docs/security-model.md
# Security Model
## Security Goals
- Do not deploy vulnerable images.
- Do not leak secrets.
- Do not run unsafe Kubernetes workloads.
- Do not expose unnecessary ports.
- Do not use root containers.
- Do not use `latest` tags.
- Enforce GitOps-based deployment.
## CI Security Gates
| Gate | Tool | Failure Condition |
|---|---|---|
| Secret scan | Gitleaks | Secret detected |
| Code quality | SonarQube | Quality gate fails |
| Image scan | Trivy | Critical vulnerability detected |
| IaC scan | Trivy/Checkov | High-risk misconfiguration |
| Dockerfile check | Hadolint later | Bad Dockerfile practices |
## Kubernetes Admission Policies
Kyverno policies will enforce:
- No privileged containers
- No root user containers
- No `latest` image tags
- Required CPU/memory requests and limits
- Required liveness/readiness probes
- Required labels
- Approved registry only
- No host network
- No hostPath volumes
- HTTPS ingress required
## Secrets Strategy
Phase 1-5:
- Use Kubernetes secrets carefully for local testing.
- Do not commit secrets to Git.
Later phases:
- Use SOPS + age for encrypted GitOps secrets.
- Use External Secrets Operator when connecting external secret stores.
## Access Strategy
- SSH key login only
- Disable password login
- Firewall enabled
- Cloudflare Tunnel for public access
- Keycloak for platform authentication later