# Security Notes ## Sensitive Files - `.env` — Contains your Tailscale/Headscale auth key and service configuration. **Never commit this file.** - `tailscale/tailscale-data/` — Contains Tailscale node state and keys. **Never commit this directory.** ## Capabilities This compose file adds the following capabilities to the Tailscale sidecar: - `net_admin` — Required for Tailscale to manage network interfaces and routes. These capabilities are necessary for Tailscale to function but increase the attack surface if the container is compromised. ## Default Passwords & Secrets The `docker-compose.yml` and `.env` files contain placeholder values (`***`) for sensitive items such as: - Database credentials - Service JWT secret **Change these values** before deploying anywhere security matters. Never use the default placeholders in production or shared environments. ## Recommendations - Use a dedicated, limited-scope auth key for each service. - Regularly rotate auth keys. - Review Headscale/Tailscale ACLs to ensure services only have the access they need. - Keep the Tailscale Docker image reasonably up to date.