This page documents security practices applied to the Enclari server and its applications.
entrypoints.web → websecure)secure-headers middleware:- traefik.http.middlewares.secure-headers.headers.stsSeconds=31536000
- traefik.http.middlewares.secure-headers.headers.stsIncludeSubdomains=true
- traefik.http.middlewares.secure-headers.headers.stsPreload=true
- traefik.http.middlewares.secure-headers.headers.contentTypeNosniff=true
- traefik.http.middlewares.secure-headers.headers.browserXssFilter=true
- traefik.http.middlewares.secure-headers.headers.referrerPolicy=no-referrer
- traefik.http.middlewares.secure-headers.headers.frameDeny=true
authentik-forwardauth@file). Portainer additionally uses OIDC login./etc/ssh/sshd_config.d/00-hardening.conf (2026-09-30; before that the default PasswordAuthentication yes was active). Files in sshd_config.d are read alphabetically and the first value wins, so the 00- prefix overrides 50-cloud-init.conf. Check: sshd -T | grep -iE '^(passwordauthentication|kbdinteractiveauthentication|permitrootlogin)'PermitRootLogin without-password)deploy (GitHub Actions for EventKit): not in the docker group. Its only key in ~deploy/.ssh/authorized_keys has restrict,command="sudo /usr/local/bin/eventkit-deploy ...", and sudoers (/etc/sudoers.d/eventkit-deploy) allows only that script. The key can deploy an existing image tag and nothing else. See /apps/eventkithtop, ncdu, rsync, restic, rclone/root/.restic-envRCLONE_BW_LIMIT=10M) to avoid DoSdocker logs and system journal# Verify TLS certs
curl -vI https://enclari.com
# Verify Authentik login
curl -I https://traefik.enclari.com
# Check for open ports
ss -tulpen
# Check Docker networks isolation
docker network ls
docker network inspect web
# Inspect Traefik middlewares
docker inspect traefik | jq '.[0].Config.Labels'
authentik-db-1 is attached only to web, so every container on web can reach it, and its service alias db hijacks the hostname db for any stack on web (broke EventKit's first start). Fix: give the Authentik stack an internal network for db/redis, keep only authentik-server on web.Portainer Gate proxy provider). Remaining: Portainer Gate has no bindings, align with PMA.pages.list are available without login, and GraphQL errors return full stack traces with server paths.authentik-forwardauth definitions: dynamic/authentik.yml (effective), dynamic/forwardauth.yml and labels on the traefik container (both unused). Remove the unused two.maxResponseBodySize is not configured on the ForwardAuth middleware. Set a limit in dynamic/authentik.yml.