Security audit (12-angle adversarial workflow) findings on the container→host boundary: - .env was created world-readable (cp of a 644 .env.example, never chmod'd) exposing the APP_KEY that decrypts the whole fleet's SSH vault. Now chown clusev + chmod 0600 before any secret write. - The root updater followed attacker-planted symlinks in the container-writable ./run (update-phase.json, update.log) → arbitrary root file write. Status writes now go via a temp + rename(2) (never follow a link); the update transcript moved to the repo root (not the ./run bind mount). - The generated UPDATE_HMAC_KEY was dead. The app now HMAC-signs the update-request marker (config/clusev.php update_hmac_key; DeploymentService) and watch.sh verifies it before running a root update, so a stray/limited write to ./run can't drive one (a full container compromise holds the key, so this is a bar-raise + integrity check; the standing guarantee is the marker only ever re-installs the trusted remote's code, never attacker code). - force_kv/set_kv wrote unescaped values into a sed replacement — a & | or newline in an operator's domain/email/port could corrupt .env or inject a sed command. Values are now CR/LF-stripped and sed-escaped, and the HTTP port is validated numeric/in-range. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| Console/Commands | ||
| Events | ||
| Http | ||
| Jobs | ||
| Livewire | ||
| Models | ||
| Notifications | ||
| Providers | ||
| Rules | ||
| Services | ||
| Support | ||