security Scanning Process
|
|
||||||
|
|
||||||
Our Docker images undergo multiple security scans:
|
|
||||||
|
|
||||||
1. **Trivy Scanning**
|
|
||||||
- OS package vulnerabilities detection
|
|
||||||
- Application dependency vulnerabilities detection
|
|
||||||
- Configuration issue detection
|
|
||||||
|
|
||||||
2. **Docker Scout**
|
|
||||||
- Deep analysis of base image security
|
|
||||||
- Comprehensive CVE detection
|
|
||||||
- Dependency analysis
|
|
||||||
|
|
||||||
3. **Artifact Storage**
|
|
||||||
- Scan results are stored as GitHub Actions artifacts
|
|
||||||
- Summary reports are generated for easy review
|
|
||||||
- Historical data allows tracking security improvements
|
|
||||||
|
|
||||||
## Manual Update Process
|
|
||||||
|
|
||||||
To manually update the Docker image with the latest system dependencies:
|
|
||||||
|
|
||||||
1. Run the update script:
|
|
||||||
```bash
|
|
||||||
./scripts/update-docker-image.sh
|
|
||||||
```
|
|
||||||
|
|
||||||
2. This script will:
|
|
||||||
- Build a fresh image with latest dependencies using `--no-cache --pull`
|
|
||||||
- Run a security scan if Trivy is available
|
|
||||||
- Provide guidance on next steps
|
|
||||||
|
|
||||||
3. Verify the updated image works as expected before deployment
|
|
||||||
|
|
||||||
## Best Practices We Follow
|
|
||||||
|
|
||||||
- We pin specific versions of Elixir, OTP, and Debian in our Dockerfile
|
|
||||||
- Multi-stage builds minimize the final image size
|
|
||||||
- We use non-root users with minimal permissions
|
|
||||||
- We secure system files and directories
|
|
||||||
- We remove unnecessary files and packages
|
|
||||||
- We use tini as an init process for proper signal handling
|
|
||||||
- We scan for vulnerabilities in both OS and application dependencies
|
|
||||||
- We update base images regularly (at least monthly)
|
|
||||||
|
|
||||||
## Improvement Roadmap
|
|
||||||
|
|
||||||
- Consider distroless images for further attack surface reduction
|
|
||||||
- Implement auto-update PR creation for base image versions
|
|
||||||
- Add dependency confusion detection
|
|
||||||
- Implement more granular vulnerability allowlisting for false positives
|
|
||||||
|
|
@ -36,6 +36,7 @@ defmodule AprsWeb.Router do
|
||||||
live "/packets/:callsign", PacketsLive.CallsignView, :index
|
live "/packets/:callsign", PacketsLive.CallsignView, :index
|
||||||
live "/badpackets", BadPacketsLive.Index, :index
|
live "/badpackets", BadPacketsLive.Index, :index
|
||||||
live "/:callsign", MapLive.CallsignView, :index
|
live "/:callsign", MapLive.CallsignView, :index
|
||||||
|
live_dashboard "/dashboard", metrics: AprsWeb.Telemetry
|
||||||
end
|
end
|
||||||
|
|
||||||
# Other scopes may use custom stacks.
|
# Other scopes may use custom stacks.
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue