generated from DAM/ts-TEMPLATE
- Move Vikunja DB user/password/database and JWT secret to environment variables - Update .env.example with clear sections and 'change-me' placeholders - Update SECURITY.md to reflect that more secrets now live in .env
1.3 KiB
1.3 KiB
Security Notes
Sensitive Files
.env— Contains your Tailscale/Headscale auth key and service configuration. Never commit this file.tailscale/tailscale-data/— Contains Tailscale node state and keys. Never commit this directory.
Capabilities
This compose file adds the following capabilities to the Tailscale sidecar:
net_admin— Required for Tailscale to manage network interfaces and routes.
These capabilities are necessary for Tailscale to function but increase the attack surface if the container is compromised.
Recommendations
- Use a dedicated, limited-scope auth key for each service.
- Regularly rotate auth keys.
- Review Headscale/Tailscale ACLs to ensure services only have the access they need.
- Keep the Tailscale Docker image reasonably up to date.
Default Passwords
The docker-compose.yml file contains placeholder values (***) for sensitive items such as:
- Postgres password
- Vikunja JWT secret
Change these values before deploying anywhere security matters. Never use the default placeholders in production or shared environments.
Environment File
The .env file now contains additional sensitive values including:
- Database credentials
- Vikunja JWT secret
Never commit your .env file. Always use .env.example as a template and keep real values private.