# Security Notes ## Sensitive Files - `.env` — Contains your Tailscale/Headscale auth key and service configuration. **Never commit this file.** - `tailscale/tailscale-data/` — Contains Tailscale node state and keys. **Never commit this directory.** ## Capabilities This compose file adds the following capabilities to the Tailscale sidecar: - `net_admin` — Required for Tailscale to manage network interfaces and routes. These capabilities are necessary for Tailscale to function but increase the attack surface if the container is compromised. ## Recommendations - Use a dedicated, limited-scope auth key for each service. - Regularly rotate auth keys. - Review Headscale/Tailscale ACLs to ensure services only have the access they need. - Keep the Tailscale Docker image reasonably up to date. ## Default Passwords The `docker-compose.yml` file contains placeholder values (`***`) for sensitive items such as: - Postgres password - Vikunja JWT secret **Change these values** before deploying anywhere security matters. Never use the default placeholders in production or shared environments. ## Environment File The `.env` file now contains additional sensitive values including: - Database credentials - Vikunja JWT secret **Never commit your `.env` file.** Always use `.env.example` as a template and keep real values private.