docs/security-model.md

# Security Model

## Security Goals

- Do not deploy vulnerable images.
- Do not leak secrets.
- Do not run unsafe Kubernetes workloads.
- Do not expose unnecessary ports.
- Do not use root containers.
- Do not use `latest` tags.
- Enforce GitOps-based deployment.

## CI Security Gates

| Gate | Tool | Failure Condition |
|---|---|---|
| Secret scan | Gitleaks | Secret detected |
| Code quality | SonarQube | Quality gate fails |
| Image scan | Trivy | Critical vulnerability detected |
| IaC scan | Trivy/Checkov | High-risk misconfiguration |
| Dockerfile check | Hadolint later | Bad Dockerfile practices |

## Kubernetes Admission Policies

Kyverno policies will enforce:

- No privileged containers
- No root user containers
- No `latest` image tags
- Required CPU/memory requests and limits
- Required liveness/readiness probes
- Required labels
- Approved registry only
- No host network
- No hostPath volumes
- HTTPS ingress required

## Secrets Strategy

Phase 1-5:

- Use Kubernetes secrets carefully for local testing.
- Do not commit secrets to Git.

Later phases:

- Use SOPS + age for encrypted GitOps secrets.
- Use External Secrets Operator when connecting external secret stores.

## Access Strategy

- SSH key login only
- Disable password login
- Firewall enabled
- Cloudflare Tunnel for public access
- Keycloak for platform authentication later