Skip to content

Security Model

github-actions[bot] edited this page Oct 5, 2026 · 2 revisions

Security model

The full document is docs/security-model.md in the repository, versioned with the code. Summary:

Trust boundaries

  1. Internet → edge. Only the master proxy on the VPS is internet-facing.
  2. Edge → appliance. A rathole tunnel, encrypted with Noise.
  3. LAN → appliance. HTTPS with a self-signed certificate that you trust once. Before that, a LAN attacker can intercept first use.
  4. notshared ↔ shared. Separate users and groups, mode-700 homes.

Known limitations

  • Shared origin. The admin UI, Nextcloud and Forgejo share one origin. An XSS in Nextcloud or Forgejo can read the admin token, which is equivalent to root. The fix would be a separate hostname for the admin UI.
  • Theft of the whole box is not defended against. The disk key is sealed to the TPM without PCR binding, so the chip releases it to any software run on that machine; only the disk on its own is unreadable. On a machine without a TPM the keyfile is on an unencrypted ESP and even the disk alone is readable.
  • The audit log is not tamper-evident and does not rotate.
  • Throttling is per address, so address spoofing on the LAN bypasses it.

Clone this wiki locally