Security¶
Report a vulnerability¶
Please report a security problem privately first, through the contact form with the subject "Fadenstack security". Describe what you found and how to reproduce it. Do not open a public issue for it.
How Fadenstack handles data, encryption and access is described on the website's Security and privacy page.
When you build on Fadenstack¶
- Keep keys out of code. Read API keys from the environment or a secret store. A key acts with the rights of the user it belongs to.
- One key per use, and revoke what you don't need. Name each key after the app or script that uses it. Revoke a key in your profile when the app is retired or the key may have leaked; the server refuses it within a minute. Revoking needs a server newer than 0.4.1.
- Agents sign in per user and device. The SDKs keep an agent's sign-in for the user on that device. The user's password or login token is used once and not kept.
- Trust the server's certificate. A Fadenstack server often uses its own certificate authority. Install that CA where your application runs, or give it to the SDK, rather than turning certificate checks off.
- Classify your tools honestly. A tool that changes something is Write or Destructive, so the user is asked first. See Tools and approvals.